Scope and standard
A call to agree the sites and network segments in scope and the standard they are compared against: CPCSC and ITSP.10.171, ISO 27001, CIS, or a client policy.
Search hans.study
Indexed across articles, news, KB updates, knowledge base, books, learning, and tools. Press Esc to close.
// NETWORK SECURITY ASSESSMENT · HANS STUDY · ONTARIO, CANADA
A cyber insurance questionnaire, a customer security review, a CPCSC or CMMC contract clause, an incident that moved sideways across the network, or a new site on a network nobody ever drew. This compares the network with the standard you owe and puts the gaps in the order to fix them.
The required standard, whichever applies: CPCSC and ITSP.10.171, ISO 27001, the CIS benchmarks, or a client's own policy. For CPCSC the two families doing most of the work are system and communications protection and configuration management. A baseline, a change record, and evidence are what an assessor reads, and network configurations can be diffed automatically so drift shows up on its own.
Four phases, delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.
A call to agree the sites and network segments in scope and the standard they are compared against: CPCSC and ITSP.10.171, ISO 27001, CIS, or a client policy.
The logical topology diagram, the list of controls between a user and the data that matters, the firewall rule set, switch configurations, and the remote access and MFA settings. Collected remotely, through the DHD where needed.
The same method as the firewall review and the switch config audit, applied across the whole network and set against the standard.
A ranked gap list, a target architecture sketch, and a remediation sequence, walked through with you.
The assessment uses the same approach as these, and you can run them yourself before a call.
A free PowerShell script that proves a declared list of firewall paths is open and returns a pass/fail matrix.
Audits a Cisco IOS or IOS-XE switch configuration offline against 121 checks, with masked credentials and cited fixes.
I don't resell hardware or software, so the target architecture is drawn for your needs, not for a price list. See the independence policy.
Authenticated and unauthenticated scanning of an agreed scope, ranked findings, and a rescan.
Network design for CCTV, access control, and security systems, designed independently.
Architecture review, greenfield design, and remediation, vendor-agnostic.
Segmentation and VLANs, the firewall rule base, switch configurations, remote access paths, MFA on admin paths, logging, and DNS filtering. Each gap is tied to the requirement or standard it fails.
A vulnerability assessment scans systems for known weaknesses. This one reviews how the network is built and configured, and compares it with a standard such as CPCSC and ITSP.10.171, ISO 27001, the CIS benchmarks, or a client's own policy.
The logical topology diagram, the list of controls between a user and the data that matters, the firewall rule set, switch configurations, and the remote access and MFA settings. If no diagram exists, say so on the scoping call.
Yes. The 4 phases are delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.
A ranked gap list, a target architecture sketch of the segments, the boundaries between them, and the paths in, and a remediation sequence ordered so each step is safe to make before the next. We go through the findings together in a working session.
The sites and network segments in scope are agreed on a scoping call, and a written quote comes before any work starts.
Bring the questionnaire or the clause that triggered this, and the topology diagram if one exists, and a short call confirms the scope.
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.