Insight on. The Indispensable Information Security Toolkit. If you are responsible for information security how useful would you find the following?

Size: px
Start display at page:

Download "Insight on. The Indispensable Information Security Toolkit. If you are responsible for information security how useful would you find the following?"

Transcription

1 Insight on The Indispensable Information Security Toolkit If you are responsible for information security how useful would you find the following? A database of over 3,000 security controls covering all aspects of information security, cross referenced to the risks they protect against and ranked by effectiveness and cost. A set of tools to support you in achieving certification or compliance against BS 7799 (The British Standard of Information Security) and also ISO (the equivalent international standard). A comprehensive risk assessment method fully compliant with BS Pro-forma information security polices and other useful security documentation. Tools to help you with business continuity planning. The ability to quickly find answers to a wide range of security questions such as: What level of authentication is required for our new e-business application? How can I assess what cryptographic services are required? Does our existing security infrastructure provide adequate protection for our new ERP system? Is the physical security at our data centre adequate? How can I justify security expenditure to the board? You might be happy to find cost-effective support in any of the above areas. However Insight Consulting provides all of these in one amazing package, the CRAMM Version 4 Information Security Toolkit. Insight, the UK s leading provider of independent services and solutions in information security, business continuity and risk management has taken CRAMM, the UK Government s preferred risk assessment method, and completely re-developed it into an indispensable aid for the security manager or analyst. Insight has incorporated its experience and knowledge base from 100 s of client consultancy assignments into CRAMM Version 4, including its successful methodology for gaining compliance with BS Insight was one of the first organisations to be formally certified for BS 7799, and has helped clients such as the Co-operative Bank's "Smile" Internet Bank, Britannic Money and Energis to achieve certification. At a fraction of the usual cost for tools providing this level of functionality and expert knowledge, CRAMM Version 4 provides fantastic value for money. CRAMM Version 4 is already in use in over 300 organisations in 20 countries. Can you afford to be without it?

2 CRAMM Controls Database The CRAMM Version 4 controls database is hugely valuable in its own right. It covers all aspects of security including technical, physical, personnel, documentation and procedural measures. These controls have been drawn from a wide variety of authoritative sources and recognised standards including the UK Government s Security Authorities, BS7799, the Information Technology Security Evaluation Criteria (ITSEC) and Insight s consultants themselves. Each control is referenced by: The assets for which it is appropriate The type of control, e.g. whether it reduces the threat of, or vulnerability to, security breaches, reduces the impact from these breaches, detects failures or facilitates recovery The risks for which the control is appropriate The effectiveness of the control The cost of the control The BS7799 control objectives that the control supports Users can browse the controls database to identify controls that may be relevant to their business and applications and then explore these in increasing levels of detail. In addition, CRAMM s risk assessment tools can be used to determine whether controls are required, and can be justified, on the basis of the assessed risks. Figure 1: Countermeasure Tree illustrating the hierarchical structure of the CRAMM controls database The CRAMM controls database is regularly updated to keep it in line with the rapid developments in information security processes, standards and technology.

3 BS 7799 Compliance Tools Insight has developed a well-proven methodology to assist organisations to assess their compliance with BS7799 and then take the actions to achieve compliance. Key components of this methodology are incorporated into CRAMM, including: Defining the scope of the Information Security Management System (ISMS) CRAMM s risk assessment tools can be used to answer single questions, to look at organisations, processes, applications or systems, or to investigate complete infrastructure and entire organisations. Users have the option of a rapid risk assessment tool or a full, more rigorous, analysis. Defining the management framework Conducting a Gap Analysis Preparing a Security Improvement Programme Producing a Statement of Applicability Producing an Information Asset Register Undertaking a BS7799 compliant risk assessment Risk Assessment Tools CRAMM includes comprehensive risk assessment tools which are fully compliant with BS7799, including: Asset dependency modelling Business impact assessment Identifying and assessing threats and vulnerabilities Assessing levels of risk Identifying required and justified controls on the basis of the risk assessment Effective risk analysis relies upon comprehensive expertise Figure 2: Screen for recording findings from a gap analysis against BS7799

4 The risk assessment tools are extremely flexible, allowing you to explore different issues and answer many different questions. Example applications of the CRAMM risk assessment tools are as follows: Determine if there is a requirement for specific controls, e.g. strong authentication, encryption, power protection or hardware redundancy Identify the security functionality required for a new application Help in developing the security requirements for an outsourcing/managed service agreement Review the requirements for physical and environmental security at a new site Examine the implications of allowing users to connect to the Internet Demonstrate compliance with legislation, such as the Data Protection Act, which requires the enforcement of appropriate security Develop a security policy for a new system Audit the suitability and status of security controls on an existing system Demonstrate to a BS7799 auditor that a BS7799 compliant risk assessment has been undertaken, and that appropriate security controls have been identified from this. Figure 3: Graphical reporting of business impact analysis CRAMM contains a variety of tools to help with evaluating the findings from the risk assessment, including: Determining the relative priority of controls Recording the estimated costs of implementing the controls Modelling changes to the risk assessment, using what-if? calculations Back-tracking through the risk assessment to show the justification for specific controls.

5 Risk Modelling Where organisations need to undertake many risk assessments on similar environments, (e.g. similar processes, applications, systems, infrastructures or locations) economies of scale can be achieved by using a CRAMM Risk model. A risk model consists of: A generic risk assessment for a typical environment A set of tools to allow the user to quickly bespoke the assessment to their own situation by identifying variances from the generic risk assessment Insight can develop CRAMM Version 4 risk models for any client environment. For example, risk models, developed by Insight for use in the Acute and Primary Care sectors, have been distributed to over 700 NHS users. Business Continuity Tools CRAMM provides tools to support the following key processes in business continuity management and is entirely consistent with the IT Infrastructure Library (ITIL) guidance on Business Continuity Management. Business impact analysis Identification of business recovery objectives Identification of key groups of staff and the time within which they must be operational following a business disruption The minimum facilities and services required by these groups of staff Risk assessment Identification of options for achieving business continuity objectives, including back-up, resilience and stand-by arrangements Pro-Forma Security Policies & Other Security Documentation CRAMM Version 4 contains pro-forma documents and wizards to help the user create a wide range of completed security documentation, including: Information Security Policy A documented Scope for a (BS7799) Information Security Management System A description of the Security Management Framework Risk Analysis Report Risk Management Report System Security Policy Interchange Agreement Reports can be exported directly to MS Word to allow further editing and tailoring. Tailoring Insight can tailor almost every aspect of CRAMM to meet specific client requirements. This can include: A controls database tailored to your own standards, architectures and product sets Security documentation tailored to your own standards Language translations Versions for other risk management subjects such as project risk and corporate governance. For example, Insight has developed tailored versions of CRAMM for the Dutch Government and NATO. Language versions currently exist in Holland and the Czech Republic and are currently in production in German and Chinese. Figure 4: Screen for recording continuity requirements

6 CRAMM Version 4 CRAMM Version 4 Support Services from Insight Consulting Software Licenses Insight Consulting can provide copies of CRAMM Version 4 within 5 working days of an order being placed. A one-time licence fee is payable plus a mandatory annual support fee. The support fee provides access to the CRAMM help desk, which can answer your questions about the tool-set. The Insight help desk is available during normal UK working hours and can be contacted either by telephone, or fax. The support fee also entitles users to all updates, free, as they are released by Insight. Pricing information is available at where orders for CRAMM software can also be placed. Training Insight runs 3-day CRAMM training courses at its offices in Waltonon-Thames, which explore and demonstrate all of the key features and capabilities of the CRAMM V4 tool-kit. The objective of the course is to provide delegates with the skills, knowledge, confidence and hands-on experience to be able to exploit CRAMM Version 4 to its full potential. Tailored and on-site CRAMM courses are run regularly for clients on request. Training places can be ordered on-line at: Consultancy Insight offers a full range of CRAMM consultancy services, including: Tailoring to specific client requirements Support to BS7799 compliance or risk assessment projects that are using CRAMM V4 Quality assurance of security documents produced using CRAMM CRAMM Agents In some territories Insight uses agents to distribute, support and provide training in CRAMM Version 4. Additional agents are being established on a regular basis, but are already in place in: Holland Czech Republic Italy South Africa Switzerland Korea Germany People s Republic of China CRAMM User Group CRAMM has its own, independently managed, CRAMM User Group. The User Group holds an annual conference at different locations around the UK and also runs several special interest groups. The conferences and SIGs are used to promote best practice in the use of CRAMM and to provide a forum for feedback and discussion of future updates. The conferences encompass working meetings, formal presentations, speakers' panels, a reception and dinner with entertainment and, above all, great value for money. Details about the CRAMM User Group can be found at: Further Information Further information is available from Insight on Free CRAMM Version 4 Demonstration Days are held each month. Bookings can be made at ww.insight.co.uk/crammopenday.htm, by ing insight@insight.co.uk or calling Insight Consulting Churchfield House, 5 The Quintet, Churchfield Road, Walton on Thames, Surrey KT12 2TZ Tel +44 (0) Fax +44 (0) web insight@insight.co.uk

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

QMS International. ISO Certification. Ensuring quality. Increasing your competitive advantage. QMS International A Citation Company

