|
Security
Security in Information Technology has two distinct aspects – physical and logical.
However, the same Risk Assessment Model may be used in both instances.
Assailants exploit vulnerabilities to initiate an attack
Early detection and controls reduce the impact of an attack.
Preventions and deterrents reduce vulnerabilities and lessen the chance of attack
Physical – controls, procedures, and devices to ensure the security, safety and reliability of your data center.
Consilium Resources will evaluate the physical security of your data center as well as your documented procedures and controls.
We will look for vulnerabilities that could be exploited to gain access to your data center.
We will assess the preventive measures and deterrents in place such as swipe card, security guards, and man-traps.
We will examine current detection methods and controls such as real-time access monitoring and cameras.
We will then scrutinize those findings and estimate the impact of a breach based on the potential for damage and destruction.
We will recommend improvements where required and provide a process to implement the improvements.
Logical – controls, applications and devices to ensure the security of your network, data and application assets.
Consilium Resources can evaluate your logical security architecture.
We will look for vulnerabilities that could be used to gain unauthorized access to your network and systems.
We will review your prevention and deterrents such as your password policies,
DMZ architecture and implementation (including all firewalls), and virus control implementations.
We will examine your detection methods such as intrusion detection systems and system warning/alert levels and methods.
We will then estimate the impact of an access breach based on potential loss of data or denial of service.
We will analyze and document where your implementation meets or exceeds industry and regulatory standards and/or recommend improvements where warranted.
Vulnerability Testing
Consilium Resources can test your physical and logical security measures.
We can conduct exercises, wherein we attempt to penetrate your network and/or facility.
The results of these exercises, along with evidence of any successful intrusion, and the methods utilized will be provided.
Recommendations on improvements will be made.
|
 |

Breach Disclosure
Your reputation is your most powerful asset.
--- Ron Alsop;The 18 Immutable Laws of Corporate Reputation
Some breaches must be disclosed to customers, if their personal data may have been compromised.
In those situations we can attempt to quantify the effect on corporate reputation, and potential customer loss.
|