Internal service catalog

NSO Service Catalog

What our team delivers, who runs it, and how to engage. Use this as the service-desk reference when a client or internal team asks "do we do that?" Operational procedures live in the Operations document.

Network Services

Discovery, mapping, and evaluation of client network estates.

Network mapping

Asset discovery, topology and port/service enumeration for an in-scope network.

Owner
Onboarding engineers, assessment leads.
SLA
5 business days from kickoff.

Network evaluations

Segmentation review, firewall/ACL audit and traffic baselining.

Owner
Senior network engineer + security analyst.
SLA
10 business days.

Wireless survey & rogue-AP detection

Active site survey, rogue identification, encryption review.

Owner
Field engineer.
SLA
Scheduled on-site.

DNS / DHCP / NTP health checks

Recursive resolver health, DHCP scope review, time drift.

Owner
MSP tier-2.
SLA
2 business days.

Security Assessments

Active scanning and testing across the attack surface.

External attack-surface scanning

Edge Scan + Nuclei + ZAP against public assets.

Owner
Assessment team.
SLA
Continuous (hourly drift) + monthly summary.
Open Scans

Internal vulnerability scanning

Nmap + Nuclei via a registered worker on the client network.

Owner
Assessment team.
SLA
Quarterly or on-demand.
Open Workers

Web application testing

Authenticated + unauthenticated DAST with session injection.

Owner
AppSec lead.
SLA
10 business days.

Container & IaC scanning

Trivy-based scans of images and Terraform/K8s manifests.

Owner
DevSecOps.
SLA
Per build (CI) or on-demand.

Cloud posture review

AWS/Azure/GCP misconfig and IAM review.

Owner
Cloud security engineer.
SLA
10 business days.

Identity & Access

Identity hygiene, MFA, and credential lifecycle.

MFA rollout & enforcement

Plan, pilot and enforce MFA across the client tenant.

Owner
MSP lead.
SLA
Phased over 4 weeks.
Security settings

Role/permission reviews

Audit of effective roles vs least-privilege baseline.

Owner
Security analyst.
SLA
Quarterly.

Service-account hygiene & secret rotation

Inventory, rotate, and document non-human identities.

Owner
DevSecOps.
SLA
Quarterly.

Managed Support (MSP)

Ongoing managed services delivered by the MSP team.

24/7 monitoring & alert triage

SOC-style monitoring of NSO findings and infra alerts.

Owner
MSP tier-1/2.
SLA
P1 acknowledged < 15 min, 24x7.

Patch & vulnerability management

Triage NSO findings, schedule remediation, verify fixes.

Owner
MSP tier-2.
SLA
Critical < 7d, High < 30d.
Vulnerabilities

Backup verification & DR drills

Backup integrity tests and tabletop DR exercises.

Owner
MSP + advisory.
SLA
Monthly verification, quarterly drills.

Endpoint management

EDR deployment, policy tuning, response.

Owner
MSP tier-2.
SLA
Continuous.

Incident response retainer

Pre-purchased IR hours with defined response SLAs.

Owner
IR lead.
SLA
On-call < 1 hour engage.

Advisory & Compliance

Policy, audit prep, and education.

Policy authoring & gap analysis

SOC 2 / ISO 27001 / HIPAA / PCI gap assessments and policy templates.

Owner
Advisory consultant.
SLA
4–6 weeks per framework.
Compliance

Tabletop exercises

Facilitated IR/BCP scenarios with written readout.

Owner
Advisory consultant.
SLA
Scheduled, 1 day each.

Security awareness training

Annual training + quarterly phishing simulations.

Owner
Advisory + MSP.
SLA
Annual + quarterly.

Onboarding & Lifecycle

Bringing clients in and out cleanly.

Client onboarding

Tenant provisioning, asset intake, scanner enrollment.

Owner
Onboarding engineer.
SLA
5 business days.
Assets

Asset intake & DNS verification assistance

Help clients publish required TXT records and verify ownership.

Owner
Onboarding engineer.
SLA
Same day support.

Offboarding & data return

Export findings, revoke access, return/destroy data.

Owner
MSP lead + DPO.
SLA
10 business days from notice.