Public IP and Port Scanning
Identify visible public IPs, exposed ports, open services, risky protocols, unauthorized systems, and internet-facing assets that may not match the approved inventory.
OC Security Audit helps businesses identify exposed public IPs, misconfigured firewalls, vulnerable VPN portals, cloud exposure, weak email security, web application weaknesses, and other external attack surface risks.
An External Security Audit is a comprehensive review of your organization’s internet-facing systems from the outside looking in. The goal is to simulate how real attackers see your digital footprint and identify vulnerabilities before cybercriminals can exploit them.
This audit focuses on public-facing components such as public IP addresses and vulnerability scanning, firewall exposure, VPN gateways, remote access systems, DNS records, email authentication, web applications, cloud services, and third-party connections.
Our assessment combines external attack surface discovery, vulnerability validation, business risk context, and practical remediation guidance for leadership and technical teams.
Identify visible public IPs, exposed ports, open services, risky protocols, unauthorized systems, and internet-facing assets that may not match the approved inventory.
Review NAT, ACLs, firewall rule exposure, DMZ segmentation, administrative access, remote management paths, and risky service publication.
Review exposed VPN portals, MFA, encryption, authentication controls, logging, patch exposure, and remote access risk.
Review SPF, DKIM, DMARC, DNS hygiene, registrar security, domain protection, mail authentication, spoofing exposure, and external email posture.
Review external websites, portals, login pages, TLS configuration, exposed admin panels, web headers, known weaknesses, and application risk signals.
Review external cloud endpoints, SaaS exposure, public storage risks, identity entry points, Microsoft 365 and Azure exposure, and third-party services.
Prioritize vulnerabilities by severity, exploitability, asset importance, compensating controls, business exposure, and practical remediation effort.
Deliver risk-rated findings, technical evidence, business impact, remediation priorities, and optional retesting after fixes.
New firewall rules, vendor access, cloud systems, web applications, certificates, remote users, and DNS changes can quietly create exposure. An external security audit helps identify real-world internet-facing risk before it becomes an incident.
Exposed administrative interfaces, outdated VPN portals, exploitable web vulnerabilities, publicly reachable sensitive systems, or high-risk services open to the internet.
Weak authentication, missing MFA on remote access, insecure firewall rules, poor TLS configuration, vulnerable web applications, or cloud services with risky public exposure.
DNS hygiene gaps, weak email authentication, unnecessary open ports, expired certificates, inconsistent asset inventory, missing monitoring, or patch exposure.
Banner disclosure, documentation gaps, cleanup items, policy inconsistencies, and findings that help improve evidence readiness and operational maturity.
OC Security Audit provides clear executive reporting, technical findings, business impact, remediation priorities, evidence details, and optional retesting after fixes.
Use this structured checklist to review public IP exposure, DMZ firewall rules, NAT and ACLs, VPN security, web applications, DNS, email authentication, cloud exposure, third-party access, monitoring, compliance, and recovery readiness. The full checklist is preserved below in a scrollable audit worksheet.
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-001 | Document all public IP addresses and CIDR ranges assigned to the organization | Public IPs / ISP ranges | Approved public IP inventory, ISP records, cloud IP list | 4 | 4 | High | CISO / IT Manager | Quarterly |
| ESA-002 | Validate that public IP ownership and business owner are assigned for each range | Public IPs / asset ownership | Asset register with owner, business function, and criticality | 3 | 4 | Medium | IT Manager | Quarterly |
| ESA-003 | Identify unknown or unmanaged public IPs responding to internet scans | Public IPs | External scan output showing responding hosts | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-004 | Map domains and subdomains associated with the business | Domains / subdomains | DNS export, subdomain discovery report | 4 | 4 | High | Cybersecurity Administrator | Quarterly |
| ESA-005 | Identify stale DNS records pointing to retired services or unclaimed cloud resources | Public DNS | DNS record review and cloud resource verification | 5 | 3 | High | Network Engineer | Quarterly |
| ESA-006 | Document all internet-facing applications and portals | Websites / portals | Application inventory with URL, owner, authentication type | 4 | 4 | High | IT Manager | Quarterly |
| ESA-007 | Validate business justification for every internet-facing service | Public services | Approved exception or business requirement per exposed service | 4 | 4 | High | CISO / IT Manager | Quarterly |
