Formal assessment of information security
This service is designed for Clients who want to assess only formal aspects, such as procedures and documentation related to IT security, without looking into technical issues, unlike in integrated security assessments.
The aim of the service is to assess formal security controls (procedures, documentation, accountability) and to identify vulnerabilities in these areas. This assessment covers the technical path of the LP-A methodology (a methodology for performing IT security audits). Its scope is tailored to the character of the analysed subject. It includes among others:
- conducting interviews with people responsible for respective security areas,
- filling in the check list of the norm PN/ISO 17799 (or Annex A to the norm PN/ISO 27001).