Certification to BS 7799/ISO 27001 must always be against a defined scope. A CRAMM reporting wizard was used to guide the Agency through a step-by-step process to define and document the scope of the Information Security Management System (ISMS). A gap analysis was undertaken to benchmark the Agency against the standard in relation to each of the BS 7799/ ISO 27001 controls, with the results recorded using the CRAMM gap analysis tool. The Plan, Do, Check, Act (PDCA) principles required by the standard were followed and the CRAMM security improvement planning tool was used to create an action plan to address the weaknesses identified by the gap analysis.

A risk assessment was carried out using the CRAMM Expert risk tool and from this, some additional control requirements were identified and added to the action plan. The database of security controls within CRAMM is aligned with the BS 7799/ISO 27001 and ISO 17799 control sets which made it easy to demonstrate that the additional controls selected were addressing the requirements of the standard. A risk assessment and treatment report describing how well the assessed risks were being managed was produced from CRAMM.

CRAMM provides tools that help in achieving compliance to ISO 17799 (the international information security management standard) as well as formal certification to ISO 27001. Infoamn has a proven ISO 27001 methodology, illustrated below, which has been used many times to guide organisations through the process of achieving compliance to ISO 27001 and, where required, formal certification against the standard.

Many of the items on the action plan had to be addressed by business or IT managers within the Agency, e.g. improved processes for administering access rights of joiners and leavers. CRAMM reporting wizards were used to guide the development of the Agency Information Security Policy and an Interchange Agreement for sharing information with partners.

Having completed the security improvement programme, the Agency was ready to demonstrate its ISO 27001 compliance to an external auditor and seek formal certification to the standard. CRAMM tools were used to develop the additional key documentation for presentation to the auditor

  Newsletter Membership

E-Mail:
     
 


Security testing needs to be a fundamental component in any organisation's information security strategy. Infoamn are recognised as the leading penetration testing organisation in the Iran and our consultants can help you to identify the vulnerabilities in your IT infrastructure - as well as demonstrating how these weaknesses could be exploited by an intruder. Find out more about Infoamn's security testing capabilities.

ISO27001 CERTIFICATION CONSULTANCY
APPLICATION SECURITY TESTING
TECHNICAL SECURITY AUDIT
VULNERABILITY & PENETRATION TESTING
WIRELESS SECURITY AUDIT
DESKTOP SECURITY AUDIT
 

BS7799 / ISO 27001 CERTIFICATION CONSULTANCY

The British Institute has suggested the Plan Do Check Act methodology for implementation of the ISO 27001 standard. INFOAMN has developed a unique methodology for implementation of ISO 27001 controls by breaking down the entire PDCA cycle in 5 distinct phases. Starting with Security Profiling which identifies the gaps in security vis-à-vis BS 7799/ISO 27001 standard, followed by Security Prescription which suggest the security measures; Security Treatment, where the security measures are implemented; Security Vigil, where the implementation is monitored to ensure that the security measures are effective in mitigating the risks and ensuring security of the information assets. Successful implementation of these phases leads to the final phase of Security Certification.

INFORMATION SECURITY GAP ANALYSIS

ISO 27001, the Code of Practice for Information Security Management describes a management framework within which an organization can examine and improve its security health. ‘End-to-End’ security is required and the controls must reflect this. Under each domain, there are defined objectives and related controls. Infoamn’s role is to understand the applicable controls based on the risk assessment and formulate policies and procedures. ISO 27001 contains a comprehensive set of security controls to improve the level of security within any organization. Even if formal certification is not a strategic objective, efforts to comply with the principles of ISO 27001 bring many tangible benefits such as reduced exposure to wide range of threats, creation of more secure operational environment, assurance that security practice is in line with the industry best practice, improvement in user security awareness and prioritizing security needs. An Information Security GAP Analysis as per ISO 27001 Standard helps organizations to know their state of security and thereby deciding the future roadmap.


MANAGED SECURITY SERVICES

Outsourcing selected managed security services (MSS) by forming a partnership with a MSS provider is often a good solution for transferring information security responsibilities and operations. Contracting a MSS provider allows it to share risk management and mitigation approaches. INFOAMN manages the information security issues so that the organization can concentrate on its key performing areas.


APPLICATION SECURITY TESTING

Application Security Testing involves analyzing a custom application for vulnerabilities. This can be done either by way of 'black box' i.e. without access to the source code, or 'white box' i.e. with access to the source code. An application security test ensures that any customized application being used is secure and doing exactly what it is supposed to do.


TECHNICAL SECURITY AUDIT

The technical security audit modules broadly consist of auditing the perimeter devices, network devices, desktop PCs, Servers and the applications and databases. The overall network security architecture is also reviewed keeping in view the business requirements and goals, its connectivity with the trading partners, its connectivity to the Internet etc. Also adequate security solutions & technical controls are recommended to mitigate the risks.


VULNERABILITY ASSESSMENT & PENETRATION TESTING

Penetration testing and Vulnerability assessment are two different and complimentary pro-active approaches to assess the security posture of the information systems networks. Penetration testing is the testing of the security posture from the hacker's perspective, whereas the Vulnerability Assessment is done to test the security posture of the Information Systems as an internal attacker. Comprehensive methodology is recommended to fix the identified vulnerabilities. INFOAMN has a proven track record of finding known and new threats.


CONTENT SECURITY SOLUTIONG

Leakage of critical data through emails and loss of productive time and bandwidth are major concerns for the organization. Spam emails are increasing by the day. INFOAMN offers MIME sweeper content filtering & antispam solution helps organizations in protecting critical data by enforcing security policies that also increase overall productivity.


WIRELESS SECURITY AUDIT

With the increased popularity of remote working in recent years, wireless networks have become more common. However, when many of the Wireless networks were deployed, not a lot was known about the security risks. A Wireless LAN needs to be audited like the internal network. The systems available through cordless devices are more vulnerable to attack if not monitored and properly secured.


ASSESSMENT OF NETWORK SECURITY ARCHITECTURE

Inherent weaknesses and design flaws in the network architecture from security perspective are detected, which can lead to compromise of confidentiality, integrity or availability of the system. The mitigation strategy is suggested. The proposed network architecture is designed and delivered. Network architecture is backbone of any secure information systems network. INFOAMN follows a structured approach to network security design often within the client's existing infrastructure or by recommending additional best-of-the-breed security components.


DESKTOP SECURITY AUDIT

Securing desktop workstations and laptops is a significant part of your network and information-security strategy because of the sensitive information often stored on workstations and their connection to the networked world. Many security problems can be avoided if the workstations and network are appropriately configured. Default hardware and software configurations, however, are set by vendors who tend to emphasize features and functions more than security. Since vendors are not aware of your security needs, the workstations should be configured to as per the security policy of the organization.

Contact Us Alliances Training ISO 20001 ISO 27001 Company Profile Home
INFOAMN Consulting is the Middle East leading provider of services and solutions for infrastructure of information security, business continuity and security risk management & information technology system management ©2004. All rights reserved. www.infoamn.com