| ESA-008 | Confirm external asset inventory matches firewall, DNS, and cloud records | Public footprint | Cross-check of firewall NAT, DNS, registrar, cloud, and scan data | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-009 | Identify shadow IT services exposed outside approved infrastructure | SaaS / cloud / websites | Shadow IT report and remediation plan | 4 | 3 | Medium | CISO / IT Manager | Quarterly |
| ESA-010 | Verify external scan scope includes all locations, cloud tenants, and vendor-hosted systems | Multi-site external scope | Approved audit scope with locations and cloud accounts | 3 | 3 | Medium | CISO / Auditor | Annually |
| ESA-011 | Track external service changes through change management | External change control | Change tickets for new ports, NAT, DNS, VPN, and cloud exposure | 4 | 3 | Medium | IT Manager | Monthly |
| ESA-012 | Maintain retired asset list to prevent forgotten exposed systems | Legacy internet-facing assets | Retirement log and external scan validation | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-013 | Scan all public IP ranges for open TCP and UDP ports | Public IPs | Nmap or equivalent external port scan evidence | 5 | 5 | Critical | Network Engineer | Monthly |
| ESA-014 | Validate only approved ports are exposed to the internet | Public services | Approved port matrix and scan comparison | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-015 | Confirm FTP is not exposed unless explicitly approved and secured | FTP services | Scan result and service configuration evidence | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-016 | Confirm Telnet is not exposed to the internet | Telnet services | External scan showing Telnet closed or filtered | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-017 | Confirm SMB is not exposed to the internet | SMB / Windows services | External scan showing ports 139/445 closed | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-018 | Review RDP exposure and require VPN or secure gateway access | RDP / remote access | Firewall rule review and scan validation | 5 | 5 | Critical | Network Engineer | Monthly |
| ESA-019 | Detect outdated service banners visible from the internet | Public services | Banner-grab report and remediation notes | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-020 | Validate SSH exposure is restricted to approved IPs or VPN access | SSH services | ACL/firewall rules and scan evidence | 4 | 4 | High | Network Engineer | Monthly |
| ESA-021 | Confirm database services are not directly exposed to the internet | SQL / database ports | Scan showing database ports closed or restricted | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-022 | Review high-risk administrative ports for exposure | Admin interfaces | Scan and firewall rule comparison | 5 | 4 | Critical | Cybersecurity Administrator | Monthly |
| ESA-023 | Validate UDP services do not expose amplification or discovery risks | UDP services | UDP scan and DDoS reflection risk review | 4 | 3 | Medium | Network Engineer | Quarterly |
| ESA-024 | Document exceptions for all externally exposed non-standard ports | External services | Exception register with owner, expiration date, and compensating controls | 4 | 3 | Medium | CISO / IT Manager | Monthly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-025 | Review inbound firewall policies for least privilege | Firewall rules | Firewall rule export and review notes | 5 | 5 | Critical | Network Engineer | Monthly |
| ESA-026 | Review outbound firewall policies for unnecessary external communication | Firewall rules | Outbound policy review and business justification | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-027 | Validate NAT rules are documented and mapped to business services | NAT policies | NAT table with destination, owner, and purpose | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-028 | Identify unused firewall rules and stale NAT entries | Firewall rules / NAT | Hit-count report and change plan | 4 | 4 | High | Network Engineer | Monthly |
| ESA-029 | Confirm temporary firewall exceptions have expiration dates | Firewall exceptions | Exception register with expiration and approval | 4 | 3 | Medium | IT Manager | Monthly |
| ESA-030 | Validate source restrictions for admin and vendor access rules | Firewall ACLs | ACL configuration showing approved source IPs | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-031 | Review any-to-any or overly broad firewall rules | Firewall rules | Rulebase review showing broad access removal plan | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-032 | Verify firewall management interfaces are not publicly reachable | Firewall admin interfaces | External scan and management plane ACL evidence | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-033 | Confirm firewall rule changes follow approval workflow | Change management | Change tickets and approval records | 4 | 3 | Medium | IT Manager | Monthly |
