ISO 27001 Compliance (BS 7799) Service

Through our unique manual process, we're helping Network18 and MakeMyTrip secure their online assets.

To get more information on Security Brigade's Professional Services, Contact Us.

Introduction

Information is critical to the operation and perhaps even the survival of your organization. ISO/IEC 27001 certification will help you to manage and protect your valuable information assets.

ISO/IEC 27001 is the only auditable international standard which defines the requirements for an Information Security Management System (ISMS). The standard is designed to ensure the selection of adequate and proportionate security controls.

Security Brigade's ISO 27001 Compliance service holistically support the adoption of the ISO 27001 standard or certification. Our versatile process and risk-based approach to information security management allows our Clients meet legal, regulatory and statutory requirements with ease.

  • Compliance with International and Industry (ISO 27001, PCI-DSS, RBI, NSE, OSSTMM, CERT-In) regulations.
  • Detailed Recommendations focusing on mitigating immediate threats and suggesting best-practice recommendations to prevent future events.
  • Drives Your Teams to deliver security aware products and services that can meet your organizational security requirements.
  • Reduced Risk of intentional or accidental misuse of sensitive data or internal assets.
  • Superior Level of confidentiality, integrity and availability of organizational information in-order to facilitate maintenance of competitive edge, cash-flow, profitability and corporate reputation.
Some of Our Unique Value Propositions
Experience
Average 8 years of industry experience per consultant.
Free Re-Testing
Ensures the detected vulnerabilities are correctly patched.
Customized Reports
With source-code examples in your development language along with patch and configuration details.
Hybrid Approach
Delivering experienced consultants coupled with ground-breaking automated processes.
Identifying the "True Impact"
Get a real-world perspective on your threat assessment.
Enhanced Remediation
Detailed remediation information for your specific infrastructure.

Approach

At Security Brigade, all engagements are carried out by experienced consultants that utilize a combination of in-house developed, commercial and open-source tools to deliver maximum value. Our methodology is aligned to industry best-practices and aim to not just meet, but go well beyond regulatory and compliance requirements.

Our Approach

Our ISO 27001 Compliance (BS 7799) Service methodology is an in-depth process that has been built through experience and thorough understanding of customer requirements.

[+] Read More

  • Pre-Assessment Analysis
  • Detailed Requirement Analysis
  • Application Architecture Review
  • Data Analysis and Identification
  • Staff Interviews and Functional Understanding
  • Threat Profiling & Risk Identification
  • Project Prioritization
  • ISMS Plan Development
  • Policy, Checklist, Documentation Development
  • Action Plan Development
  • ISMS Plan Implementation
  • Project Completion Audit
  • Report Generation
  • Support

Technical Experience

Security Brigade has had the privilege of working with a large number of customers with varied operational environments. As a result, our consultants have broad technical experience and some of the environments we have worked with are listed below.

[+] Read More

Operating Systems: Windows Server 2000, 2003, 2008, Redhat Linux, Sun Solaris, HP-UX, IBM AIX, Open VMS, Novell Netware, Open Enterprise Server, Suse Linux, IBM OS/2, Win NT, SCO Unix, SCO OpenServer, IRIX, FreeBSD, OpenBSD, NetBSD, OpenSolaris.
Databases: Oracle, SQL Server, IBM DB2, MySQL, PostgreSQL, Sybase, Access, SAP DB, Interbase, Ingres, Informix.
Firewalls: Cisco PIX/ASA, Checkpoint, Netscreen, Watchguard, Sonicwall, Fortigate, Web Application Firewalls.
Intrusion Detection Systems: ISS RealSecure, Cisco Secure, Dragon IDS, Fortinet, Snort, Sourcefire, Checkpoint RealSecure.
Network Devices: Routers, Firewalls, Switches, IDS/IPS, Load Balancers, Layer 7 Switches.
VoIP Devices: VoIP Routers, IP Phones, PSTN Gateways, ISDN Gateways, PBX Gateways, VoIP Switches, SIP Phones, H.323 Gateways.
Wireless Devices: Wireless Access Points, Wireless Routers, Wireless Bridges, Wireless Switches and Controllers, Wireless IPS, Wireless Client Devices.
Applications: ASP, .NET, PHP, Ruby, Perl, Python, C#, Java, C/C++, Delphi.
Web Servers: IIS, Apache, Tomcat, Netscape Enterprise, Caucho Resin Server, IBM HTTP Server, Lotus Domino HTTP Service, JRun, lighthttpd, Oracle HTTP Server, Sun Web Server, WebLogic.
Messaging Servers: Microsoft Exchange, Sendmail, Qmail, Lotus Domino, Blackberry Enterprise Server.
Others: Microsoft Sharepoint, SAP, Active Directory, ISA Proxy, Squid Proxy.
Mobile Devices: PDAs, Blackberies, Notebook Computers, Netbooks, Pocket PCs, Smart Phones, Tablet PCs, Microsoft Mobile Servers, Blackberry BES/MDS Servers.
SAP Systems: SAP R/2, R/3, BOBJ, APO, AFS, BW, BI, CCM, CC, CI, EBP, EL, EP, XI, etc.


