Information Security Strategy Consulting Services
Polar Cove Strategic Consulting

Home

Strategic Consulting
Info Risk Management
Policy Consulting
Security Strategy

Professional Services
Vulnerability Assessment
Penetration Testing
Attack Simulation
Vulnerability Scanning
Application Security Testing

SOX and SAS-70s
Sarbanes-Oxley and IT Regulations
Sarbanes-Oxley Sec. 404 Roadmap
SAS-70 Overview and Planning

SAS-70 Frequently Asked Questions

Company Information
Clients
White Papers
News
Contact Us
Events

Security Strategy

Polar Cove is a trusted guide for developing client-centered comprehensive information security strategies.

People, programs, and technology need to work together to manage risk. They must do so in a real-time business environment, where growth and change mean ever-greater complexity and even higher risks. As technology develops and enterprises grow, the danger is that security models can become fragmented and emergency-responsive. Polar Cove helps to ensure that at all stages of growth, security standards and strategies can be implemented through goal-driven plans; integrated, productive approaches; and ongoing monitoring.

Polar Cove’s security strategy programs are client-centered, reflecting the needs, business patterns, and direction that are unique to each enterprise.

Security Strategy Includes:

Strategic Assessment

Polar Cove determines your organization’s security posture. Reports show the steps needed to move from reactive and/or fragmented to proactive and/or unified practices. Studies may cover:

  • Organization Assessment, to see how current security functions fit the needs of the overall business.

  • Framework Gap Analysis, to compare current security functions with our best-practice model.

  • Security Benchmarking, to measure current security functions against those of other organizations of the same size in the same industry.

Strategic Planning

Polar Cove works with each client to develop long-term plans for building a proactive, comprehensive security process focused on business-specific needs. Services may include:

  • Security Process Engineering, to design the structure of future security programs and establish a path for getting there.

  • Security Accreditation, to identify regulatory business requirements, determine how to address them and take steps to assure regulators, customers and others of the presence of necessary security measures.

  • Access Control Design, to balance user need for access to the enterprise with the enterprise’s need for security.

  • Privacy Infrastructure Design, to build privacy into the infrastructure framework and thereby provide security strength for the long term.

  • Security Awareness and Training, to educate staff at every level so that they understand and can properly implement the security processes.

  • Security Implementation Planning, to help Polar Cove clients design and implement the technical aspects of their security processes.


| Download the Security Strategy Brochure [pdf 81k]

[ Back to Top ]

 
White Papers
›  IT Security Benchmarking – Compare yes, but insist on hard data too.
›  IT Security Awareness in Finance – “ People are the weak link
›  Understanding the Many Benefits of a SAS 70
›  SAS 70 Overview and Planning Guide
›  Polar Cove’s Experience in Sarbanes-Oxley Sec. 404 – A Roadmap

more »


You Should Know...
Top 10 Actions for the Board of Direcotrs and Management

Make sure your business:

Creates a security-aware culture by educating staff about security risks and their responsibilities
Has a clear up to date security policy to facilitate communication with staff and business partners
• Has people responsible for security with the right knowledge of good practice and the latest security threats—consider supplementing their skills with external security experts
• Evaluates return on investment on IT security expenditure
• Builds security requirements into the design of IT systems and outsourcing arrangements
• Keeps technical security defenses (e.g. anti-virus software) up to date in the light of latest threats
• Has procedures to ensure compliance with data protection and other relevant regulatory requirements
• Has contingency plans for dealing with a serious information breach
• Understands the status of its insurance cover against damage as a result of information security breaches
• Tests compliance with its security policy (e.g. security audits, penetration testing of its web-site, etc).

Most important of all, do not wait for a serious security incident to affect your business before you take action.


Source: UK Department of Trade and Industry Information Security Breaches Survey

    more »


Contact us
For any questions you may have, contact us at
1-401-454-3939.
Our Polar Cove representative will answer and assist you with your specific needs.

 


   Privacy Statement    ||    Sitemap    ||    Careers
© 2005     Polar Cove