| ESA-034 | Review firewall security profiles for inbound traffic | Firewall UTM services | IPS/AV/URL filtering profile assignments | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-035 | Validate logging is enabled for critical firewall rules | Firewall logs | Log configuration and SIEM ingestion evidence | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-036 | Review firewall firmware and security patch status | Firewall hardware | Vendor advisory check and patch record | 5 | 3 | High | Network Engineer | Monthly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-037 | Validate DMZ servers are segmented from internal networks | DMZ | Network diagram and firewall policy validation | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-038 | Review DMZ-to-internal firewall rules for least privilege | DMZ / internal zones | Rule review showing specific destination and service access | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-039 | Confirm public web, mail, and application servers are placed in appropriate zones | DMZ architecture | Network diagram and server placement review | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-040 | Verify DMZ hosts cannot initiate broad access to internal systems | DMZ outbound controls | Firewall rules and traffic test evidence | 5 | 4 | Critical | Cybersecurity Administrator | Quarterly |
| ESA-041 | Review IDS/IPS coverage for DMZ inbound and outbound traffic | DMZ monitoring | IDS/IPS sensor placement and alert test evidence | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-042 | Validate DMZ servers are hardened and patched | DMZ servers | Patch report and hardening checklist | 5 | 4 | Critical | Systems Administrator | Monthly |
| ESA-043 | Confirm management access to DMZ systems uses secure jump host or VPN | DMZ admin access | Access path diagram and authentication evidence | 4 | 3 | Medium | Network Engineer | Quarterly |
| ESA-044 | Verify DMZ logging is forwarded to centralized monitoring | DMZ logging | SIEM log source list and sample events | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-045 | Review DMZ DNS, mail, reverse proxy, and web server exposure | DMZ services | Scan and service inventory | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-046 | Confirm DMZ backup and recovery procedures are documented | DMZ recovery | Backup policy and recovery test record | 3 | 3 | Medium | IT Manager | Annually |
| ESA-047 | Validate no production database is directly reachable from the DMZ | DMZ / databases | Firewall path analysis and scan evidence | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-048 | Review segmentation after network or firewall changes | DMZ change review | Post-change validation report | 5 | 3 | High | Network Engineer | After change |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-049 | Inventory all user VPN portals and remote access gateways | VPN / remote access | VPN inventory with URL/IP and owner | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-050 | Verify MFA is enforced for all user VPN access | User VPN | VPN authentication policy screenshot or config | 5 | 5 | Critical | Cybersecurity Administrator | Monthly |
| ESA-051 | Review VPN encryption protocols and cipher strength | VPN crypto | VPN config showing approved encryption and hashing | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-052 | Disable weak VPN protocols and legacy authentication methods | VPN security | Config review showing legacy methods disabled | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-053 | Review split tunneling configuration and business justification | User VPN | VPN profile policy and risk approval | 4 | 3 | Medium | IT Manager | Quarterly |
| ESA-054 | Validate VPN user access follows least privilege network segmentation | User VPN ACLs | VPN group-to-network mapping | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-055 | Review VPN failed login logs for brute-force activity | VPN logs | Authentication log review and alert evidence | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-056 | Confirm inactive VPN accounts are disabled promptly | User VPN accounts | Account review report | 4 | 4 | High | Systems Administrator | Monthly |
| ESA-057 | Validate VPN portal is protected by rate limiting or lockout controls | VPN portal | Policy configuration and test evidence | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-058 | Review remote access certificates and expiration dates | VPN certificates | Certificate inventory and renewal schedule | 4 | 3 | Medium | Network Engineer | Monthly |
| ESA-059 | Confirm remote access vendors use named accounts and MFA | Vendor VPN | Vendor access list and MFA evidence | 5 | 4 | Critical | IT Manager | Monthly |
| ESA-060 | Test VPN exposure for known vulnerabilities | VPN gateway | External vulnerability scan against VPN endpoints | 5 | 4 | Critical | Cybersecurity Administrator | Monthly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-061 | Inventory all site-to-site VPN tunnels and peer IPs | S2S VPN | Tunnel inventory with owners and purpose | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-062 | Validate site-to-site VPN encryption settings meet current standards | S2S VPN crypto | IKE/IPsec configuration review | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-063 | Review allowed subnets across each site-to-site tunnel | S2S VPN routes | Encryption domain or proxy-ID review | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-064 | Remove stale or unused VPN tunnels | S2S VPN | Tunnel activity and business owner validation | 4 | 3 | Medium | Network Engineer | Quarterly |
