| |
|
|
|
SecurView’s Network Risk Assessment is often the first step in a client engagement. Our consultants conduct a thorough evaluation of a client’s security posture, and present a detailed findings document that outlines top risk factors and proposed step for remediation. The final deliverable represents a deep analysis of the client’s systems, policies, and controls in the context of the client’s business and regulatory climate. Risks and remediation steps are prioritized based on potential business impact and a thorough cost-benefit analysis. At the end of a Network Risk Assessment, clients will be able to answer the following questions |
|
- What is our enterprise security strategy?
- Are our policies aligned with our business objectives?
- What are our high value assets, and what can we do to better protect them?
- Where are the weaknesses in our security policies and architecture?
- How can we address gaps through technology and process optimization?
- How can we make security data actionable and get timely compliance reports to address audit requirements?
- How much does an effective risk management solution cost?
|
The deliverable may take anywhere from 30 to 90 days, depending on the complexity of the client’s infrastructure and their business needs. |
|
|
|
|
- Security Policy Audit—Evaluates security policies based on availability, business continuity, and compliance requirements; it also establishes key risk factors and security metrics
- Technical Security Evaluation—Analyzes the security architecture in the context of security policies and control objectives to uncover vulnerabilities
- Threat Management Assessment—Examines threat identification, investigation, and incident response processes
- Disaster Recovery & Business Continuity Planning—Ensures that plans for returning systems to operational standards are in place to minimize business interruption should an incident occur
|
The work in each phase culminates in the findings document and presentation, which translates findings and recommendations from the preceding phases into a prioritized list of remediation steps. The deliverable goes beyond pinpointing areas of network and systems vulnerability to address weaknesses in policies and processes. Recommendations are practical; they carefully factor both risk and cost, so clients can instead focus on the gaps that they really need to address to achieve their compliance and business objectives. |
|
|
|
|