- Secure product or system reviews (health-checks to full design)
- Security risk analysis & assessment (structured)
- Network (& Internet) security & architecture design or get well analysis
- Security policy produced in light of legislation, and standards (BS7799 / CESG)
- Secure product / service agreement specification
- Business continuity planning
- Secure operating procedures
- Product or system security evaluation planning (ITSEC, Common Criteria)
- Tender evaluation
- Security implementation strategy
- PKI design and implementation
Do you need information security? Well, how strong and appropriate is your current security? Who tells you it is secure and how do they know? Do you know what security breaches are costing now? Is it flexible enough so that it does not limit the business? Think of information availability:-
Appropriate availability (entitlements)
Should all your employees see everything? Is everyone you communicate with entitled to see all the information on your network? Does your business hold personal data? Can your competitors see it? Can you assure appropriate protection to partner organisations?
Correct information available (integrity)
Do clients and business partners rely on that information being correct? Why do they trust your business? What if your information is corrupted, will your business notice - in time, can you correct it. How much time and effort will it cost? Will you lose business, pay penalties, and what about your reputation? What other business processes are disrupted? In e-commerce can you show they really made that electronic order? Is that really the right person or server?
Timely availability (availability)
How much will it cost the business if it's not available for an hour, a day, or a month? What about clients? How patient are they?


