Security Governance
Risk Assessment
Today's risk management has grown to include the
use of computers, networks, and the Internet. The backbone and beginning
point of risk management is a formal risk assessment. What is a
risk assessment? A successful risk assessment gathers data about
how Information Technology is addressed by your business. The goal
is to create a document or series of documents that establishes
baselines for the risks your organization faces, reviews the mechanisms
for managing, and creates mitigation or acceptance strategies for
these risks.
Business Continuity Assessment
A business continuity assessment reviews your existing
plan against a set of common baselines based on industry standard
best practices and regulatory guidance. We analyze every facet of
your operation, the threats against your business and the controls
already established. Once we have created a master catalog of these
factors, in-depth analysis is performed to determine existing risk
levels, mitigated risks and the residual risks your organization
faces. Detailed mitigation plans are developed and the results are
expressed in both technical detail and at a level suitable for executive
management.
Policy and Process Services
Our policy and process experts can help you build policy that increases your organization’s security awareness, and stresses the right security solution particular to your unique environment. Whether you’re aiming to match ISO 17799, HIPAA, GLBA, NCUA, Sarbanes-Oxley, or just want to meet security “best practices,” our policy services can be tailored to meet those requirements. Modified from the sensitive U.S. government methodology, we scale the needs of both small business and large enterprises with multiple business units, in order to provide you with the information security framework you need to answer the current challenges your organization faces - and the ability to develop and grow as your needs change.
Compliance Services
To successfully address security compliance is to
understand the purpose and spirit of the legislation, how auditors
may judge compliance, documenting security posture, performing a
“gap analysis” between that security posture and the
regulatory concern, and implementing a plan to compliance. We helped
many organizations from many different vertical markets comply with
the regulations such as the Graham-Leach-Bliley Act, NCUA Section
748, FFIEC Examinations, PCI Standards, HIPAA, and government policies
and standards.
|