Security Services

Security

Flexible Computing Ltd is a specialist consultancy devoted to advising Commercial, Utility and Government organizations on Information Security. Our high quality independent advice is founded on deep experience in computer and network systems design, development, operation, requirement definition and procurement. This is combined with highly specialist security experience covering:

  • Computer security evaluation (Formal and semiformal)
  • Risk assessment and policy design
  • Cryptography
  • Security Architectures
  • Business continuity
  • Secure Operating Systems
  • Secure products

As we do not sell any security products we benefit clients by designing lower risk and cost solutions to security objectives when appropriate. We have tailored this work for clients ranging in size from international financial organizations through to small entrepreneurial partnerships. Our staff have worked for the computer electronics security group (CESG) within GCHQ as well as international Funds transfer companies thus understanding very different client security priorities.

We can supply consultants registered and monitored by GCHQ's CESG under CLAS (CESG Listed Adviser Scheme). British Computer Society Chartered Engineers and the corresponding European Engineering charters (FEANI) are available. In this way we deliver a high quality of security support to all our customers.

 

Security Services

  • Secure product or system reviews (health-checks to full design)
  • Security risk analysis & assessment (structured)
  • Network (& Internet) security & architecture design or get well analysis
  • Security policy produced in light of legislation, and standards (BS7799 / CESG)
  • Secure product / service agreement specification
  • Business continuity planning
  • Secure operating procedures
  • Product or system security evaluation planning (ITSEC, Common Criteria)
  • Tender evaluation
  • Security implementation strategy
  • PKI design and implementation
 

Do I Need Security?

Do you need information security? Well, how strong and appropriate is your current security? Who tells you it is secure and how do they know? Do you know what security breaches are costing now? Is it flexible enough so that it does not limit the business? Think of information availability:-

Appropriate availability (entitlements)

Should all your employees see everything? Is everyone you communicate with entitled to see all the information on your network? Does your business hold personal data? Can your competitors see it? Can you assure appropriate protection to partner organisations?

Correct information available (integrity)

Do clients and business partners rely on that information being correct? Why do they trust your business? What if your information is corrupted, will your business notice - in time, can you correct it. How much time and effort will it cost? Will you lose business, pay penalties, and what about your reputation? What other business processes are disrupted? In e-commerce can you show they really made that electronic order? Is that really the right person or server?

Timely availability (availability)

How much will it cost the business if it's not available for an hour, a day, or a month? What about clients? How patient are they?

   

How Can We Help Your Security?

When you ask who could help, think about what security means to you. The clear definition of your security objectives in light of your business trust environment is key. Without this, IT security becomes a minefield of salesman claiming their product as the wonder palliative to the latest publicised threats.

Many consultancies sell products, with their staff being little more than product installers. Other advisers (often auditors) will happily derive a risk assessment and security policy with no experience of the operational costs or risks of developing the implied security architecture. Often they run through elaborate security risk methods which obscure the reasoning. This also makes the assessment difficult to cater with changes in the objectives, threats or vulnerabilities.

Thus, to review information security or conduct a re-useable risk assessment and devise the security architecture requires:

  • Operational and technical development experience
  • Security evaluation experience
  • Policy and risk assessment experience in government or commercial fields
  • Unbiased advice
 

Security Evaluations

Depth and breadth

For the depth of experience we have developed software systems that have met extremely high reliability needs (Non-Stop and clustered architectures) together with X.400 message handling systems using kernel software and Transaction Processing middleware for high performance scalable systems.

This involved an in-depth understanding of software and systems together with all the networking layers. This has been complimented with n-tier system architecture work to develop security architectures for distributed high user systems. Different topologies have covered centralized networks as well as Extranet and Intranet IP architectures, together with legacy systems and leased lines. PKI security objectives and solutions have been devised for clients that both need their own Certification Authority and others whose needs can link with third party CAs.

Business areas

We have covered the following, which involve a variety of risk philosophies:

  • Finance (international) - Information providers (international) - Media Telecommunications - Government (& Research) - Police and Utilities.

The scale of organisations covered is also wide ranging through:

  • Tri-national projects - 2 man partnerships - FTSE100 - International finance organisations.

For larger client organisations the above choices have been synthesized and explained leading to approval by Management committees. This involves derivation of security policies, objectives and associated risk assessments appropriate to business drivers.

Security evaluation

Our staff helped form the first ITSEC licensed evaluation facility in the UK which independently evaluates security systems and products against internationally agreed criteria. Furthermore our principle helped in the DTI working groups that developed the latest Common Criteria standards as well as the only standard world-wide for security management: BS7799.

   

More Articles...

Page 1 of 2

Banner

News Flash

  • Size Zero IT - Service Release

    Flexible Computing's Latest Innovation on IT Development - Size Zero IT

    We have created a new unique service to assist any established or start up company to develop new IT services. We can provide the following services for no startup costs;

    Read more... Link  
  • 10K Virtuoso's

    Super Powered Hopeful Individual - Individually Capable of Changing the World


    I was asked the other day 'What would you describe as the key aspect of an Enterprise Architect role?' and in a separate conversation 'What did you do before you got into IT?'

    After a little thought and watching an inspiring presentation by Jane McGonigal a 'Super Powered Hopeful Individual' because;

    Read more... Link  
JoomlaWatch Stats 1.2.9 by Matej Koval