Details.
Analyse the security configuration of equipment against a reference of good practices. The review is based on a configuration extraction performed manually by an administrator or automatically with a script. The objective is to determine whether the current level of hardening is consistent with the state of the art or company policy. References may include CIS, ANSSI, NIST or the audited organisation's internal standards. Examples include firewalls, server bases, application servers and database servers.
