E R T A

Information Technology Risk & Control Services

Information Technology Risk & Control Services

Information Technology Risk, Control and Assurance Services

IT Check – Information Technology Risk, Control and Assurance Assessment

We assess companies’ information technology infrastructure, corporate data assets and digital working environments from an independent risk, control and assurance perspective.

Today, a significant portion of companies’ financial processes, customer data, employee information and operational records are managed directly through information technology systems. Therefore, a control weakness within the IT environment is not merely a technical issue; it may also constitute an operational, financial, legal and reputational risk.

Erta IT Check is an independent IT risk, control and assurance service that assesses companies’ existing information technology infrastructure, data security controls and digital working environments in light of internationally recognized standards and good practices.

The purpose of the engagement is not to replace existing systems or promote the purchase of a particular technology product. The current environment is analyzed, the design and operating effectiveness of controls are assessed, identified risks are classified, and management is provided with an IT Risk and Control Report containing prioritized improvement recommendations.

Our Audit Methodology and Reference Frameworks

Depending on the nature of the control area being reviewed, IT Check assessments reference internationally recognized standards and good-practice frameworks.

  • CIS Controls v8: Critical security controls and technical security practices
  • ISO/IEC 27001:2022: Information security management systems and information security controls
  • COBIT: IT governance, control and risk management
  • NIST Cybersecurity Framework (CSF): Identification, protection, detection, response and recovery relating to cybersecurity risks
  • KVKK Technical Measures: Technical and organizational measures relating to the protection of personal data
  • NIST AI RMF and ISO/IEC 42001: Artificial intelligence use, governance and associated data security risks
  • CIS Benchmarks and cloud security good practices: Security configurations for Microsoft 365, Azure, AWS, Google Workspace and similar environments

Approach: These frameworks are not used for certification purposes. They are used to assess the existing control environment, identify control gaps and map findings to objective criteria.

How Is IT Check Performed?

1 Scope and Risk Profile

The scope of IT Check is determined by considering the company’s business activities, technology infrastructure, critical data assets and regulatory obligations.

2 Control Design

Policies, procedures, authorization models and technical security configurations are reviewed to determine whether they are appropriately designed to address the relevant risks.

3 Operating Effectiveness Testing

Controls are assessed not only to determine whether they exist on paper, but also whether they are operating effectively in practice.

4 Gap Analysis and Reporting

Control deficiencies are classified according to risk level and translated into a prioritized management action plan.

What Do We Review Within the Scope of IT Check?

1 IT Asset and Inventory Management Controls

Reference: CIS Controls | ISO/IEC 27001

Visibility over desktops, laptops, servers and related software assets used within the organization is assessed.

The review includes;

  • inventory of devices and hardware,
  • operating system and software distributions,
  • unauthorized or unmanaged software,
  • applications that may create security risks,
  • outdated or unmanaged systems,
  • license and usage visibility,
  • differences between formal IT inventory records and actual use

Objective: To enable management to reliably answer the question: “Which systems and software are running on our devices, and which of them are under our control?”

2 Data Loss Prevention and Data Security Controls – DLP Check

Reference: CIS Controls | ISO/IEC 27001

Risks relating to corporate data being transferred outside the organization by employees, applications or external devices are assessed.

The review particularly considers;

  • use of USB and external storage devices,
  • ability to copy files outside the organization,
  • uploading sensitive data through web applications,
  • data exfiltration via e-mail,
  • clipboard/copy-and-paste activities,
  • uncontrolled transfer of data to cloud storage,
  • uncontrolled transfer of corporate data outside the organization,
  • the scope and operating effectiveness of existing DLP policies

Data Security in the Use of Artificial Intelligence

As generative AI tools become increasingly integrated into business processes, employees may transfer internal documents, customer information, financial data, contracts, source code or other sensitive content to AI platforms, creating new data leakage risks. IT Check assesses these risks and the existing technical control mechanisms within the agreed scope and available technical visibility.

Objective: Not only to identify an actual data leakage incident, but to determine in advance through which channels data could leave the organization, including USB, e-mail, web applications, cloud services and artificial intelligence platforms.

3 KVKK and Sensitive Data Controls

Reference: KVKK Technical Measures | ISO/IEC 27001

Risks arising from sensitive or personal data stored without adequate controls on company devices, shared folders and other data environments within the agreed scope are assessed.

Examples include;

  • Turkish Republic identification numbers,
  • IBAN information,
  • credit card information,
  • passport information,
  • customer and employee personal data,
  • payroll and financial information,
  • contracts,
  • files containing usernames and passwords,
  • API keys, tokens and similar access credentials

This assessment supports the evaluation of the company’s existing technical and organizational measures under the Turkish Personal Data Protection Law (KVKK).

Objective: To identify where personal or critical data may exist without adequate controls and to assess the related access, sharing and data leakage risks.

4 Critical File Integrity and Unauthorized Access Controls

Reference: CIS Controls | ISO/IEC 27001

The protection level of critical corporate files and folders is assessed.

  • ability to make unauthorized changes to critical files,
  • deletion or modification of files,
  • users accessing information they should not be authorized to view,
  • ability to transfer critical files outside the organization,
  • whether file integrity is monitored,
  • authorization structures for critical shared locations

Critical data areas such as accounting, finance, human resources, customer data and management documents may be prioritized.

Objective: To determine who can view, modify, delete or transfer critical corporate data outside the organization.

5 Identity, Access and Privileged Account Management – IAM / PAM

Reference: CIS Controls | ISO/IEC 27001 | COBIT

One of the fundamental information security risks is users having broader access rights than required for their responsibilities.

