Security
Certification Program |
|
 |  | |  |
|
| The
Purpose |
Reduce
the time and money spent on security-related audits. Perform a single
rigorous assessment. Capture, store, and present key security audit
findings. Satisfy the reporting demands of government, industry,
partners, and customers. Communicate your compliance to them. |
| Value
to You | Save
time and money with a single assessment. Get quarterly check-ups to
make sure you're up to date. Have confidence in open standards. |
| How
We Work | Conduct
a comprehensive compliance assessment. Identify the problems you need
to fix. Verify the fixes with a complete audit. |
| The
Results | A
single, comprehensive analysis. A custom report for each audit request.
Access to the Security Compliance Repository. A strategy to remain in
compliance. Quarterly reviews. The Alawy Security Certification Seal. |
| Why
Alawy | The
only company to offer certification based on open standards. Our focus
is on secure connections and transactions over worldwide communications
networks. | | Next Steps | To
talk with us about security and your business, call (860) 859-3564 (U.S.)
or visit the Middle East. You
can also submit your inquiry online.
Or, see the Security
Consulting Services Overview. |
Save time and money with a single security
assessment based on open standards. You receive a single, comprehensive analysis
with a strategy to remain in compliance and a custom report for each audit
request. Get quarterly check-ups to make sure you stay up to date.
The
Purpose
Our Security Certification
Program can help reduce the number of separate security audits you have
to go through each year.
The Security Certification
Program is the cornerstone of Alawy’s compliance management solutions,
which encompass:
- Assessment services
- Monitoring services
- Vulnerability
management services
The goal of the
compliance management solutions is to help you better manage your
ongoing compliance management practices.
A
Single Assessment
Government regulations and industry standards share many common
elements. We’ve consolidated the most common requirements into a single
program. We conduct a single enterprise compliance assessment covering
many of the regulations and standards that apply to you. For an
overview of the regulations and standards we can include, see Compliance and Your Business.
A
Comprehensive Report
We provide you with a comprehensive analysis report. The analysis is
designed to satisfying the audit demands of any governmental regulatory
agency, standards certification organization, business partner, or
customer that wants to verify how you comply with each requirement.
Back
to top
Value
to You
A
Single Assessment to Satisfy Scores of Audits
If you face many audits each year. You don’t need to start from scratch
for each one. We conduct a single, rigorous, and complete assessment.
The Security Certification Program focuses on collecting and
centralizing key audit results—so that they can be examined again and
again whenever an audit is necessary.
Save
Time and Money
Centralizing key audit data means that you can provide reports of with
the appropriate detail and in the appropriate format to auditors,
regulators, industry groups, business partners—and any other
organization that requires them. With centralized data, you save time
and money without sacrificing compliance.
Quarterly
Check-Ups
We also perform quarterly check-ups to make sure you keep up to date as
regulations and standards evolve.
Open
Standards
The Security Certification Program is based on open standards generally
recognized throughout the industry. Certification means something not
because we say so, but because you follow standards that are open and
transparent.
Standard
and Customized Reports
We develop standard and customized reports that can satisfy government,
industries, and partners.
Back
to top
How
We Work
- We
conduct a thorough compliance assessment. For
details, see Enterprise
Compliance Assessments.
- We
identify what you need to fix. Our
recommendations identify the requirements you need to satisfy in order
to comply. We also rank them by how effectively they advance your
business goals. We rate each recommendation by its cost-effectiveness
and by how easy it is to implement.
- We
conduct a complete audit. After
you’ve corrected the problems we’ve identified, we help asses whether
you’re in compliance.
Back
to top
The
Results
A
Comprehensive Analysis Report
After you pass the comprehensive audit, we provide you with a
comprehensive analysis report certifying compliance.
A
Strategy
You get a strategy for achieving compliance—not just a pass-or-fail
audit. We help identify what you need to do immediately to comply—and
we help you set goals for six months out so you remain compliant. We
map out a complete plan for one and two years out to help you evolve as
regulations change. We also help you track changes in your plan and
assess its long-term effectiveness.
Quarterly
Reviews
We review your policies, procedures, and technical infrastructure once
each quarter to make sure you remain compliant.
Back
to top
Why
Alawy
Alawy offers security certification based on open standards according
to regulations and industry practice. Alawy has worked to secure the networks
of Fortune 500 companies in the financial, energy, insurance, media and consumer
goods sector in the United States. A significant amount of this experience
has been within the financial services and banking sectors—assessing
infrastructure security and architecting and deploying secure solutions. We
participate in the FBI's InfraGard as advisers in threat and security matters.
Our Security Consultants are Software Engineers trained in Information Security.
They understand systems architecture. They see the whole picture. We’re
not a software company limited to our own line of products. We provide our
clients with the solution that best fits their business and budget needs. We
do not cater to a "one size fits all" approach. Our focus is on protecting
the sensitive information you are trusted to safeguard -- information belonging
to your business and your clients -- from malicious theft or careless mishandling.
Security isn't just about security; it's about your business. We focus on
providing solutions tailored to your corporate goals and the real threats you
face. Read about Our
Approach - the foundation for all our work.
Focus on your business:
- We help you stay competitive. We use our knowledge and experience to benchmark
your risk against your industry.
- We value actions by their consequences. Our focus is consequences, not
just risk.
- We focus on our relationship with our customers. Our goal is to be your
trusted security advisor.
- We provide recommendations that are vendor independent to give you the
freedom to implement the solution that suits you best.
- We help you stay competitive. Our business is security, not just consulting.
Focus on our experience:
- We have a wide variety of clients in
a broad range of industries.
That exposes us to the need for many different architectures, designs, and
solutions.
/clients/index.jsp are IT security professionals who’ve worked with
Fortune 500 companies or in the financial, energy, insurance, media and consumer
goods industries.
- Our team of consultants is made up of Certified Information System Security
Professionals (CISSPs).
Back to top
|