|
Information Systems Security
Corporate Liability
Every organisation is now dependent on information systems for the daily operation of
its business.
Directors and managers are responsible for the integrity of the information which the organisation holds. They are legally obliged to ensure compliance with statutory requirements.
Threat
Computerised information systems are inherently insecure. This poses a serious threat to the viability of the organisations which rely on them.
Threats come from an astonishingly wide range of sources, external and internal. The main risks to the organisation can be summarised as:
• Loss of intellectual property
• Loss of reputation
• Loss of revenue
• Fraud
• Default on statutory responsibilities
The Ovag Approach
The Information Systems Security services offered by OVAG take full advantage of the skills and experience of consultants and investigators in other parts of its business.
Based on BS7799 and enhanced by a proactive approach to security analysis, OVAG offers services in two key areas:
• Identification and investigation of breaches of information security
• Design of procedures, systems and software to support best practice
The Process
Investigations
When a breach of information security has been identified, OVAG:
• Contains the breach
• Identifies the source
• Rectifies the damage
OVAG uses a well defined methodology to address the problem:
• An action team of key client staff and OVAG consultants is formed
• Affected systems are identified and secured against further compromise
• The source of the breach is identified
• Methods include e-mail analysis, network traffic analysis, disc imaging, communications
surveillance and video surveillance
• OVAG ensures that the information and evidence gathered is of a quality capable of
supporting legal or tribunal proceedings
• Weaknesses in the security model are identified and recommendations made to minimise the risk of recurrence
Security Consultancy
OVAG can offer advice and consultancy on:
• Policy, procedures and statutory compliance
• Vulnerability analysis
• Systems and software selection advice
• Application design risk analysis
• BS 7799 compliance assessment
Business Advantage
The organisation is assured that both its business integrity and its statutory obligations are maintained to meet the requirements of best practice in Information Security.
|