|
|
|
|
|
|
|
Information Security Consultancy
|
|
|
- Governance Risk and Compliance (GRC)
- Information Security policies and procedures
- Information Security Law services
- Data security
- Data Leakage Prevention
Our information Security services are designed to assist you in achieving your objectives,
we operate a model that makes Information Security fit around your business model
thereby enabling you to grow your business whilst we make it secure for you. Our
approach is a very “can do” based and based on the ethos that there are a plethora
of solutions to a problem and we think outside the box in order to enable you to
achieve your business goal. We are very keen on re-usability as a means of reducing
the cost impact of
|
Governance, Risk Management, and Compliance or GRC is the broad term
used to describe how an organization approaches the key topics of:
- Governance (deals with
its policies& procedures and the dissemination to its staff and suppliers).
Our services can help you describe your overall management approach through which
your senior executives direct and control your entire organization, using a combination
of management information and hierarchical management control structures. We will
help you put in place activities to ensure that critical management information
reaching the executive team is sufficiently complete, accurate and timely to enable
appropriate management decision making. We also specialize in implementing the control
mechanisms to ensure your strategies, directions and instructions from your management
are carried out systematically and effectively. instruct us
- Risks (deals with the process of identifying
risks, mitigating and managing them). We provide you with the set of processes and
tools, through which your management can identify, analyze and as appropriate respond
appropriately to risks that might adversely affect your organization's business
objectives. We can help you determine your Risk appetite which will set the response
to risks typically depends on their perceived gravity, and also implement the controls,
avoiding options, mechanisms for accepting or transferring them to a third party.
We can cover Technological risks, commercial/Financial risks, Information security
risks, and Legal and Regulatory compliance risks as part of your GRC. instruct us
- Compliance – we can assist you in development
your corporate governance, enterprise risk management (ERM) and corporate compliance
with applicable laws and regulations. Our service will often include Audits and
gap analysis, you can instruct us prior to your External auditors visit or as part
of your standard operation. instruct us
|
Information Security Policies and procedures - one of the first and foremost
task or challenge an organisation faces is around Policies and procedures. You need
your policies and procedures to be in place as well as distributed amongst staff
and suppliers as frequently as they change, even if you are a small organisation.
You can instruct us to draft any
of your policies and procedures via the instruct
us
|
Information Security Law services - There are several legal requirements
you ought to have in place for business and you can instruct us to draft one for you. They include:
- Information Security schedule in all contracts – employee and supplier
- 3rd party agreements
- Outsourcing contracts terms
- Confidentiality agreements
- NON Disclosure Agreements
- Intellectual Property Rights terms in relation to employees or suppliers
- Compliance assessment on business operation
- Information sharing Agreements
- Contract review for validity and enforceability
- Investigating Breach of confidence
|
Data security – Our Data Security services can assist you to address the
following areas
- Disk encryption - refers to encryption technology that encrypts data on a
hard disk drive. We can implement these for your laptop, desktop and server estates.
The Disk encryption implementation can take form in either software or hardware
and also includes application encryption that application that extends outside your
organisation. instruct us
- Data Backup- policies and procedures including periodic testing. instruct us
- Data Masking – we can assist you in implementing the process of obscuring
(masking) specific data within a database table or cell to ensure that data security
is maintained and sensitive information is not exposed to unauthorized personnel.
For example, in outsourcing or sharing information with 3rd parties and suppliers
include masking the data from your supplier’s users (for example so banking customer
representatives can only see the last 4 digits of a customer’s national identity
number), developers (who need real production data to test new software releases
but should not be able to see sensitive financial data), outsourcing partners or
vendors outside the EEA. instruct us
|
|

|
|
|