IT Risk Management Consulting
Company Information    ||    Clients    ||    White Papers    ||    Contact Us  
Polar Cove Strategic Consulting

Home

Strategic Consulting
Info Risk Management
Policy Consulting
Security Strategy

Professional Services
Vulnerability Assessment
Penetration Testing
Attack Simulation
Vulnerability Scanning
Application Security Testing

SOX and SAS-70s
Sarbanes-Oxley and IT Regulations
Sarbanes-Oxley Sec. 404 Roadmap
SAS-70 Overview and Planning

SAS-70 Frequently Asked Questions

Company Information
Clients
White Papers
News
Contact Us
Events

Information Risk Management and Gap Analysis

Risk. The possibility of suffering harm or loss. The potential for realizing the unwanted negative consequences of an event.

Translating business requirements into IT resources is always a challenge. It is a greater challenge when security is involved. IT staff need to fully understand their business’ mission-critical requirements. Then, they need to find the sets of ways to allow the enterprise to conduct its business while ensuring that the business’ information is available, confidential, and secure. Misunderstandings can be costly. Critical information may be inadequately secured, and non-essential information may even be over-secured.

Polar Cove’s information risk management and gap analysis approach uses quantitative and qualitative tools to enumerate our clients’ security risk exposures. Consultants lay the foundation by gaining agreement with clients about specific risks in direct relation to their missions and their essential IT assets. After these risks are identified, Polar Cove works in cooperation with management to ensure that operational and business units work together to understand and address the information security needs of the enterprise. As a result, clients can close the gaps between business requirements and the IT resources that protect them. Risks are managed, not merely experienced.

Information Risk Management and Gap Analysis Includes:

  • Building Asset-Based Threat Profiles. Polar Cove examines key enterprise-wide information assets, the specific threats to those assets, the resulting security requirements, existing security practices, and potential vulnerabilities.


  • Identify Infrastructure Vulnerabilities. Evaluating the key operational components of each client’s information infrastructure uncovers possible technology flaws that can be exploited.


  • Developing a Security Policy, Strategy, and Plan. Based on the specific information developed in the steps above, Polar Cove works with management to establish a tailored, effective protection strategy for each client. Security policies developed for each are based on prioritized risk assessments, the available or necessary assets, and the organizational requirements for mitigating risk.

Polar Cove risk assessment and risk management consultation enables clients to make information management decisions and develop effective security policies, based on management’s decisions about specific business information and its uses. The result is a program tailored to ensure critical controls and protection for each enterprise.


| Download the Info Risk Management Brochure [pdf 84k]

[ Back to Top ]

 
White Papers
›  IT Security Benchmarking – Compare yes, but insist on hard data too.
›  IT Security Awareness in Finance – “ People are the weak link
›  Understanding the Many Benefits of a SAS 70
›  SAS 70 Overview and Planning Guide
›  Polar Cove’s Experience in Sarbanes-Oxley Sec. 404 – A Roadmap

more »


You Should Know...
Average Hourly losses in the event of Data center Outage, by industry

$1,107,274
Retail
$1,202,444
Insurance
$1,344,461
Information Tech
$1,495,134
Financial Institutions
$1,610,654
Manufacturing
$2,066,245
Telecommunications
$2,817,846
Energy

Source: META Group

The cost savings realized by integrating risk management and security into business operatons and IT planning can be tenfold.

Source: Gartner

    more »


Contact us
For any questions you may have, contact us at
1-401-454-3939.
Our Polar Cove representative will answer and assist you with your specific needs.

 


   Privacy Statement    ||    Sitemap    ||    Careers
© 2005     Polar Cove