|
Health Check
Security Health Check
Do you have an overall view of how effectively your security plan is working? Are
the right IT security controls in place to protect the information that is critical to
the your business? Controls must cover all aspects of your business, including mechanisms
used by hardware and software systems, networks, databases, human resource systems. SSG's
Security Health Check review will identify both strengths and weaknesses in your organization's
IT security controls. When you are aware of the business exposures resulting from inadequate
security controls, you can begin to implement improved controls and also establish the
processes that are required to ensure that the controls are effective.
SSG security consultants will conduct interviews with key managers and staff members
in your organization to understand what security controls are in place in the following
ten management areas: policy, organization, personnel, physical controls, asset
classification and control, system access control, network and computer management,
business continuity, application development and maintenance, and compliance.
This controls assessment, at any given location, is designed to take approximately
two weeks to assess more than seventy-five management controls within the above ten areas.
The breadth of the assessment can be corporate-wide, site by site, or for individual business
units within your organization. Whatever scope you select, the results will provide you with
business oriented recommendations for meeting your organization's security objectives with a
repeatable assessment methodology.
|
Range of Services
- a review of your organization's IT security controls across the ten management areas:
- policy
- organization
- personnel
- physical controls
- asset classification and control
- system access control
- network and computer management
- business continuity
- application development and maintenance
- compliance
- an analysis of the information gathered against a standards-based model of
"best practices" for commercial environments
- a final report of the strengths and weaknesses found, along with recommendations for
actions that could improve your security program and reduce risks to an acceptable level
|