
Information Security
Security Audits by certified specialists
Assessment of IT security and information security
Security Audit
Audits of information security and IT security
A regularly conducted security audit of the implemented technical and organizational measures provides transparency regarding compliance requirements and the level of IT security achieved.
A security audit considers one or more of the following aspects: IT security, information security processes, information security organization and physical security.
Concepts for cloud security, customer requirements and other IT compliance topics are also frequently taken into account.
Our Security Audits
Internal audit according to VDA/ISA TISAX®
In an internal TISAX® audit, we assess the state of information security in accordance with the VDA/ISA requirements.
Internal audit according to ISO 27001
An internal audit according to ISO/IEC 27001 assesses the maturity of your own ISMS.
Redlings Cyber Security Check
With this security audit you gain visibility into the current status of your information security and existing IT risks.
Service provider audit
With a service provider audit you can ensure compliance with agreed contractual requirements at external service providers or contractual partners.
Cloud Security Audit
A cloud security audit performs a detailed security assessment of your cloud infrastructure in a comprehensive assessment.
Internal audit
An internal audit independently checks compliance with internal, external, contractual or regulatory requirements.
Cyber Security Due Diligence
To minimize cyber risks in mergers and acquisitions, we assess the state of a company’s cyber security.
Reasons for a Security Audit
- Status and maturity of your own information security: A regularly conducted security audit highlights the progress of your own activities in the areas of IT security and information security. Prioritized measures and potential for improvement are also identified.
- Strengthening security awareness within the company. A security audit is always carried out in close coordination with site or executive management. Conducting the audit also always contributes to raising security awareness.
- Minimizing the risks of using information technology By implementing the proposed measures, your own IT risks can be permanently reduced. The risk of possible damage is also reduced.
- Demonstrating the maturity of your own information security to customers and other third parties: A certification can be a valuable means of demonstrating the fulfillment of contractual, legal or regulatory requirements.
- Strengthening customer trust Conducting regular security audits is regarded by customers as a trust-building measure. Especially since most customer orders involve the transfer of data from the customer to the contractor.
- Responsibility for information security A security audit often uncovers unclear gaps in responsibility for information security within companies.
What is the difference between a Security Audit and a Penetration Test?
A security audit examines the implemented technical and organizational measures for conformity with a standard. Examples of such a standard are ISO 27001 or VDA/ISA TISAX®. Even if such an assessment is comprehensive, no testing of technical IT security takes place — instead, the focus is on the implemented processes.
In contrast, penetration testing simulates a cyber attack. On behalf of a company, a penetration tester attempts to break into its own IT systems. In particular, configuration errors and existing security vulnerabilities are exploited.
A security audit and a penetration test are complementary and combine to provide an overall picture of IT security.
Depending on their design, however, the terms are not entirely distinct. Depending on the agreement, Redlings’ security audits also include components of penetration tests in order to establish sufficient transparency in all relevant areas.
certified and experienced
Qualifications and Standards







Why Redlings?
A Trusted Partner
Certified and experienced auditors (CISSP, OSCP, OSCE, GIAC)
Years of experience with ISO/IEC 27001 and VDA/ISA TISAX®
Audits in accordance with recognized norms and standards (ISO 27001, TISAX®, BSI IT-Grundschutz)
Detailed report with prioritized measures and improvement potential
Holistic assessment of IT security and information security

Have we sparked your interest?
Just give us a call or write us a message!


