Get a Good Overview Quickly
Determine the current state of your information security and identify potentials for improvements or as a starting point for InfoSec initiatives.
We use established and internationally proven standards as the basis for the assessments. Assessment profiles for different industries, company sizes, and strategic protection goals of the customer are utilized.
The assessments are suitable for further use in strategic and operational planning, including budgeting for information security initiatives or projects such as introducing Information Security Management Systems (ISMS). The reports can be shared with third parties as needed to demonstrate the organization's current state of information security.
Identify
Are all information assets known? Are inventories maintained? Is there a risk management process, and what is the attitude of the executive management to information security? Is it taken into account in corporate strategy? Is shared responsibility with Cloud Service Providers managed?
Protect
How are assets protected against cyber and non-cyber threats? What preventive measures, concepts, and protection of a technical and organizational nature are implemented?
Detect
How are anomalies, deviations from baselines, and attacks in the IT system landscape detected?
React
How are anomalies, vulnerabilities, and incidents responded to and managed?
Recover
In the event of successful attacks against the organization, how will normal operations be restored and damage minimized? Can basic operations be maintained even in emergencies and disasters?
We use the outcomes to defined control questions to determine the status of the individual aspects of information security. The result is a report with risk scores and recommendations for improving information security.
The reports can serve as a basis for planning an ISMS implementation project, for example in accordance with ISO 27001 as results of the individual chapters and questions can be linked to ISO requirements.
For the automotive industry and its business partners, such as suppliers, dealers, or service providers (e.g. advertising agencies), the ISA catalog published by the ENX Association on the TISAX standard serves as the basis for the assessment. The results of the (self-)assessment according to TISAX can be used directly for further project progress, such as establishing an ISMS.