IT / Information security audit

Comprehensive assessment of the state of the IT infrastructure and information security system.

Comprehensive assessment of the IT infrastructure and information security system of your organization.

What is an IT/IS Audit

An IT/IS audit is an independent expert assessment of the current state of an organization’s information technology and information security. The audit provides an objective picture of how effectively your IT infrastructure operates, how information protection is organized, what risks exist, and what measures need to be taken.

We conduct audits not “for the sake of compliance” — our goal is to provide you with a real understanding of the current maturity level of IT and IS, identify weaknesses, and provide a prioritized action plan.

Types of Audit

IT Audit

Comprehensive assessment of the organization’s IT infrastructure:

  • Server equipment, storage systems, and virtualization
  • Network infrastructure
  • Software and licensing
  • Backup
  • IT processes (changes, incidents)

IS Audit

Assessment of the information security system:

  • Information security policies and procedures
  • Access management (IAM)
  • Perimeter protection (NGFW, IDS/IPS)
  • Security event monitoring (SIEM)
  • Endpoint protection

Compliance

Assessment of compliance with standards and regulatory requirements:

  • Unified Requirements (Resolution of the Government of the Republic of Kazakhstan No. 832)
  • ISO/IEC 27001
  • PCI DSS
  • Law of the Republic of Kazakhstan “On Personal Data”
  • Requirements of the National Bank of Kazakhstan and the Ministry of Digital Development, Innovation and Aerospace Industry

Who Needs an Audit

  • Organizations planning GTS RK certification — assessment of readiness and determination of the scope of required improvements.
  • Companies preparing for ISO 27001 certification — preliminary audit (GAP analysis).
  • Organizations following a cyber incident — determining the causes of the incident, assessing the impact, and preventing recurrence.
  • Businesses in a growth or transformation stage — assessing information security during scaling, mergers, or implementation of new systems.
  • Companies without a dedicated information security team — an independent external assessment of their security posture.

How We Work

01

Scope Definition

We define the audit scope and agree on the objectives (overall assessment, certification, incident investigation).

02

Information Gathering

Interviews, documentation analysis, and technical assessment of the infrastructure.

03

Analysis and Assessment

Assessment against the standard’s criteria. Determination of IT/IS maturity level and risk prioritization.

04

Report and Presentation

We prepare a detailed report and executive summary. We present the findings to the team and management.

What You Will Receive

Result Description
Audit Report A detailed document describing the current state of IT/IS, identified issues, and risk assessment
Executive Summary A concise version for management: key risks, maturity level, and priority actions
Risk Map Visualization of identified risks by criticality and likelihood of occurrence
Action Plan A prioritized list of recommendations with estimated implementation timelines and resource requirements
Compliance Assessment A compliance matrix against the requirements of the selected standard (for a compliance audit)

Why SAQTEK

Comprehensive Expertise

Our auditors combine expertise in IT, information security, and regulatory requirements — providing you with a comprehensive perspective.

Knowledge of the Local Context

We work with consideration for Kazakhstan’s legislation, Unified Requirements, and the specifics of the Republic of Kazakhstan’s regulatory authorities.

Practical Recommendations

We provide not abstract advice, but specific, actionable recommendations that take your budget and resources into account.

From Audit to Action

As a system integrator, we can not only identify problems but also help resolve them.

Find Out the Real State of Your Information Security

Submit a request — we will conduct a free preliminary consultation and determine the optimal audit scope for your organization.

Submit a Request →