| ESA-065 | Confirm vendor tunnels are limited to required systems and ports | Vendor VPN | ACL and route restriction review | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-066 | Review tunnel logging and alerts for outages or abnormal traffic | S2S VPN monitoring | Firewall logs and alert configuration | 3 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-067 | Validate peer devices and endpoints are known and approved | VPN peers | Approved vendor/site details and contact information | 4 | 3 | Medium | IT Manager | Quarterly |
| ESA-068 | Review pre-shared keys or certificates for rotation requirements | VPN credentials | Key/certificate rotation log | 4 | 3 | Medium | Network Engineer | Semi-annually |
| ESA-069 | Verify vendor offboarding includes tunnel removal | Vendor VPN offboarding | Offboarding checklist and firewall change record | 5 | 3 | High | IT Manager | After vendor termination |
| ESA-070 | Confirm high-risk vendor access is monitored by SIEM/SOC | Vendor traffic | SIEM rules and sample alert evidence | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-071 | Review business continuity dependencies for critical VPN tunnels | Critical tunnels | Dependency matrix and failover plan | 3 | 3 | Medium | IT Manager | Annually |
| ESA-072 | Validate no broad internal network access is allowed through vendor tunnels | Vendor VPN segmentation | Tunnel ACL and route review | 5 | 4 | Critical | Network Engineer | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-073 | Inventory all public websites and web applications | Web applications | Application inventory with owner and hosting location | 4 | 4 | High | IT Manager | Quarterly |
| ESA-074 | Test web applications for OWASP Top 10 risks | Web applications | Web vulnerability scan or penetration test report | 5 | 4 | Critical | Cybersecurity Administrator | Quarterly |
| ESA-075 | Check for SQL injection vulnerabilities | Web applications | DAST or manual test evidence | 5 | 4 | Critical | Cybersecurity Administrator | Quarterly |
| ESA-076 | Check for cross-site scripting vulnerabilities | Web applications | DAST or manual test evidence | 4 | 4 | High | Cybersecurity Administrator | Quarterly |
| ESA-077 | Review authentication and session management controls | Web applications | Login/session control review | 5 | 4 | Critical | Cybersecurity Administrator | Quarterly |
| ESA-078 | Verify admin portals are restricted and protected by MFA | Admin portals | Access restriction and MFA evidence | 5 | 4 | Critical | Network Engineer | Monthly |
| ESA-079 | Review web server headers for security hardening | Web servers | Header test report for HSTS, CSP, X-Frame-Options, etc. | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-080 | Confirm directory browsing is disabled | Web servers | Web server configuration and test evidence | 4 | 3 | Medium | Systems Administrator | Quarterly |
| ESA-081 | Review error messages for information disclosure | Web applications | Application testing notes | 3 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-082 | Validate web application firewall deployment and policies | WAF | WAF policy, mode, and tuning review | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-083 | Confirm web applications are patched and supported | Web platforms | Patch report and application version inventory | 5 | 4 | Critical | Systems Administrator | Monthly |
| ESA-084 | Review file upload functionality for malware and content controls | Web applications | Upload control test evidence | 5 | 3 | High | Cybersecurity Administrator | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-085 | Inventory all public SSL/TLS certificates | Certificates | Certificate inventory with expiration and owner | 4 | 4 | High | Network Engineer | Monthly |
| ESA-086 | Validate certificate expiration monitoring is enabled | Certificates | Monitoring alert evidence | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-087 | Check SSL/TLS configuration for weak protocols | TLS services | SSL test report showing TLS 1.0/1.1 disabled | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-088 | Disable weak ciphers and insecure key exchange methods | TLS configuration | SSL scan report and configuration evidence | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-089 | Verify certificates match expected hostnames | Certificates | Certificate SAN/CN review | 4 | 3 | Medium | Network Engineer | Monthly |
| ESA-090 | Review public certificates for unintended host exposure | Certificate transparency | CT log review | 3 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-091 | Validate HSTS is enabled for appropriate public web services | Web TLS | Header scan and web server config | 3 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-092 | Confirm API endpoints enforce HTTPS only | APIs / cloud endpoints | API endpoint testing and redirect config | 4 | 4 | High | Cloud Engineer | Quarterly |
| ESA-093 | Review VPN certificates and revocation procedures | VPN certificates | Certificate lifecycle documentation | 4 | 3 | Medium | Network Engineer | Quarterly |
| ESA-094 | Verify email encryption in transit where applicable | Email TLS | Mail TLS test and policy evidence | 3 | 3 | Medium | Email Administrator | Quarterly |
| ESA-095 | Check certificate private key storage and access controls | Certificates | Key management policy and access review | 4 | 3 | Medium | IT Manager | Semi-annually |
