Services:
 » Risk Management
 » IT Audit
 » Information Security and Assurance
 » IT Governance
 » Regulatory Compliance
 » Data Management
 » Business Continuity Management
 » Certification and Accreditation
 » Trainings and Workshops
 » Other IT Services
 
Nowadays there is a growing concern in the commercial sector after the collapse of Enron and other major corporate scandals in safeguarding their information systems. Over the next few years, as compliance with legislative requirements such as MiFID (Market in Financial Instrument Directive), Graham Leach Bliley, Clinger-Cohen and Sarbanes-Oxley increasingly demand for security programs that can demonstrate that private firms are exercising due diligence in conducting their business operations. This will, in return, lead to changes in terminologies and fine-tuning of process to more closely meet the needs of the commercial sector. Perhaps it will lead to even more streamlining and simplification of process and greater flexibility in how certification and accreditation is conducted.

Certification and Accreditation (C&A) is a comprehensive methodology, which consists of a number of individual processes. It is the combination of these related processes into one coherent risk management approach that gives C&A its real value. Although there are many wellknown approaches to implement a risk management program, still there is a dire need for a coherent methodology to manage risks at individual system level. To meet this requirement, the risk management approach would need to be integrated to provide for a consistent input and outputs from each process in the methodology at an enterprise level in a top to bottom approach. When certification and accreditation approach is tied along with risk management, it does create a pathway to success.

Businesses that need to minimize the security risks imposed to their information systems and to increase their client's trust on their businesses, can follow the C&A model provided by us to align their businesses with standards, legislations and directives. We help organisations in getting Certification and Accreditation with Standards Organisations which:

  • Shows customers, partners, vendors and the public that information security is a top priority for organisation
  • Demonstrates compliance with regulations and standards such as BS7799, ISO 17799, Sarbanes-Oxley, HIPAA, GLBA, and others
  • Reduces risk and the costs associated with risk
  • Improves return on investment for information security infrastructure
  • Reduces the costs of remediation activities.
   
  IRC News:
Information Security Management Conference
Information Security Management Conference, 10-12 September 2007, Las Vegas, NV

IT Governance Using COBIT® and Val IT?
IT Governance Using COBIT® and Val IT? updates the material COBIT in Academia to COBIT 4.1.

IT Assurance Framework (ITAF)
IT Assurance Framework (ITAF): Exposure Draft Comments on this framework are invited by ISACA through 27 September 2007.

  Search: