Information Security for Busines
Friday, May 09, 2008
Cyber Ensure Cyber Ensure
      ABOUT US      SERVICES SUMMARY      PUBLICATIONS & RESEARCH      CONTACT US      HOME
Tool Suite
Information Security Assessments
Risk Assessments
Policies
Awareness & Training
Security Metrics
PCI DSS Compliance & ISO 27001 Registration Assistance
Support Systems
 

Risk Assessments

An effective Information Security Program bases its decisions about which controls to deploy on an analysis of the risks it faces. Risk Assessments, the processes used to identify and understand these risks, may vary in scope:

  1. Comprehensive - an examination of all types of risks throughout the enterprise, including those introduced by major changes in the environment;
  2. Application-Based - an assessment of risks in applications and on supporting infrastructure throughout the Development Life Cycle;
  3. Third Party - an evaluation of risks associated with using third parties;
  4. Vulnerability - the identification of technical (e.g. out-of-date patches) and non-technical (e.g. awareness) vulnerabilities using scans, penetration tests, etc.; and
  5. Ad Hoc - risk assessments performed on new technologies, acquisitions, etc.

Companies should base the selection and frequency of use of risk methodologies on the value of the information processed and stored. CyberEnsure can help you select and implement appropriate methodologies. Please contact us for more information.

The CyberEnsure Team
866-CYBER11 (866-292-3711) toll free

 
   
         Privacy Policy | About Us | Services Summary | Publications | Contact Us | Home


CyberEnsure LLC. • P. O. Box 1700, Sykesville, MD 21784-1700 • (P) 866.cyber11 • (F) 410-795-3889 • ensure-info@cyberensure.com
Copyright © 2008 CyberEnsure LLC. • All rights reserved