| ESA-096 | Validate expired or unused certificates are removed from services | Certificates | Service certificate cleanup report | 3 | 3 | Medium | Systems Administrator | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-097 | Inventory externally accessible cloud services | Cloud / SaaS | Cloud asset inventory and public endpoint list | 4 | 4 | High | Cloud Engineer | Quarterly |
| ESA-098 | Review public cloud storage for unintended exposure | Cloud storage | Storage access review report | 5 | 4 | Critical | Cloud Engineer | Monthly |
| ESA-099 | Verify MFA is enforced for cloud administrator accounts | Cloud identity | Conditional access or IAM policy evidence | 5 | 5 | Critical | Cloud Engineer | Monthly |
| ESA-100 | Review public APIs for authentication and authorization controls | Cloud APIs | API gateway or IAM policy review | 5 | 4 | Critical | Cloud Engineer | Quarterly |
| ESA-101 | Validate cloud security alerts are enabled for external exposure | Cloud monitoring | Alert policy and sample alert evidence | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-102 | Review internet-facing cloud load balancers and listeners | Cloud networking | Load balancer listener and security group review | 4 | 4 | High | Cloud Engineer | Quarterly |
| ESA-103 | Confirm security groups and network ACLs follow least privilege | Cloud firewalling | Security group review report | 5 | 4 | Critical | Cloud Engineer | Monthly |
| ESA-104 | Check cloud admin portals for risky external access paths | Cloud admin | Identity and conditional access policy review | 5 | 4 | Critical | Cloud Engineer | Monthly |
| ESA-105 | Review SaaS third-party app consent and integrations | SaaS apps | OAuth/app consent review | 4 | 4 | High | Cloud Engineer | Quarterly |
| ESA-106 | Validate cloud data encryption at rest and in transit | Cloud data | Encryption policy/config evidence | 4 | 3 | Medium | Cloud Engineer | Quarterly |
| ESA-107 | Review exposed cloud databases or managed services | Cloud databases | Public access and firewall rule review | 5 | 4 | Critical | Cloud Engineer | Monthly |
| ESA-108 | Confirm cloud configurations are reviewed after major changes | Cloud change management | Post-change security review record | 4 | 3 | Medium | Cloud Engineer | After change |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-109 | Inventory all domains and registrars used by the organization | Domains | Domain inventory with registrar and owner | 4 | 3 | Medium | IT Manager | Quarterly |
| ESA-110 | Verify registrar accounts use MFA | Registrar security | Registrar account security screenshot or policy | 5 | 4 | Critical | IT Manager | Quarterly |
| ESA-111 | Enable registrar lock or domain transfer protection | Domains | Registrar lock evidence | 5 | 3 | High | IT Manager | Quarterly |
| ESA-112 | Review DNS zone permissions and administrator access | DNS management | DNS provider access review | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-113 | Validate DNSSEC implementation where appropriate | DNSSEC | DNSSEC validation evidence or documented exception | 3 | 3 | Medium | Network Engineer | Annually |
| ESA-114 | Review public DNS records for unnecessary exposure | DNS records | DNS export and service ownership review | 4 | 4 | High | Network Engineer | Quarterly |
| ESA-115 | Identify dangling DNS records and takeover risks | DNS / cloud | Dangling record scan and remediation evidence | 5 | 4 | Critical | Cybersecurity Administrator | Quarterly |
| ESA-116 | Monitor domain spoofing and typosquatting risks | Domain protection | Lookalike domain monitoring report | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-117 | Review DNS logs for unusual activity where logging is available | DNS logs | DNS provider logs or SIEM evidence | 3 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-118 | Confirm DNS changes follow change management | DNS change control | DNS change ticket records | 4 | 3 | Medium | IT Manager | Monthly |
| ESA-119 | Validate DNS records for email authentication are correct | DNS email records | SPF, DKIM, and DMARC record review | 5 | 4 | Critical | Email Administrator | Monthly |
| ESA-120 | Document emergency domain recovery contacts and procedures | Registrar recovery | Domain recovery procedure and contacts | 4 | 3 | Medium | IT Manager | Annually |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-121 | Validate SPF record is configured and not overly permissive | SPF | SPF DNS record review | 5 | 4 | Critical | Email Administrator | Monthly |
| ESA-122 | Validate DKIM signing is enabled for all approved email platforms | DKIM | DKIM selector and signing verification | 5 | 4 | Critical | Email Administrator | Monthly |
| ESA-123 | Validate DMARC policy is configured and aligned | DMARC | DMARC record and aggregate report review | 5 | 4 | Critical | Email Administrator | Monthly |
| ESA-124 | Progress DMARC policy toward quarantine or reject where appropriate | DMARC enforcement | DMARC policy roadmap and monitoring data | 5 | 3 | High | CISO / Email Administrator | Quarterly |
| ESA-125 | Review MX records and mail gateways for approved configuration | Email DNS | MX record and gateway review | 4 | 3 | Medium | Email Administrator | Quarterly |
| ESA-126 | Test for open relay vulnerabilities | Mail servers | Open relay test result | 5 | 4 | Critical | Email Administrator | Quarterly |
