Certification to BS 7799/ISO 27001 must always be
against a defined scope. A CRAMM
reporting wizard was used to guide the
Agency through a step-by-step process to
define and document the scope of the
Information Security Management System
(ISMS).
A gap analysis was undertaken to
benchmark the Agency against the
standard in relation to each of the BS 7799/ ISO 27001
controls, with the results recorded using the
CRAMM gap analysis tool. The Plan, Do,
Check, Act (PDCA) principles required by
the standard were followed and the
CRAMM security improvement planning tool
was used to create an action plan to
address the weaknesses identified by the
gap analysis.
A risk assessment was carried out using the
CRAMM Expert risk tool and from this,
some additional control requirements were
identified and added to the action plan.
The database of security controls within
CRAMM is aligned with the BS 7799/ISO 27001 and
ISO 17799 control sets which made it easy
to demonstrate that the additional controls
selected were addressing the requirements
of the standard. A risk assessment and
treatment report describing how well the
assessed risks were being managed was
produced from CRAMM.
CRAMM provides tools that help in
achieving compliance to ISO 17799 (the
international information security
management standard) as well as formal
certification to ISO 27001.
Infoamn has a proven ISO 27001 methodology,
illustrated below, which has been used
many times to guide organisations through
the process of achieving compliance to
ISO 27001 and, where required, formal
certification against the standard.
Many of the items on the action plan had to
be addressed by business or IT managers
within the Agency, e.g. improved processes
for administering access rights of joiners
and leavers. CRAMM reporting wizards
were used to guide the development of
the Agency Information Security Policy
and an Interchange Agreement for sharing
information with partners.
Having completed the security
improvement programme, the Agency was
ready to demonstrate its ISO 27001
compliance to an external auditor and
seek formal certification to the standard.
CRAMM tools were used to develop the
additional key documentation for
presentation to the auditor
Security testing needs to be a fundamental component
in any organisation's information security strategy. Infoamn
are recognised as the leading penetration testing organisation in the
Iran and our consultants can help you to identify the
vulnerabilities in your IT infrastructure - as well as demonstrating how these
weaknesses could be exploited by an intruder. Find out more about
Infoamn's security testing capabilities.
The British Institute has suggested the Plan Do Check Act methodology for implementation of the
ISO 27001 standard.
INFOAMN has developed a unique methodology for implementation of ISO 27001 controls by breaking down the entire PDCA cycle
in 5 distinct phases. Starting with Security Profiling which identifies the gaps in security vis-à-vis BS 7799/ISO
27001 standard,
followed by Security Prescription which suggest the security measures; Security Treatment, where the security measures
are implemented; Security Vigil, where the implementation is monitored to ensure that the security measures are effective
in mitigating the risks and ensuring security of the information assets. Successful implementation of these phases leads to
the final phase of Security Certification.
INFORMATION SECURITY GAP ANALYSIS
ISO 27001, the Code of Practice for Information Security Management describes a management framework within which
an organization can examine and improve its security health. ‘End-to-End’ security is required and the controls must reflect this.
Under each domain, there are defined objectives and related controls. Infoamn’s role is to understand the applicable controls based
on the risk assessment and formulate policies and procedures.
ISO 27001 contains a comprehensive set of security controls to improve the level of security within any organization. Even if formal
certification is not a strategic objective, efforts to comply with the principles of ISO 27001 bring many tangible benefits such as reduced
exposure to wide range of threats, creation of more secure operational environment, assurance that security practice is in line with the
industry best practice, improvement in user security awareness and prioritizing security needs. An Information Security GAP Analysis as
per ISO 27001 Standard helps organizations to know their state of security and thereby deciding the future roadmap.
MANAGED SECURITY SERVICES
Outsourcing selected managed security services (MSS) by forming a partnership with a MSS provider is often a good solution for transferring
information security responsibilities and operations. Contracting a MSS provider allows it to share risk management and mitigation approaches.
INFOAMN manages the information security issues so that the organization can concentrate on its key performing areas.
APPLICATION SECURITY TESTING
Application Security Testing involves analyzing a custom application for vulnerabilities. This can be done either by way of 'black box'
i.e. without access to the source code, or 'white box' i.e. with access to the source code. An application security test ensures that
any customized application being used is secure and doing exactly what it is supposed to do.
TECHNICAL SECURITY AUDIT
The technical security audit modules broadly consist of auditing the perimeter devices, network devices, desktop PCs, Servers and
the applications and databases. The overall network security architecture is also reviewed keeping in view the business requirements
and goals, its connectivity with the trading partners, its connectivity to the Internet etc. Also adequate security solutions & technical
controls are recommended to mitigate the risks.
VULNERABILITY ASSESSMENT & PENETRATION TESTING
Penetration testing and Vulnerability assessment are two different and complimentary pro-active approaches to assess the security
posture of the information systems networks. Penetration testing is the testing of the security posture from the hacker's perspective,
whereas the Vulnerability Assessment is done to test the security posture of the Information Systems as an internal attacker.
Comprehensive methodology is recommended to fix the identified vulnerabilities. INFOAMN has a proven track record of finding known and new threats.
CONTENT SECURITY SOLUTIONG
Leakage of critical data through emails and loss of productive time and bandwidth are major concerns for the organization.
Spam emails are increasing by the day. INFOAMN offers MIME sweeper content filtering & antispam solution helps organizations
in protecting critical data by enforcing security policies that also increase overall productivity.
WIRELESS SECURITY AUDIT
With the increased popularity of remote working in recent years, wireless networks have become more common. However, when many of
the Wireless networks were deployed, not a lot was known about the security risks. A Wireless LAN needs to be audited like the internal network.
The systems available through cordless devices are more vulnerable to attack if not monitored and properly secured.
ASSESSMENT OF NETWORK SECURITY ARCHITECTURE
Inherent weaknesses and design flaws in the network architecture from security perspective are detected, which can lead to compromise
of confidentiality, integrity or availability of the system. The mitigation strategy is suggested. The proposed network architecture
is designed and delivered. Network architecture is backbone of any secure information systems network. INFOAMN follows a structured
approach to network security design often within the client's existing infrastructure or by recommending additional best-of-the-breed
security components.
DESKTOP SECURITY AUDIT
Securing desktop workstations and laptops is a significant part of your network and information-security strategy because of the sensitive
information often stored on workstations and their connection to the networked world. Many security problems can be avoided if the
workstations and network are appropriately configured. Default hardware and software configurations, however, are set by vendors who tend to
emphasize features and functions more than security. Since vendors are not aware of your security needs, the workstations should be configured
to as per the security policy of the organization.