|
|
Regulatory Compliance AuditsA growing body of regulation imposes enormous burdens on institutions to safeguard their information systems, transaction processes and sensitive databases. Among them are Sarbanes-Oxley (SOX), ISO 27001, Gramm-Leach-Bliley Act (GLBA), Fair and Accurate Credit Transactions Act (FACTA), Health Insurance Portability and Accountability Act (HIPAA), and the latest requirements, adopted as part of the ARRA of 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act. Failure to comply with applicable regulatory standards can result in the exploitation of vulnerabilities by hackers and other cybercriminals. Identities may be stolen, and sensitive information abused for malicious profit. Security breaches can have far-reaching impacts, ranging from remediation costs and damages payable to victims, to the incalculable toll of negative publicity, customer churn, and lost business. For these reasons, compliance audits should be conducted on a regular basis. SECNAP's professionally certified security auditors leverage a complete audit tool kit—in tandem with their extensive, in-depth experience in conducting compliance audits—to ensure that you receive useful, comprehensive information suitable for immediate action. Tools may include automated testing, network and wireless scans, personnel interviews, social engineering techniques, policy reviews, procedural and process evaluations, in-depth analyses and more. By leveraging third-party support for compliance audit projects, organizations ensure that experienced, objective experts are engaged appropriately, and that in-house IT and audit personnel are able to remain focused on mission-critical responsibilities. The Compliance Audit Process Interviews and Reviews
Preparation of Full Network Map (IP address and services assessment)
Procedural Component
Compliance Overlay
Deliverables Upon completion of the compliance audit, deliverables include a draft and final Detailed Report, an Executive Summary, and supporting data in both paper and electronic form. Executive Summary At the executive level, we will demonstrate where you stand relative to other companies in your industry, and outline steps that can be taken to improve your security profile, enhance compliance, and reduce risk. Results of the automated scans and any other tests are summarized. An outline of possible employee abuses or violations of your policies is provided. This report may be useful in allocating budget for remediation. Detailed Report Designed to be used as an actionable guide for the compliance officer and similar stakeholders as well as appropriate IT management and staff, this detailed report outlines recommendations for changes to written security and Internet use policies, security handling procedures, and any additional measures to bring your company into compliance with applicable standards in addition to best security practices for your industry. At the close of our work, you’ll possess the information necessary to bring your security program up to date and into compliance, and earn some well-deserved peace of mind in the process. Click here to request more information or a free consultation.
|
“With Rule18 Email Encryption, I know beyond a doubt that my confidential emails are totally private as they transit the Internet. The whole process couldn't be easier, faster, or more efficient--and the privacy is infinitely reliable!" Victor Nappe, Founder Iron Investments LLC |