What is this service?
The ever increasing risks to information dependent businesses has transformed information security has transformed into more of a business practice than mere products and technologies. Security practices can be implemented by means of appropriate policies, procedures, processes, guidelines and standards. Paramount's consulting services can assist the organization in implementing strong and adequate information security policies, processes and standards. This also ensures that appropriate procedures and guidelines are developed for successful implementation including the practice of these policies, processes and standards.
...............................................................................................................................................................................................................................................................................................................................
Why is this services required?
Policies drive the processes and processes in turn drive the business. Policies are high level statements that act as mandates of the top management in successful implementation of security policies throughout the organization. The policies are more like a constitution which must be adhered to by everybody in the organization. The processes and procedures explain the step by step approach to implement and follow the security policies that are issued by the management. On the other hand, the guidelines explain best practices to be followed, where as standards act as the minimum baseline which must be achieved. All these which are collectively known as the information security manual serve as a complete guide for effective information security management practices. The organization can enforce these practices on its employees which drives the organization towards a safe computing environment. The paramount policy, process and procedure service can develop a security manual based on business and information security needs that are derived from international best practices and information security standards.
...............................................................................................................................................................................................................................................................................................................................
Customer Benefits
Some of the benefits that an organization can get from the service are
- Common practice for all the personnel and technologies
- Manageable information security
- Documented process that can assist in adhering to various international standards
...............................................................................................................................................................................................................................................................................................................................
Policy, Procedure, Process Service delivery process
The paramount method of delivering the consulting service for the development of policy, procedure, process guidelines and standards is simple, proven and follows industrial best practices. The development of these documents is purely a knowledge based task. This service tries to bring out the management intent in implementing and following of information security practices. The service also focuses on developing best practices using our vast experience in information security processes and technologies as well as international security standards. The tasks involved are given below
Scope and Plan
- The identification of scope
- Project planning and resourcing
Understanding Management Intent
- Discussions with top management
- Discussions with IT and business personnel
- Understand current business processes
- Understanding the IT systems and operations
Policies and Procedures
- Inputs from international best practices and management's intent while developing policies
- Detailed steps in implementing the policies
Standards and Guidelines
- Knowledge on processes and products used in development of baseline documents
- International and vendor best practice guides used as inputs and also for validating the baseline documents developed.
Documentation
- Preparation of policies and procedure document
- Development of baseline security standards and guidelines
...............................................................................................................................................................................................................................................................................................................................
Deliverables
Policies
- Corporate information security policies
- Organization of information security policy
- Operating system and application, database management policies
- Business continuity and disaster recovery policies
- Firewall, router, IDS/IPS, anti virus security policies
- System acquisition and development policies
- Compliance policies
- Information asset management policies
- Human resource security policies
- Physical and environmental security policies & many more depending on requirement
Procedures
- Asset management procedures
- Internal audit procedures
- Document and record control procedures
- Risk management procedures
- Corrective and preventive action procedures
- Physical and environmental security procedures
Procedures and Guidelines
- Baseline Security Documents for OS/Applications/Devices etc.
Deliverables
- Change management process
- Incident handling process
- User and privilege management process
|