Wednesday, December 23, 2009

Risk Management - IT Security Assessments

Has your company performed an IT Security Risk Assessment?

As we move into the new year and you are busy planning for 2010, one area of Risk Management that Companies should not overlook is an IT Security Risk Assessment by a Certified Information Systems Security Professional (CISSP).

An IT Security Risk Assessment should be performed on-site in conjunction with the CEO, CTO/CIO, and key IT employees. The initial assessment should include a review of both physical and internal infrastructures and will usually last up to 4 hours for most small to medium size businesses. Your deliverable should include a completed review of your current practices and an SOW that clearly states options to mitigate identified risks based on best practices and industry standards. You will need to determine your company's tolerance for the areas of risk identified. A customized plan can then be implemented.

Pratt Brown & Associates is here to assist with all of your IT Security Risk Assessment needs.

0 comments: