Overview
Organisations are increasingly in need to benchmark their information security and risk management against accepted or best practice.
As a premier security consulting business, we are very proud to be members of the British Standards Institute’s (BSI) ISO 27001 Associate Consultants Network. This Network comprises organisations with trained and experienced resources who are able to demonstrate the necessary skills, focus and credentials in relation to the design and implementation of ISO 27001 -compliant Information Security Management Systems (“ISMS”).
This solution is designed to provide an independent evaluation of your existing ISMS, however formal or informal, through a gap analysis of your current security and risk management practices against the detailed controls specified in the internationally recognized security standard.
Key Features
• Identification of current areas of risk which, in our view, is unacceptably high. In this way, you will have input from an independent source with experience in this specialist area, to your internal risk assessment and cost benefit analysis
• Identification of gaps or weaknesses to your information security control environment, which will assist you in implementing focused enhancements
• Identification of possible opportunities for cost savings in relation for example, to telecommunication costs or unnecessarily laborious, security-related processes
• Avoidance of “false assurance” that may be present based on current assumptions that you make, in this way helping you reduce the risk of becoming an easy target
• Enhanced ability to protect your external connection points and reduce the likelihood and impact of unauthorised access / attacks and other malicious activity
• Identification of specific and measurable ways to assess the technology, connectivity and access risks arising from inside the business – i.e. via practical recommendations to assist you in controlling internal users’ behavior and other network traffic
• Evidence to regulatory bodies and other interested parties of management’s “due process”
• Easy to understand and use deliverable – through a categorization of our recommendations into quick wins, strategic programs, tactical issues and best practice areas
• Practical and prioritized recommendations which include descriptions of their nature, as well as rough estimates of likely costs to implement them.
|