QMS International. ISO Certification. Ensuring quality. Increasing your competitive advantage. QMS International A Citation Company QMS International ISO Certification. Ensuring quality. Increasing your competitive advantage. QMS International A Citation Company Who are QMS? What is the Certification Process? QMS is the third largest

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy To ensure the effective availability of essential products and services, BCQ has raised this Business Continuity Policy in support of a comprehensive program for business continuity,

More information

Information Security Policy

Information Security Policy Information Security Policy Issue sheet Document reference Document location Title Author Issued to Reason issued NHSBSARM001 NHS Business Services Authority Information Security policy Head of Security

More information

ISMS AUDIT CHECKLIST

ISMS AUDIT CHECKLIST 4.1 REQUIREMENT REFER TO BS ISO / IEC 27001 : 2005 Has the organisation developed a documented ISMS based on the PDCA model? Checked at Stage 1 for development and Stage 2/surveillance for implementation,

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Number IG001 Target Audience CCG/ GMSS Staff Approving Committee CCG Chief Officer Date Approved February 2018 Last Review Date February 2018 Next Review Date February

More information

Presentation TOPdesk. Rik Prins. TOPdesk Service Management Simplified

Presentation TOPdesk. Rik Prins. TOPdesk Service Management Simplified Presentation TOPdesk Rik Prins TOPdesk Presentation and Demonstration Rik Prins TOPdesk Facts & Figures Established in 1992; UK Office in 2002 Headquarters in Delft, the Netherlands Products London, UK

More information

Mapping ISO/IEC 27001:2005 -> ISO/IEC 27001:2013

Mapping ISO/IEC 27001:2005 -> ISO/IEC 27001:2013 Mapping ISO/IEC 27001:2005 -> ISO/IEC 27001:2013 Carlos Bachmaier http://excelente.tk/ - 20140218 2005 2013 In 2005 0 Introduction 0 Process approach PDCA In 2013 0 No explicit process approach ISMS part

More information

ASSESSMENT AND CERTIFICATION OF SHIP RECYCLING MANAGEMENT SYSTEMS

ASSESSMENT AND CERTIFICATION OF SHIP RECYCLING MANAGEMENT SYSTEMS Page 1/10 1 SCOPE AND FIELD OF APPLICATION This document defines the methods for the auditing, certification, periodic surveillance and recertification of Ship recycling Management Systems compliant with

More information

Information governance strategy

Information governance strategy Information governance strategy January 2018 Version 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment V 1.0 Trevor Duplessis 22/01/18 Due for review Dec

More information

F: Compliance Audit Checklists: Organisational & Management Issues

F: Compliance Audit Checklists: Organisational & Management Issues Page 1 F.1.1 Data Protection Policy (Good Practice Observations Only) a) Does the organisation have a clearly documented statement of Data Protection Policy? b) Does this policy specify the organisation's

More information

Services. Equipment, Software, Training and Validation Services.

Services. Equipment, Software, Training and Validation Services. Life Sciences Nuclear Medicine / PET Services Equipment, Software, Training and Validation Services Radiation Safety Services Minimise downtime and maximise reliability At LabLogic, we understand the need

More information

Risk and risk management

Risk and risk management Risk and risk management In 205 we made changes to our risk management framework to ensure it was fully integrated across the business. Nicholas Anderson Chairman, Risk Management Committee Managing risks

More information

Believe in a higher level of IT Security SECUDE Business White Paper. How to Improve Business Results through Secure Single Sign-on to SAP

Believe in a higher level of IT Security SECUDE Business White Paper. How to Improve Business Results through Secure Single Sign-on to SAP Believe in a higher level of IT Security SECUDE Business White Paper How to Improve Business Results through Secure Single Sign-on to SAP Executive Summary CIOs and IT managers face tremendous demands

More information

FREECERT ISO Certification Scheme Management Standard Presentations. [Type text]

FREECERT ISO Certification Scheme Management Standard Presentations. [Type text] FREECERT ISO Certification Scheme Management Standard Presentations FREECERT ISO Certification Scheme The competitive advantage for your business Page 1 Freecert Scheme Presentation Contents Page 1. Title

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Guidelines for information security management systems auditing

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Guidelines for information security management systems auditing INTERNATIONAL STANDARD ISO/IEC 27007 First edition 2011-11-15 Information technology Security techniques Guidelines for information security management systems auditing Technologies de l'information Techniques

More information

Alcumus ISOQAR. Leading the way in management system certification

Alcumus ISOQAR. Leading the way in management system certification Alcumus ISOQAR Leading the way in management system certification Inspiring confidence in management systems ISOQAR is a leading provider of audit and certification services. For over 20 years, we have

More information

ISO Business Continuity Management. Your implementation guide

ISO Business Continuity Management. Your implementation guide ISO 22301 Business Continuity Management Your implementation guide Build a robust and resilient organization with ISO 22301 It s never been more important to protect your business from the unexpected.

