We review the complete IT infrastructure, networking, business applications, data security and controls. The primary focus is to protect information assets in line with business risks, using comprehensive audit checklists and necessary audit tools, executed by specially trained (DISA-qualified) professionals.