We can help you establish a security program for your business.
Elements of Security Program:
- Information Security Policy for the Organization -- Map of business objectives to security, management's support, security goals and responsibilities.
- Organizational security -- Create and maintain an organizational security structure through the use of security forum, security officer, defining security responsibilities, authorization process, outsourcing and independent review.
- Asset Classification and Control -- Develop a security infrastructure to protect organizational assets through accountability and inventory, classification and handling procedures.
- Personnel Security -- Reduce risks that are inherent in human interaction by screening employees, defining roles and responsibilities, training employees properly and documenting the ramifications of not meeting expectations.
- Physical and Environmental Security -- Protect the organization's assets by properly choosing a facility location, erecting and maintaining a security perimeter, implementing access control and protecting equipment.
- Communications and Operations Management -- Carry out operations security through operational procedures, proper change control, incident handling, separation of duties, capacity planning, network management and media handling.
- Access control -- Control access to assets based on business requirements, identity management, authentication methods and monitoring.
- System Development and Maintenance< -- Implement security in all phases of a system's lifetime through development, implementation, maintenance and disposal.
- Business Continuity Management -- Counter disruptions of normal operations by using continuity planning and testing.
- Compliance -- Comply with regulatory, contractual and statutory requirements by using technical controls, system audits and legal awareness.