Cyber Risk Assessment Services
QuietAudit®
QuietAudit® (QA) is a web-based, automated self-assessment service that empowers you to measure your own network risk. Based on the ISO 27002 security standard and other best practices, QA is a practical, cost-effective approach that assesses people, processes and technology. It produces a summary scorecard deliverable for businesses and financial institutions that need to measure their level of due-care network security and privacy measures-or to simply reaffirm and document their security posture.
QA provides a panoramic snapshot of crucial network-based risks, including:
|
•
|
Current events (e.g. recent laws and new risk exposures)
|
|
•
|
Security policy
|
|
•
|
Security organization
|
|
•
|
Asset classification and control
|
|
•
|
Personnel security
|
|
•
|
Physical and environmental security
|
|
•
|
Computer and network management
|
|
•
|
System access controls
|
|
•
|
System development and maintenance
|
|
•
|
Business continuity planning
|
|
•
|
Security compliance
|
|
•
|
Internet liability (website-based intellectual property infringement)
|
|
•
|
Privacy and regulatory compliance
|
|
•
|
Records Information Management Practices (Based on ISO 15489 standard developed by a partner: ARMA www.arma.org)
|
|
•
|
FBI top network threats & recommendations
|
|
•
|
Compliance modules (e.g. GLBA 501b, HIPAA, and more)
|
Our approach is designed to extract critical information related to network security management and to verify that due care standards, including baseline safeguards, are in place.