Business Continuity Management Service
Our security services are helping the IRDA to securely manage India's Largest Insurance Portal.
Introduction
BCM is a management process that identifies potential impacts that threaten an organization and provides a framework for building resilience and the capability for an effective response which safeguards the interests of its key stake holders, reputation, brand and value creating activities.
Security Brigade's Business Continuity Management (BCM) helps organizations to analyse and implement comprehensive business continuity plans to ensure the availability of critical business processes. It is based upon the risk to organizations critical business process drivers. Our business continuity approach incorporates industry best practices and is compliant to BS 25999 standards.
- Customer Specific reports with clearly outlined responsibilities and detailed remediation steps including device specific commands/patches and source-code examples.
- Detailed Recommendations focusing on mitigating immediate threats and suggesting best-practice recommendations to prevent future events.
- Delivering Experts with the correct experience and domain-expertise to meet your security requirements.
- Prevent Loss of customer information, trust and organizational reputation.
- Reduced Risk of intentional or accidental misuse of sensitive data or internal assets.
Approach
Security Brigade's Business Continuity Management Service approach is based on best practices and well-developed methodologies while incorporating sophisticated testing software, methodology and experienced consultants - A blend of best practices and proprietary process. In-addition, our continual innovation through research & development ensures a thorough check of your system and application infrastructure.
Our Approach
Our Business Continuity Management Service methodology is an in-depth process that has been built through experience and thorough understanding of customer requirements.
|
|
Technical Experience
Security Brigade has had the privilege of working with a large number of customers with varied operational environments. As a result, our consultants have broad technical experience and some of the environments we have worked with are listed below.| Operating Systems: Windows Server 2000, 2003, 2008, Redhat Linux, Sun Solaris, HP-UX, IBM AIX, Open VMS, Novell Netware, Open Enterprise Server, Suse Linux, IBM OS/2, Win NT, SCO Unix, SCO OpenServer, IRIX, FreeBSD, OpenBSD, NetBSD, OpenSolaris. |
| Firewalls: Cisco PIX/ASA, Checkpoint, Netscreen, Watchguard, Sonicwall, Fortigate, Web Application Firewalls. |
| Intrusion Detection Systems: ISS RealSecure, Cisco Secure, Dragon IDS, Fortinet, Snort, Sourcefire, Checkpoint RealSecure. |
| Network Devices: Routers, Firewalls, Switches, IDS/IPS, Load Balancers, Layer 7 Switches. |
| Wireless Devices: Wireless Access Points, Wireless Routers, Wireless Bridges, Wireless Switches and Controllers, Wireless IPS, Wireless Client Devices. |
| Others: Microsoft Sharepoint, SAP, Active Directory, ISA Proxy, Squid Proxy. |
| Mobile Devices: PDAs, Blackberies, Notebook Computers, Netbooks, Pocket PCs, Smart Phones, Tablet PCs, Microsoft Mobile Servers, Blackberry BES/MDS Servers. |
In-House Tools for Business Continuity Management Service
| sdFinder - Identifies internal hosts on non-contiguous IP ranges. It allows us to detect sensitive information about our clients commercial, intranet and extranet networks. | ||||||||
| webDiscovery - Identifies as many applications as possible on Client web-servers. The applications discovered through webDiscovery allow us to provide a superior web application security testing service than competitive services and products. It allows us to increase the scope of the audit and cover more areas that could be attacked by malicious users; that would not be covered by a traditional audit. | ||||||||
| networkMapper - Network Mapper uses proprietary technology to be able to identify alternative network routes to bypass security mechanisms such as IDS/IPS/Firewall etc. It allows our experts to bypass existing security implementations and gain direct access to the systems behind them. | ||||||||
| webTester - Utilizes our Benchmark Development System to ensure that we can identify maximum vulnerabilities in applications through automated mechanisms. Along with flaws that are known, it uses in-house research to test for vulnerabilities that are not in the public domain. It allows us to automate the process of identifying and testing known and unknown vulnerabilities in web-applications and strike a cost-effective time to effort ratio. | ||||||||
| VA Framework - Integrated solution developed by our security experts that have an expertise in the vulnerability assessment domain. It allows us to integrate the manual and automated testing processes with commercial and open-source software. Our Integrated Reporting Engine allows us to cross-reference information from all the different components and generate a report based on our Client's requirements. | ||||||||
| PT Framework - Integrated solution developed by our security experts that have an expertise in the penetration testing domain. It allows us to integrate the manual and automated testing processes with commercial and open-source software. Our Integrated Reporting Engine allows us to cross-reference information from all the different components and generate a report based on our Client's requirements. | ||||||||
| webSpider - Uses advanced HTML, Java Script, Ajax, Flash and XML parsing engines to identify and map as much of the client applications as possible. This not only assists our automated webTester engine, but also assists in carrying out the manual testing process in an efficient manner. It allows us to attain a cost-effective balance between thorough testing and time required. | ||||||||
sapScan - Security and Configuration Assistant for SAP Security Audits.
| riskReview - General Risk Assessment Tool.
| erpInterrogate - ERP Security and Configuration Assessment and Control Tool.
| Windows Batch Scripts - Windows batch scripts to automate routine server hardening functions and processes.
| Linux Bash Scripts - Linux Bash scripts to automate routine server hardening functions and processes.
| Oracle Security Assessment Scripts - Oracle Security Assessment Scripts to automate routine hardening functions and processes.
| MSSQL Security Assessment Scripts - MSSQL Security Assessment Scripts to automate routine hardening functions and processes.
| Internal Vulnerability Database - Automated vulnerability database that is updated every 15 minutes from over 100 public and 20 private feeds.
| SQL Explorer: identifies vulnerabilities in and retrieves data from MSSQL, MySQL, Oracle, PostgreSQL, MS Access etc database servers. | |
Case-Studies
Business Continuity Management Solutions for a Financial Services Firm Security Brigade implemented Business Continuity Management Solutions for a Financial Services Firm. This case study highlights the techniques and processes implemented to meet the Client's key business goals while helping them meet their BCP DR targets and timelines. | |
Business Continuity Management Solutions for a Insurance Company Security Brigade audited the Business Continuity Management Plan for an Insurance Company. This case study highlights the techniques and processes implemented to meet the Client's key business goals while ensuring that their BCP DR Plan was functional and would work succesfully in-case of a disaster. | |
Business Continuity Management Solutions for a Stock Exchange Security Brigade implemented Business Continuity Management Solutions for a Stock Exchange. This case study highlights the techniques and processes implemented to meet the Client's key business goals while helping them meet their BCP DR targets and timelines. |
Deliverables
Security Brigade's reporting process is industry-unique and aims to deliver maximum value to your organization and the administrations / developers directly interacting with the security audit. Each report is customer-specific and contains detailed information, proof of concepts, source code examples and configuration details with the aim of educating your IT teams for the long-term. The following are some of the deliverables you will receive on completion of a Business Continuity Management Service.
Executive Summary Provides a holistic overview of the entire process implemented to help the organization meet its compliance targets. In-addition, it highlights the best practice recommendations and action-items to sustain the same for the future. |
|
Technical Report Provides a detailed report of the gaps identified in the organizations process and policies along with the recommendations, action items and best-practices implemented to help the organization meet its compliance requirements. |
|
Action Items Tracker Simple and comprehensive action item tracker aimed at helping management keep track of the recommendations, milestones and goals set to achieve their compliance requirements. |
|
Best Practice Recommendations Report Provides a series of best-practice recommendations based on the organizations current compliance and security posture focusing on taking the same to the next level. |
Request a Call
Business Continuity Management Solutions for a Financial Services Firm
Business Continuity Management Solutions for a Insurance Company
Business Continuity Management Solutions for a Stock Exchange
Business Continuity Management Service
Executive Summary
Technical Report
Action Items Tracker
Best Practice Recommendations Report

+1-347-994-8732
+91-022-23532909