Athena Software now Offering HIPAA readiness and Security Audit Services
June 15, 2007

Athena Software takes system security and the confidentiality of your client's data extremely seriously. We strongly encourage all organizations that store confidential data of any type to have their systems tested periodically for a range of vulnerabilities. Ensuring that you have taken important steps to protect the privacy of your client's confidential information is absolutely vital - for your accreditors, for your funders, for your client's privacy and confidentiality and for your peace of mind.

We are pleased to offer a security audit service by an experienced and accredited senior Network Analyst that allows your organization to select which areas of your system and business policies you would like "audited" for vulnerabilities. Contact us today to find out how we can help yoru organization improve its overall systems security and ability to recover from disaster. It may be the smartest, most far-sighted decision you will ever make! Security areas you may choose to be included in your audit include:

Network Review includes items such as:

  • Hardware inventory and network scan
  • Develop up to date network diagram
  • Check for devices bypassing FW
  • Check access to network devices - including password strength etc.
  • Check for network monitors
  • If VPN access is enabled, check access to system and ensure proper policies in place
  • Determine if network or system monitoring software is required; configure if needed
  • Penetration testing and port scanning of firewalls and servers
Server Review Includes Items such as:
  • Checking of patch levels - Update procedure
  • Check of running processes- removal of unneeded processes
  • Check access rights
  • Hardening of servers
  • Virus scanning
  • Spy-ware scanning
  • Check fans - for heat issues
Firewall Review Includes Items such as:
  • Check rules and check access rights
  • Limit outbound / inbound traffic if needed
  • Check updates, Version
Access Methods Includes Items such as:
  • Passwords policies and controls
  • Account creation policies and controls
  • Access cards - Audit Logs
  • Physical security of the computer room
Facility-related Issues Includes Items such as:
  • Physical access review
  • Redundant power supply
  • Fire precautions
  • Ventilation - temperature controls
Backups Testing Includes Items such as:
  • Off-site transfer frequency / method / completeness
  • Disaster recover planning
Data Handling Issues Includes Items such as:
  • Level of Encryption
  • Manner of transferred
  • Access control
  • Can the backed up data be removed, copied, modified?
Workstation-related Issues Includes items such as:
  • Laptop security - Disk encryption, VPN access etc.
  • Screen-savers with password lock
  • No displayed passwords or userids
  • Workstation Lock down