|

|
Risk and Control Assessment |
|

|
Security Policies and Procedures |
|

|
Firewall Vulnerability and Perimeter Protection |
|

|
Logical Access Security Controls |
|

|
Sarbane-Oxley:
Statement 404-process documentation and detailed transaction testing |
|

|
Physical Security Controls of Restricted Areas |
|

|
Adequacy of Written IT and Security Procedures and Instructions |
|

|
Incident Detection and Response Reporting and Investigation |
|

|
Application
Processing Controls Assessment |
|

|
Disaster
Recovery Testing |
|

|
Business
Continuity Planning |
|

|
Emergency Procedures |
|

|
Security Awareness Training Programs |