Compliance
We can review the readiness of your organization for compliance with EU Directives such as NIS 2 and GDPR, and International and Industry Standards in cybersecurity such as ISO 27001, ISO 22301 as well as PCI DSS.
What is ISO 27001?
ISO 27001 is the International Standard for Information Security. The Standard lays out a framework for an Information Security Management System (ISMS), helping to deliver improved security arrangements within your business.
The purpose of the ISMS is to ensure that an organization is still able to meet its defined business objectives and comply with its policies in case of a security incident.
Why is ISO 27001 certification important?
With an ISO 27001 certification, organizations can demonstrate their commitment to data protection. Although not legally required, with an ISO certified ISMS organizations can show customers and partners that they have controls in place to protect their data in the event of a breach.
Furthermore, with a global rise of supply chain threats, more and more businesses today insist that their partners and suppliers comply with carefull information security management controls.
Our Methodology & Approach
Business Objectives
We assist you to determine the ISMS scope so that the identified business objectives are achieved, creating a solid foundation for building an effective ISMS. During this phase a “gap analysis” of the organization’s current position with regard to ISO/IEC 27001:2022 is conducted.
Data Collection and Risk Assessment
The objective in this phase is to create an effective risk management process to ensure that potential consequences are avoided, or if they don’t, that contingencies are in place to deal with them.
Control Implementation
During this phase, we identify and propose a set of actions that should be put in place to address the unacceptable risks identified by the Risk Assessment as well as a plan for their implementation. In addition, we also develop the ISMS documentation and functional IT security policies and procedures according to ISO 27001 (as per the risk mitigation and treatment plans).
Monitor and Review
The main purpose of this stage is to ensure that Information Security processes are carried out effectively, efficiently and economically to the benefit of the organization. With internal audits we identify compliance or any areas of non-compliance with ISO 27001 as well as further opportunities for continual improvement, which may extend beyond the criteria set out in the standard.
Benefits
The NIS 2 Directive – Link
Directive (EU) 2022/2555 (NIS 2 Directive).
https://eur-lex.europa.eu/eli/dir/2022/2555
What is NIS 2?
The NIS 2 Directive is the EU legal framework on cybersecurity.
The EU cybersecurity requirements for critical infrastructures, introduced in 2016, were updated by the NIS 2 Directive that came into effect in 2023.
NIS 2 expands its scope of the network and information systems security requirements to more entities from both the public and private sector and therefore, improves EU member states cyber resilience against new and more sophisticated digital threats.
What we offer
Our consultants have a lot of experience with NIS and therefore are ready to assist your Organization for NIS 2 compliance.
We help you to address the NIS 2 requirements by implementing technical and organizational security measures and focusing on mission critical systems resilience in order to quickly recover from both anticipated and unexpected security incidents.
We can guide you to:
What is ISO 22301?
ISO 22 301 is the international standard for Business Continuity Management (BCM).
Why is a BCMS important?
A BCMS (business continuity management system) helps organizations manage incidents affecting their business-critical processes and activities. The goal is to develop your organization’s business recovery capabilities in order to enhance resilience and minimize disruptions.
Our Professional Services assist your organization with:
What is GDPR?
The General Data Protection Regulation is a European Union regulation on information privacy.
GDPR replaced the 1995 General Data Protection Directive, and is applied to all EU member states. The Regulation took effect from May 2018.
Companies are subject to the regulation as far as they process personal data of EU data subjects for their goods or service offerings in the EU and/or for the monitoring of the behavior of EU data subjects taking place within the EU. It introduces new requirements and more strict data protection challenges.
GDPR could bring market opportunities and competitive advantage for those who effectively implement it or potential revenue loss for those who fail to react.
What we offer?
Our experienced consultants assist organizations to define clearly and analytically all the necessary actions for a complete and compliant implementation of the regulation, by addressing the following:
The Payment Card Industry Data Security Standard (PCI DSS) is a set of policies and procedures intended to optimize the security of card transactions and protect cardholders against misuse of their personal information.
If your organization accepts, processes, stores, or transmits payment card information, you will need to meet certain accepted industry standards to become PCI compliant.
Our consultants can help your organization to achieve compliance by developing a number of objectives, policies and procedures supported by technological security controls to protect cardholder data.