Gaining the most from your ISMS program implementation
In addition to satisfying multiple aspects in world standards and regulations, the achievement of ISO 27001 certification is recognized for:
- Improved company reputation and image
- Proof of senior management’s commitment to the security of the organization
Companies embarking on the path of UK Cyber Essentials, Cyber Essentials Plus, or any number of other similar certifications such as ISO 27001 or PCI DSS 3.2, need assistance to establish, monitor, maintain and measure improvement in their information security management systems. Leveraging IS027002, NIST, and UK Cyber Essentials as a combined Unified Compliance allows clients to:
- Identify information assets and their associated security requirements
- Assess information security and treat risks according to their relative tolerance
- Select and implement relevant controls to manage or mitigate threats
- Monitor, maintain and improve the effectiveness of controls associated with the organization’s information assets
THE SOLUTION
- Settings that indicate missing patches for operating systems and applications.
- Monitoring and detecting sensitive data loss (data exfiltration)
- Locating policies that enable weak passwords.
- Lack of logs and audit trails necessary to conduct forensics
- Security validation for new systems
- Missing or outdated anti-malware technology
- Settings that enable encryption of sensitive information in transit
- The information necessary to remediate deficiencies that would otherwise be impossible to manage due to the lack of trained staff maintaining security controls.
Cyber Ready
- Know the critical assets and who’s responsible for them
- Get everyone involved in cyber-resilience
- Assure they have the knowledge and autonomy to make good decisions
- Be prepared for both unsuccessful AND successful attack
- Prevent a cyber-attack from throwing your organization into complete chaos.
To learn more about certifications visit http://www.itgovernance.co.uk/cyber-essentials-scheme.aspx, or read from the Official website for Cyber Essentials, and a Self-Assessment Questionnaire to help determine which of the two certifications a company needs: https://www.cyberstreetwise.com/cyberessentials/
Supporting standards and guidance
- ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems – Requirements
- ISO/IEC 27002:2013 Information technology — Security techniques — Code of practice for information security controls
- Information Security Forum – The Standard of Good Practice for Information Security (2013)
- The IASME Consortium – The Standard for Information Assurance for Small and Medium-Sized Enterprises – (2013)
- HMG 10 Steps to Cyber Security
- Further advice is available through the CESG Listed Advisor Scheme detailed at www.cesg.gov.uk/servicecatalogue/CLAS/Pages/CLAS.aspx.
UK Cyber Essentials Compliance with EnterpriseGRC Solutions
EnterpriseGRC Solutions develops the security policy to system rules mapping. Company members are active contributors to numerous major standards organizations, especially those responsible for the mapping of regulatory requirements. In addition to organic CIS Benchmarks and DISA STIG NIST-based configuration hardening and change management, we suggest assessments with NIST Cybersecurity Framework (CSF) and NIST 800-53 r5, which have most recently been optimized for use with Cloud Security Alliance STAR programs using the CCM v 4.2.
EnterpriseGRC Solutions is empowered to implement governance, security, risk, and compliance automation products and programs, emphasizing system-based policies specific to security settings for secure configuration management. EnterpriseGRC is a women-owned small business offering compliance readiness, Security & GRC tools, Enterprise Security Architecture, Cybersecurity Risk Assessment, and a wide variety of resources for security and GRC technology support. Founded in October of 2002 as Phoenix Business and Systems Process, and rebranded in 2011 as EnterpriseGRC Solution, the company is positioned to solve an organization's greatest cloud security and cyber challenges. True to its tagline "Simple Solutions to Complex Problems" the company offers pragmatic, remote and on-site web-enabled compliance implementation, training, strategy, management consulting, security and risk management services.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics