We assess and document compliance to:

  1. H.I.P.A.A.

  2. Sarbanes-Oxley (SoX)

  3. Gramm-Leach-Bliley Act (GLBA)

  4. Payment Card Industry (PCI) Data Security Standard

  5. N.I.S.T SP 800-30

  6. I.S.O. 27001/I.S.O. 17799

  7. SAS 70

  8. FERPA

  9. FISMA

  10. NERC

  11. Safe Harbor Act

N.I.S.T. - SP 800 - 30

The principal goal of an organization’s risk management process should be to protect the organization and its ability to perform their mission, not just its IT assets. Therefore, the risk management process should not be treated primarily as a technical function carried out by the IT experts who operate and manage the IT system, but as an essential management function of the organization.

Risk is the net negative impact of the exercise of a vulnerability, considering both the probability and the impact of occurrence. Risk management is the process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level.

Risk is a function of the likelihood of a given threat-source’s exercising a particular potential vulnerability, and the resulting impact of that adverse event on the organization.

To determine the likelihood of a future adverse event, threats to an IT system must be analyzed in conjunction with the potential vulnerabilities and the controls in place for the IT system. Impact refers to the magnitude of harm that could be caused by a threat’s exercise of a vulnerability. The level of impact is governed by the potential mission impacts and in turn produces a relative value for the IT assets and resources affected (e.g., the criticality and sensitivity of the IT system components and data). The risk assessment methodology encompasses nine primary steps:

  • System Characterization (NIST SP 800-30 Section 3.1)
  • Threat Identification (NIST SP 800-30 Section 3.2)
  • Vulnerability Identification (NIST SP 800-30 Section 3.3)
  • Control Analysis (NIST SP 800-30 Section 3.4)
  • Likelihood Determination (NIST SP 800-30 Section 3.5)
  • Impact Analysis (NIST SP 800-30 Section 3.6)
  • Risk Determination (NIST SP 800-30 Section 3.7)
  • Control Recommendations (NIST SP 800-30 Section 3.8)
  • Results Documentation (NIST SP 800-30 Section 3.9)

