Comprehensive security assessment follows a layered approach, wherein it covers the assessment of all the in-line infrastructure components (network devices, security devices, Server environments and Mobile/web applications/APIs) to ensure that all areas of threats, vulnerabilities and risks are identified and reported. Comprehensive Security Assessment (CSA) Audit is to carry out in depth analysis of existing Application, Web Infrastructure threats and check for the existing built-in security controls in the running Project portal. The CSA further aims to trace hidden security issues, check for strong access controls, assessment to prevent Data breaches and recommends strong measures for Data Security. The CSA approach includes five key verticals that should be executed to assess the respective Project portal strengths and weakness. The outline scope for Security Compliance testing process should be properly documented with steps clearly laid out in the test plan. It should also include layered deliverables with deliverables in each assessment step. The Components included in CSA scope are: All the below processes are taken up continuously in iterative mode till all the raised vulnerable issues are not mitigated. The CSA process provides granular Security compliance assessment mechanism that would help us to build a viable and fool-proof security posture. The Business logic Process Compliance check mainly involves Access Control checks (as per ISO 27001:2013), Checks for Out-of-bound processes Being used (like OTPs/password changes etc.), API and Data Security Controls (Data Privacy, Sensitive Data Handling etc.), Audit Logs Check of complete process workflow. This test also focuses to ensure that Data Security controls are properly in place or not. The External facing Infrastructure Assessment covers Configuration/ Firewall Rules and Vulnerability Assessment of in line Perimeter/ Security Devices being in use by respective Project portal. The Public IP Addresses/URLs are also taken up of Security Compliance assessment The Internal Infrastructure Vulnerability Assessment of internal Servers, Security and network devices is also taken for Security Compliance testing. The Network and Deployment Architecture is reviewed for any security gaps The Web/Mobile App/API/Web Services being used by the Project portal are also taken for Security Compliance testing