Currently it is a relevant and public domain topic to companies, the serie of worldwide computer attacks against them which have impacted by theft of information and affected company's image. At this context, companies should implement actions to build their technological platform up. Among the strategies for this implementation are detection and analysis of possible vulnerabilities of information system. Several worldwide establishments have formulated initiatives such as guides and methodologies which establish guidelines for a methodical application of security tests; in this way, any company could have a course of action through validation of its exposure level of information assets. The objective of this paper is to present a security evaluation scheme which can be applied by small and medium companies. This is proposed from reviewing of security-analysis area references; the steps, techniques and tools are presented too. Then, the scheme is applied to an accounting advisory company and the obtained results are presented and discussed.