Security System Study
Studies and analysis the aspects of confidentiality, integrity and availability of information(data) with regard to the organisation.
Identify exposure to accidental or intentional , destruction, disclosure , modification or interruption of information that may cause serious financial and or information loss
Study of cyber security and incident response and has become necessary because attacks frequently cause the compromise of personal and business data.
Heightened incidents concerns about national security and exposure of personally identifiable information. Racing awareness of the possible effects of computer barred attacks is the other reason.
Security Policy
-
Developing security plans
-
Recommending & configuring security products
-
Planning disaster recovery & risk analysis in evident response, crisis management, asset allocation, performing security audit and penetrating testing.
-
Educating employees in security policy
-
Data classification, guidelines, standards and procedures
-
Develop, establish and maintain standards, procedures and guidelines to promote the security and uninterrupted operation of computer based application systems.
Why do we need a security policy?
-
Protect people and information
-
Set the rules for expected behavior by users, the system administrator, management and security personal
-
Authorize security personal to monitor probe and investigate.
-
Define the company – consumer baseline stands in security
-
Help minimize risk
-
Help track compliance with regulations and legislation.
Security System Audit
-
Applicability of the policy
-
Evaluation of the risk treatment methods
-
Maintain and improve the security policy
-
Monitor and review the security policy
-
Monitor and verify the implementation of security policy
-
Verify and monitor the implementation of the statutory and regulatory requirements
-
Ensure availability of resources
-
Verify for effectiveness
-
Continual improvement
-
Corrective action
-
Analysis of data
-
Preventive action
-
Management review
-
Confirmation that the organisation is acting in accordance with the polices ,objectives and procedures
-
Assessment of information security related risk