| Microland's Governance Service Offering
Security Strategy Development
To help every CSO / CISO to determine their security strategy, Microland team will perform a detailed assessment evaluating the security aspects in people, process and technology. This assessment gauges the security posture of the organization against various best practices and international security standards and based on the outcome, the security strategy is evolved. Microland ensures that the security strategy is aligned with business strategy and IT strategy.
Security Control Maturity Assessment
Every organization has security controls which are monitored. However, the security function still has audit findings indicating the ineffectiveness of the control. This is because the control has not matured and / or is inconsistent. To strengthen this, Microland can periodically assess the maturity of the critical controls and ensure that these are consistent and enable the organization to achieve the intended security objective.
Security Policy and Process Development
Security policy is the starting point for all security initiatives within an organization. It is imperative that the security policy document is comprehensive, simple and practical to achieve good compliance results. Microland can periodically review the security policy document to ensure conformance to the best practices and to incorporate the changing risk profile so that the organization can achieve the intended security objective. Apart from the security policy definition, Microland can also assist in defining the security processes required to achieve compliance to the defined security policy document.
Information Security Risk Management Framework
In keeping ahead of changing risks across the organization, a simple and practical Information security risk management framework plays a critical role. Microland can assist organizations to define such a framework which is based on ISO IEC 27005, Guide 73 and ISO 31000 standards. This ensures that the framework is world-class yet simple to implement and comply with.
|