| ESA-127 | Review anti-phishing and anti-malware policies | Email security | Mail protection policy review | 5 | 4 | Critical | Email Administrator | Monthly |
| ESA-128 | Confirm attachment sandboxing is enabled where available | Email security | Sandbox policy evidence | 4 | 3 | Medium | Email Administrator | Quarterly |
| ESA-129 | Review mail forwarding rules for suspicious external forwarding | Email accounts | Forwarding rule audit report | 4 | 4 | High | Email Administrator | Monthly |
| ESA-130 | Validate inbound and outbound email logs are monitored | Email logs | Log source and alert evidence | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-131 | Review domain impersonation and spoofing protection settings | Email/domain security | Impersonation protection policy review | 4 | 4 | High | Email Administrator | Quarterly |
| ESA-132 | Validate user phishing reporting process is documented | Email incident process | Phishing reporting workflow and escalation evidence | 3 | 3 | Medium | IT Manager | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-133 | Verify MFA is enforced for all external access paths | External identity | Conditional access/VPN/SaaS MFA evidence | 5 | 5 | Critical | Cybersecurity Administrator | Monthly |
| ESA-134 | Review privileged accounts with external access | Privileged access | Admin account access review | 5 | 4 | Critical | CISO / IT Manager | Monthly |
| ESA-135 | Disable inactive external accounts | External accounts | Account inactivity report | 4 | 4 | High | Systems Administrator | Monthly |
| ESA-136 | Review guest and temporary accounts | Guest accounts | Guest access report and expiration review | 4 | 3 | Medium | Systems Administrator | Monthly |
| ESA-137 | Validate password policies for external-facing authentication | Identity policies | Password and lockout policy review | 4 | 3 | Medium | Systems Administrator | Quarterly |
| ESA-138 | Review anomalous external login alerts | Identity logs | Sign-in risk alert report | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-139 | Rotate API keys and secrets exposed to external services | API/secrets | Key rotation evidence | 5 | 3 | High | Cloud Engineer | Quarterly |
| ESA-140 | Confirm least privilege for externally accessible admin portals | Admin access | Role assignment and access review | 5 | 4 | Critical | IT Manager | Quarterly |
| ESA-141 | Remove external access promptly during offboarding | Identity lifecycle | Offboarding evidence and access removal log | 5 | 4 | Critical | IT Manager | Monthly |
| ESA-142 | Review service accounts used by internet-facing systems | Service accounts | Service account inventory and permissions review | 4 | 4 | High | Systems Administrator | Quarterly |
| ESA-143 | Validate secure authentication for partner and vendor portals | Vendor identity | MFA and access policy evidence | 5 | 4 | Critical | IT Manager | Quarterly |
| ESA-144 | Document emergency access accounts and monitoring | Break-glass accounts | Break-glass procedure and alerting evidence | 4 | 3 | Medium | CISO / IT Manager | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-145 | Run authenticated or unauthenticated external vulnerability scans as appropriate | External scanning | Vulnerability scan report | 5 | 5 | Critical | Cybersecurity Administrator | Monthly |
| ESA-146 | Validate critical and high findings are remediated within policy | Vulnerabilities | Remediation tracking report | 5 | 5 | Critical | IT Manager | Monthly |
| ESA-147 | Document accepted risks and remediation exceptions | Risk exceptions | Exception register with approval and expiration | 4 | 3 | Medium | CISO | Monthly |
| ESA-148 | Conduct external penetration testing for high-risk systems | Pen testing | External penetration test report | 5 | 4 | Critical | CISO / Auditor | Annually |
| ESA-149 | Retest remediated high-risk findings | Retesting | Retest report showing resolved findings | 5 | 4 | Critical | Cybersecurity Administrator | After remediation |
| ESA-150 | Test internet-facing systems against newly disclosed vulnerabilities | Threat-driven testing | Vendor advisory and scan validation | 5 | 4 | Critical | Cybersecurity Administrator | As needed |
| ESA-151 | Review scanner coverage for all public assets | Scan coverage | Asset inventory compared to scan scope | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-152 | Validate scan results are reported to management | Reporting | Management summary and remediation status | 3 | 3 | Medium | IT Manager | Monthly |
| ESA-153 | Integrate vulnerability findings into risk management | Risk management | Risk register entries mapped to findings | 4 | 3 | Medium | CISO | Monthly |
| ESA-154 | Review false positives with technical evidence | Vulnerability validation | Validation notes and supporting evidence | 3 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-155 | Scan web applications with appropriate depth and safe settings | Web scanning | DAST scope and scan configuration | 4 | 4 | High | Cybersecurity Administrator | Quarterly |
