|
A frighteningly
large number of organizations
believe that having a firewall
and anti-virus software
in place makes them secure.
This is the IT equivalent
of having an armor-plated
front door, but forgetting
to shut the windows when
you go out. |
|
Many people think of IT
security as being an absolute,
whereas in reality security
is always a trade off with
accessibility of systems
and information. Security
must be intelligently blended
with the need to make information
accessible to those who
need it. |
|
Business requirements
regarding data availability,
data integrity and confidentiality |
|
Potential legal exposures
under relevant privacy and
data protection legislation |
|
Internal vulnerability
assessment |
|
External vulnerability
assessment |
|
Intellectual capital (asset)
classification and log |
|
Network design review
(from security perspective) |
|
Review of current security
policies and procedures
(staff awareness and compliance) |
|
Intelligent
and pragmatic approach based
on Risk Management |
|
Focus on policies and
procedures as well as technology |
|
Analysis of operational
and legal exposures and
recommended fixes |
|
Objective and independent,
in line with AS 7799 |
|
Report of findings in
plain English |
|
Platform for creation
of an integrated Security
Plan |