In-House Tools for ISO 27001 Compliance (BS 7799) Service

One of our core strengths has been our ability to adapt to challenging customer environments and requirements. We have been able to consistently meet these challenges through a strong process of research and development. Some of the many tools we have developed over the years are given below.

[+] Read More

sdFinder - Identifies internal hosts on non-contiguous IP ranges. It allows us to detect sensitive information about our clients commercial, intranet and extranet networks.
webDiscovery - Identifies as many applications as possible on Client web-servers. The applications discovered through webDiscovery allow us to provide a superior web application security testing service than competitive services and products. It allows us to increase the scope of the audit and cover more areas that could be attacked by malicious users; that would not be covered by a traditional audit.
networkMapper - Network Mapper uses proprietary technology to be able to identify alternative network routes to bypass security mechanisms such as IDS/IPS/Firewall etc. It allows our experts to bypass existing security implementations and gain direct access to the systems behind them.
webTester - Utilizes our Benchmark Development System to ensure that we can identify maximum vulnerabilities in applications through automated mechanisms. Along with flaws that are known, it uses in-house research to test for vulnerabilities that are not in the public domain. It allows us to automate the process of identifying and testing known and unknown vulnerabilities in web-applications and strike a cost-effective time to effort ratio.
VA Framework - Integrated solution developed by our security experts that have an expertise in the vulnerability assessment domain. It allows us to integrate the manual and automated testing processes with commercial and open-source software. Our Integrated Reporting Engine allows us to cross-reference information from all the different components and generate a report based on our Client's requirements.
PT Framework - Integrated solution developed by our security experts that have an expertise in the penetration testing domain. It allows us to integrate the manual and automated testing processes with commercial and open-source software. Our Integrated Reporting Engine allows us to cross-reference information from all the different components and generate a report based on our Client's requirements.
webSpider - Uses advanced HTML, Java Script, Ajax, Flash and XML parsing engines to identify and map as much of the client applications as possible. This not only assists our automated webTester engine, but also assists in carrying out the manual testing process in an efficient manner. It allows us to attain a cost-effective balance between thorough testing and time required.
sapScan - Security and Configuration Assistant for SAP Security Audits.
riskReview - General Risk Assessment Tool.
erpInterrogate - ERP Security and Configuration Assessment and Control Tool.
Windows Batch Scripts - Windows batch scripts to automate routine server hardening functions and processes.
Linux Bash Scripts - Linux Bash scripts to automate routine server hardening functions and processes.
Oracle Security Assessment Scripts - Oracle Security Assessment Scripts to automate routine hardening functions and processes.
MSSQL Security Assessment Scripts - MSSQL Security Assessment Scripts to automate routine hardening functions and processes.
Internal Vulnerability Database - Automated vulnerability database that is updated every 15 minutes from over 100 public and 20 private feeds.
SQL Explorer: identifies vulnerabilities in and retrieves data from MSSQL, MySQL, Oracle, PostgreSQL, MS Access etc database servers.

Case-Studies

ISO 27001 Implementation Services for a Manufacturing Company


Security Brigade implemented ISO 27001 for a Manufacturing Company. This case study highlights the techniques and processes implemented to meet the Client's key business goals while ensuring that their business was equipted to meet all the challenges put forward by the ISO 27001 Standard.

Download PDF

ISO 27001 Auditing Services for a Financial Brokerage


Security Brigade audited the ISO 27001 Implementation for a financial brokerage. This case study highlights the techniques and processes implemented to meet the Client's key business goals while ensuring that the Gaps in their policies and processes were identified, documented and rectified.

Download PDF

ISO 27001 Implementation Services for a Software Development Company


Security Brigade implemented ISO 27001 for a Software Development Company. This case study highlights the techniques and processes implemented to meet the Client's key business goals while ensuring that their business was equipted to meet all the challenges put forward by the ISO 27001 Standard.

Download PDF

Deliverables

Security Brigade's reporting process is industry-unique and aims to deliver maximum value to your organization and the administrations / developers directly interacting with the security audit. Each report is customer-specific and contains detailed information, proof of concepts, source code examples and configuration details with the aim of educating your IT teams for the long-term. The following are some of the deliverables you will receive on completion of a ISO 27001 Compliance (BS 7799) Service.

Executive Summary


Provides a holistic overview of the entire process implemented to help the organization meet its compliance targets. In-addition, it highlights the best practice recommendations and action-items to sustain the same for the future.

Download PDF

Technical Report


Provides a detailed report of the gaps identified in the organizations process and policies along with the recommendations, action items and best-practices implemented to help the organization meet its compliance requirements.

Download PDF

Action Items Tracker


Simple and comprehensive action item tracker aimed at helping management keep track of the recommendations, milestones and goals set to achieve their compliance requirements.

Download PDF

Best Practice Recommendations Report


Provides a series of best-practice recommendations based on the organizations current compliance and security posture focusing on taking the same to the next level.

Download PDF

Request a Call

Telephone: +91-022-23532909 | Contact Us | Twitter | Linked In
Security Consulting | Penetration Testing | Web Application Security | CERT-IN Empanelled | Privacy Policy
Copyright © 2007-2013 by Security Brigade InfoSec Pvt. Ltd. All rights reserved.