| ESA-156 | Review external attack surface changes since last scan | Exposure changes | Delta report and change tickets | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-157 | Enable logging for internet-facing firewall rules | Firewall logs | Firewall log configuration and sample entries | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-158 | Forward perimeter logs to SIEM or centralized logging | SIEM | Log source onboarding evidence | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-159 | Monitor for external reconnaissance and scanning activity | Threat detection | SIEM alert or IDS/IPS report | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-160 | Configure alerts for VPN brute-force attempts | VPN monitoring | Alert rule and sample alert evidence | 4 | 4 | High | Cybersecurity Administrator | Monthly |
| ESA-161 | Configure alerts for firewall policy violations | Firewall monitoring | Alert rule evidence | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-162 | Review IDS/IPS signatures and update status | IDS/IPS | Signature update report | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-163 | Monitor external cloud admin sign-ins | Cloud identity logs | Cloud sign-in reports and alerts | 4 | 4 | High | Cloud Engineer | Monthly |
| ESA-164 | Track indicators of compromise related to public assets | IOC monitoring | Threat intelligence and SIEM correlation evidence | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-165 | Review dark web or credential exposure related to business domains | Credential exposure | Exposure monitoring report | 4 | 3 | Medium | Cybersecurity Administrator | Quarterly |
| ESA-166 | Verify alert escalation procedures for external threats | SOC process | Escalation workflow and contact list | 3 | 3 | Medium | IT Manager | Quarterly |
| ESA-167 | Review DDoS detection and mitigation monitoring | DDoS monitoring | DDoS provider or firewall monitoring evidence | 4 | 3 | Medium | Network Engineer | Quarterly |
| ESA-168 | Document external security metrics for leadership reporting | Security metrics | Monthly dashboard with exposure, findings, and remediation | 3 | 3 | Medium | CISO | Monthly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-169 | Map external assets to applicable compliance requirements | Compliance scope | Control mapping for HIPAA, PCI DSS, NIST, SOC 2, etc. | 4 | 3 | Medium | CISO / Compliance Officer | Annually |
| ESA-170 | Maintain evidence for external security controls | Compliance evidence | Audit evidence repository | 4 | 3 | Medium | Compliance Officer | Quarterly |
| ESA-171 | Review external audit results with leadership | Governance | Executive summary and meeting notes | 3 | 3 | Medium | CISO | Quarterly |
| ESA-172 | Update policies to reflect external access controls | Policies | Approved policy updates | 3 | 3 | Medium | CISO / IT Manager | Annually |
| ESA-173 | Review vendor security clauses for external access | Vendor governance | Contract language and security requirements | 4 | 3 | Medium | Compliance Officer | Annually |
| ESA-174 | Ensure cyber insurance requirements are addressed for external systems | Cyber insurance | Insurance questionnaire evidence | 4 | 3 | Medium | CISO / IT Manager | Annually |
| ESA-175 | Track remediation progress for external findings | Remediation governance | Remediation tracker with owners and dates | 4 | 4 | High | IT Manager | Monthly |
| ESA-176 | Review high-risk findings through risk acceptance process | Risk management | Risk acceptance document with expiration | 5 | 3 | High | CISO | Monthly |
| ESA-177 | Document external audit methodology and scope | Audit governance | Audit plan and methodology document | 3 | 3 | Medium | Auditor | Annually |
| ESA-178 | Validate third-party assessment results are reviewed | Third-party reports | Vendor pen test or SOC report review notes | 4 | 3 | Medium | Compliance Officer | Annually |
| ESA-179 | Maintain external security standard baseline | Security baseline | Approved baseline for firewall, VPN, DNS, email, cloud | 4 | 3 | Medium | CISO | Annually |
| ESA-180 | Review compliance gaps resulting from external exposure | Compliance gaps | Gap report and remediation plan | 4 | 3 | Medium | Compliance Officer | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-181 | Inventory vendors with external network or application access | Vendor access | Vendor access inventory | 4 | 4 | High | IT Manager | Quarterly |
| ESA-182 | Review vendor access approvals and business justification | Vendor access | Access approval records | 4 | 3 | Medium | IT Manager | Quarterly |
| ESA-183 | Validate vendor MFA and named user requirements | Vendor identity | Vendor account review and MFA evidence | 5 | 4 | Critical | IT Manager | Quarterly |
| ESA-184 | Restrict vendor access by IP, time, service, and destination where possible | Vendor access controls | Firewall/VPN access rules | 5 | 4 | Critical | Network Engineer | Quarterly |
| ESA-185 | Review third-party APIs exposed to or from the organization | Third-party APIs | API integration inventory and security review | 4 | 4 | High | Cloud Engineer | Quarterly |
| ESA-186 | Validate vendor data exchange uses encryption | Vendor data exchange | TLS/SFTP/API encryption evidence | 4 | 3 | Medium | IT Manager | Quarterly |
| ESA-187 | Confirm vendor offboarding removes accounts, VPNs, and firewall rules | Vendor offboarding | Offboarding checklist and change tickets | 5 | 4 | Critical | IT Manager | After vendor termination |