Within the scope of IT Check;

  • administrator and privileged accounts,
  • user access levels,
  • high-privilege accounts such as Domain Admin / Global Admin,
  • shared accounts,
  • accounts belonging to former employees,
  • unused accounts,
  • MFA usage,
  • third-party access,
  • over-privileged users,
  • implementation of the Least Privilege principle

Objective: To answer the question: “Who has access to which system, with what level of authorization, and do they genuinely require that access?”

6 Microsoft 365 and Google Workspace Security Controls

Reference: CIS Benchmarks | ISO/IEC 27001

Security and sharing configurations within cloud-based working environments are assessed.

Within Microsoft 365 and Google Workspace environments;

  • accounts without MFA,
  • privileged/administrator accounts,
  • external sharing links,
  • anonymous or uncontrolled sharing capabilities,
  • incorrect file and folder sharing permissions,
  • third-party application and OAuth permissions,
  • unused or unmanaged user accounts,
  • over-privileged users,
  • baseline security policies and configurations

Objective: To identify open access, sharing and authorization risks that the company may have unintentionally created within its cloud working environment.

7 Cloud Infrastructure and SaaS Security Controls

Reference: ISO/IEC 27017 | CIS Cloud Benchmarks

Baseline security and access configurations of cloud services and SaaS applications used by the company are assessed.

Depending on the technology environment and level of access provided;

  • Microsoft Azure,
  • Amazon Web Services (AWS),
  • Google Cloud Platform (GCP),
  • Microsoft 365,
  • Google Workspace

and similar environments may be reviewed for publicly accessible data locations, internet-facing resources, over-privileged accounts, misconfigured access permissions, IAM configurations and in-scope API/service access rights.

Technical access: Assessments of cloud environments are performed through appropriate access provided by the client, read-only/audit permissions or relevant configuration exports.

Objective: To identify critical security risks arising from misconfigurations or unnecessarily broad access rights within cloud environments.

8 Artificial Intelligence Risk and Data Security Governance

Reference: NIST AI RMF | ISO/IEC 42001

The use of generative artificial intelligence is assessed not only from a technical data leakage perspective, but also from a corporate governance and control perspective.

The assessment may include;

  • whether a corporate artificial intelligence usage policy exists,
  • which AI services employees are permitted to use,
  • whether data categories that may or may not be transferred to AI platforms have been defined,
  • rules governing the protection of customer data, financial information, contracts and other critical content,
  • approved and uncontrolled AI usage channels,
  • existing technical blocking, filtering and monitoring mechanisms,
  • the extent to which roles, authorities and responsibilities for artificial intelligence use have been defined

Objective: Not to prevent the use of artificial intelligence, but to make visible and manageable which data is used with AI, under which rules, and subject to which control mechanisms.

IT Risk and Management Reporting

IT Check is not limited to technical findings. Findings identified during the engagement are assessed from a management perspective and classified according to the following risk levels:

Critical Risk
High Risk
Medium Risk
Low Risk
Improvement Area

The risk level is determined by considering both the likelihood of the finding and its potential impact on the organization.

For each finding, the report may include;

  • current state,
  • identified control weakness,
  • associated risk,
  • potential operational, financial, legal or reputational impacts,
  • relevant standard / control reference,
  • recommended control or improvement action,
  • priority level

This enables management to focus on an understandable action plan showing which risks matter, why they matter and which actions should be addressed first, rather than reviewing hundreds of technical data points.

Control Maturity Assessment

The main control areas reviewed under IT Check may also be assessed using a five-level control maturity model defined by Erta.

Level 1 – Initial
Controls are absent or are applied inconsistently and depend heavily on individuals.
Level 2 – Repeatable
Certain controls are implemented, but practices have not yet been standardized across the organization.
Level 3 – Defined
Controls are defined, documented and incorporated into organizational processes.
Level 4 – Managed
Controls are regularly monitored, measured and reviewed by management.
Level 5 – Optimized
Controls are managed through continuous improvement, automation and measurable risk management practices.

Note: The maturity assessment is not a certification result. It is a management indicator designed to help management understand the current control level and identify target areas for improvement.

What Does Management Receive?

  • the organization’s current IT Risk Profile,
  • Critical / High / Medium / Low risk classification,
  • Impact × Likelihood assessment,
  • a 1–5 Control Maturity Level for key control areas,
  • mapping of findings to relevant standards and control frameworks,
  • a prioritized remediation and action plan

Objective: To answer not only “What weaknesses do we have?” but also “Which of our risks matters most, why does it matter, and what should we address first?”

IT Check Is Not a Product Sale

The purpose of Erta IT Check is not to sell any particular software or technology product.

The purpose of the engagement is to assess the company’s existing information technology environment from an independent risk and control perspective, identify control weaknesses and potential risks, and develop practical recommendations to address those risks.

Where appropriate, various technical tools may be used for analysis, visibility, sampling and testing purposes.

The technology used is a measurement and analysis tool supporting the assessment; it is not the audit conclusion itself.

Regardless of the technical tools or technology providers used, the evaluation and classification of findings from a risk perspective and the preparation of the final IT Risk and Control Report are performed by Erta.

The Core Question Behind Erta IT Check

We do not assess a company’s information technology environment solely by asking whether its systems are operational.

Our core question is:

“If the company’s devices, data, users, cloud systems and digital working environments were independently assessed from a risk and control perspective today, what risks would be identified?”

With Erta IT Check, our objective is to identify, prioritize and make these risks manageable before an incident or data breach occurs.