Infrastructure Solutions

Security Assessment

A security assessment is an excellent tool for identifying the types of threats an organization faces and evaluating the measures to be taken to address them in a cost effective manner.

Our security assessment looks at an organization's business environment, the threats it faces, and the effectiveness of the security measures that are in place. We also offer assessment services to help clients comply with legislative and regulatory requirements such as FRCP, FRE, SOX, GLBA, SEC, NASD and HIPAA.

Micro Strategies' security assessment provides an independent "set of eyes" that are not inappropriately influenced by an organization's history or internal dynamics.

Recommended steps include:

  • Identifying the threats and establishing an approach for a secure IT infrastructure and data assets;
  • Developing and implementing a security program to assure that it is achieving the stated management goals;
  • Having a mechanism to assure that a security program is maintaining pace with an ever-changing security threatened environment.

The assessment process and deliverables are tailored to each client's needs and include a report on the client's business environment from an IT security perspective, the significant threats that have been identified, the effectiveness and cost efficiency of the existing security program, and recommendations for improvement.

Security Assessment Programs are also offered to help clients mitigate security breaches often caused by their "inside users." About 70% of all security breaches are initiated by the inside user committing either an unintentional or intentional act. Typically, the inside user has access to the network, critical data and/or confidential information, and is trusted; which makes him or her essential elements of a secure environment.

A strong Security Assessment Program includes:

  • Training to help make employees aware of a broad range of external and internal security risks they face and ways to thwart them;
  • Establishing and implementing a set of company-appropriate user policies that establish security guidelines and minimum standards, and providing initial and ongoing training to the users on the approved policies;
  • Measuring the user's level of security awareness and the effectiveness of the policies and their implementation, and taking corrective action where necessary.