| ESA-188 | Review vendor incident notification procedures | Vendor incident response | Contract or security addendum review | 4 | 3 | Medium | Compliance Officer | Annually |
| ESA-189 | Assess vendor external vulnerabilities where contractually permitted | Vendor risk | Vendor security assessment or attestation | 4 | 3 | Medium | Compliance Officer | Annually |
| ESA-190 | Monitor third-party integrations for abnormal activity | Vendor monitoring | Logs and anomaly alerts | 4 | 3 | Medium | Cybersecurity Administrator | Monthly |
| ESA-191 | Document supply-chain risks related to critical external services | Supply chain | Risk register entries | 4 | 3 | Medium | CISO | Quarterly |
| ESA-192 | Review shared credentials or generic vendor accounts and remove them | Vendor accounts | Account review showing named accounts only | 5 | 4 | Critical | Systems Administrator | Quarterly |
| ID | Checklist Item | Asset / Scope | Evidence / Method | Impact | Likelihood | Risk | Owner | Frequency |
|---|---|---|---|---|---|---|---|---|
| ESA-193 | Ensure incident response plan covers external attacks | Incident response | IR plan section for external compromise | 4 | 3 | Medium | CISO | Annually |
| ESA-194 | Define escalation path for public-facing security incidents | Incident escalation | Escalation matrix and contact list | 4 | 3 | Medium | IT Manager | Quarterly |
| ESA-195 | Document process for isolating compromised public systems | Containment | Containment playbook | 5 | 3 | High | Cybersecurity Administrator | Annually |
| ESA-196 | Validate evidence preservation for external incidents | Forensics | Evidence handling procedure | 4 | 3 | Medium | Cybersecurity Administrator | Annually |
| ESA-197 | Test response to exposed credential or VPN compromise | IR drill | Tabletop exercise report | 5 | 3 | High | CISO | Annually |
| ESA-198 | Test response to compromised web application or portal | IR drill | Tabletop or technical drill evidence | 5 | 3 | High | CISO | Annually |
| ESA-199 | Review backup and restoration readiness for public-facing systems | Recovery | Backup test results | 4 | 3 | Medium | IT Manager | Semi-annually |
| ESA-200 | Validate communication plan for customer-impacting external incidents | Communications | Incident communication plan | 4 | 3 | Medium | CISO / Compliance Officer | Annually |
These tools are for initial guidance only and do not replace a professional cybersecurity audit, compliance assessment, penetration test, or legal/compliance review.
External exposure affects every industry differently, but most organizations need protection for remote access, email, public websites, vendor connections, cloud services, and sensitive data workflows.
Healthcare clinics and dental offices often need external security evidence to support HIPAA security readiness, secure remote access, email protection, and ePHI safeguards. CPA firms and tax preparers often need stronger internet-facing controls for IRS WISP compliance, client data protection, portals, and email security.
Law firms, real estate companies, nonprofits, manufacturers, construction companies, engineering firms, and professional services firms often need external vulnerability validation, firewall review, VPN security, cyber insurance evidence, and cyber insurance readiness.
OC Security Audit identifies exposure and prioritizes remediation. When the work requires firewall changes, VPN hardening, patching, endpoint fixes, Microsoft 365 or Azure configuration, backup improvements, or ongoing IT operations, ITPerfection can help implement and operate the related technology.
Help with firewall rule cleanup, VPN coordination, network segmentation, secure remote access, and ongoing infrastructure support.
Support for endpoint health, patch follow-through, monitoring, maintenance, and practical remediation after the security review.
Support for Azure, Microsoft 365, backup and disaster recovery, help desk, co-managed IT, and ongoing operational improvements.
OC Security Audit is led by Ali Hassani, CISO, with 25+ years of real-world IT, cybersecurity, compliance, network security, Microsoft infrastructure, firewall, cloud, and infrastructure experience.
An External Security Audit typically includes public IP review, port scanning, firewall exposure analysis, VPN and remote access review, web application testing, DNS and email security review, cloud endpoint assessment, vulnerability scanning, risk rating, and remediation recommendations.
Yes. OC Security Audit reviews firewall rules, NAT policies, exposed services, VPN portals, MFA, encryption, authentication controls, logging, and remote access risk.
No. An external security audit may include validation and vulnerability testing, but it is focused on business exposure, control gaps, evidence, remediation priorities, and security readiness. A penetration test is usually a more aggressive exploitation-focused engagement with a specific scope.
Yes. External audit evidence can help support HIPAA, PCI DSS, SOC 2, NIST, cyber insurance, vendor due diligence, customer security reviews, and executive risk management.
OC Security Audit can review your internet-facing systems, prioritize external risks, and help your team plan practical remediation.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.