Enterprise Risk Management
Enterprise Risk Management strategies focus around global standards such as COSO, ISO/IEC 27001, the Information Security Forum’s Statement of Good Practice (SOGP) and various derived standards such as as the UK Government’s ITSEC (Information Technology Security Evaluation and Certification) and IA (also known as the Information Assurance Maturity Model). Also commonly included in the mix are standards for Business Continuity such as BS 25999.
Lacunae Risk have experience in delivering effective, reliable programmes which incorporate gap assessment where required, defining the “as-is” and establishing the desired state to move the client towards. We understand the complexities of organisational change involved and the various strategic, tactical and operational changes that can entrammel an information security programme.
Where formal accreditation is required, we liaise with impartial accreditors and government assessors to ensure that information assurance and security maturity are demonstrably assessed and that our customers are ready not only for formal audit, but to incorporate the changes into their normal “business-as-usual” operations afterward.
In addition, where appropriate we can provide specialised managed security services that ease the operational burden of information assurance and provide an effective early warning of threats.
