Development of an ISMS and preparation for certification according to ISO 27001 often present organisations with considerable challenges. The many security problems and gaps which are present within an organisation are often not known in advance and are only discovered gradually during preparation for the certification itself. This means that the generation and continuous adaptation of the documentation which is relevant to certification costs a great deal of time and money. To accelerate the development of your ISMS, TÜViT offers you a useful entry into the IT security process in the form of an assessment. The assessment procedure is based on technical tests (using tools for network and system analysis), augmented by relevant interviews and inspections on site.
Our service
Definition of the items to be examined
Analysis of the IT values
Identification of risk areas
Security Scans using tools for network and system analysis
Interviews on defined subjects with the relevant experts
On-site inspections and configuration analyses of technical systems
Statistics for documenting the level of implementation of the management framework for IT security acc. ISO 27001
Statistics for documenting the level of implementation of the safety measures in accordance with ISO 27001 (Annex A) and ISO 27002
Description of the threats and weaknesses which have been identified
Recommendations for improvement of the management framework for IT security and of the IT security itself
Drafting of the procedure for entry into the ISMS certification process according to ISO 27001
Detailed reporting and presentation of results on site
Benefits/Usefulness to you
Structured procedure focused on most fundamental security aspects
Efficient discovery of weaknesses within the IT security system and its management processes prior to or during use of standards ISO 27001 and ISO 27002
Suggestions on how to eliminate security problems with targeted recommendations
Early recognition of fundamental obstacles to the realisation of a sustainable IT system which is always appropriate to requirements
Reduction of costs for development of an ISMS according to ISO 27001 and ISO 27002
The procedure
Documentation analysis
Security scans
Configuration analyses
Inspections
Interviews
Reporting
The objective
Control of scheduling and budget within the ISO 27001 certification process
Increase in the effectiveness and efficiency of your ISMS project
Your contacts:
IT Security Mr. Dipl.-Ing. Adrian Altrhein Leimbachstraße 227 57074 Siegen Germany Phone: +49 271 3378 - 195 Telefax: +49 271 3378 - 197 Send secure email