More information

Our approach to Service Charge Examinations

Our approach to Service Charge Examinations Our approach to Service Charge Examinations Contents Our Experience 1 Value Added Services 4 Our Approach 5 About Us 9 SERVICE CHARGE EXAMINATIONS PAGE 2 Our Experience As a Top 5 provider of audit services

More information

Course Specification. Making the Transition to ISO 14001:2015

Course Specification. Making the Transition to ISO 14001:2015 Course Specification Making the Transition to ISO 14001:2015 CONTENTS 1. ABOUT US... 3 2. BACKGROUND... 4 3. COURSE DURATION... 4 4. WHO IS THIS COURSE FOR?... 4 5. MATERIALS AND CERTIFICATION... 4 6.

More information

Topics. Background Approach Status

Topics. Background Approach Status 16 th September 2014 Topics Background Approach Status Background e-governance in India National e-governance Plan 2006 31 Mission Mode Projects Quality Assurance in e-governance Quality Assessment of

More information

Risk Oversight and Management

Risk Oversight and Management Risk Oversight and Management Introduction Nufarm s policies and procedures relating to the management and oversight of risk provide effective management of material risks at a level appropriate to Nufarm

More information

Leading provider of pre-employment screening and background checks

Leading provider of pre-employment screening and background checks Leading provider of pre-employment screening and background checks Speed Cost Effective Accurate Reliable Vetting Solutions Limited t: +44 (0) 1276 415818 e: info@vetting-solutions.com w: www.vetting-solutions.com

More information

INFORMATION TECHNOLOGY STRATEGY Mission. Vision. Priorities

INFORMATION TECHNOLOGY STRATEGY Mission. Vision. Priorities Mission INFORMATION TECHNOLOGY STRATEGY 2010-14 Support the University s key processes by providing: Excellent, customer-focussed, cost efficient services and support A robust, secure and accessible architecture.

More information

ENERGY MANAGEMENT SYSTEMS

ENERGY MANAGEMENT SYSTEMS ENERGY MANAGEMENT SYSTEMS Audit, CERTIFICATION & Training Services HOW CAN YOU continuously improve energy efficiency? ENERGY MANAGEMENT AUDIT, CERTIFICATION & Training Services FROM SGS With energy costs

More information

ISD SENIOR MANAGER STRATEGY AND ARCHITECTURE. Purpose. More information

ISD SENIOR MANAGER STRATEGY AND ARCHITECTURE. Purpose. More information ISD SENIOR MANAGER STRATEGY AND ARCHITECTURE Information Technology (IT) and end-to-end communication systems are a critical enabler to HPUK s successful business operations. The Information Systems Department

More information

QUALITY INTEGRATED ENGINEERING SERVICES to the energy sector

QUALITY INTEGRATED ENGINEERING SERVICES to the energy sector QUALITY INTEGRATED ENGINEERING SERVICES to the energy sector COMPANY PROFILE offers a complete service including Project Management, Engineering, Procurement, Construction Management, Training and related

More information

ENTERPRISE RISK MANAGEMENT TRAINING A ROAD MAP TO ENTERPRISE RISK MANAGEMENT

ENTERPRISE RISK MANAGEMENT TRAINING A ROAD MAP TO ENTERPRISE RISK MANAGEMENT ENTERPRISE RISK MANAGEMENT TRAINING A ROAD MAP TO ENTERPRISE RISK MANAGEMENT Marsh Risk Consulting Marsh Risk Consulting has been involved in the delivery of various enterprise risk management (ERM) programmes

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Applicable to All employees Version1.0 Last Updated March 2014 CONFIDENTIAL Page 2 of 6 Contents 1. Objectives 3 2. Scope 3 3. Principles 3 4. Information Governance Policy

More information

SERVICE EQUIPMENT DISPOSAL POLICY

SERVICE EQUIPMENT DISPOSAL POLICY SERVICE EQUIPMENT DISPOSAL POLICY Version 2.1 IT Equipment Disposal Policy COR/047/V2.01 December 2016 updated January 2018 Version 2.1 1 Subject and version number of document: Serial number: Service

More information

ISO 9001:2015 Your implementation guide

ISO 9001:2015 Your implementation guide ISO 9001:2015 Your implementation guide ISO 9001 is the world s most popular management system standard Updated in 2015 to make sure it reflects the needs of modern-day business, ISO 9001 is the world

More information

Standards. The framework for the award of the PASA accreditation for quality pension administration. October PASA Standards Version 1.

Standards. The framework for the award of the PASA accreditation for quality pension administration. October PASA Standards Version 1. s The framework for the award of the PASA accreditation for quality pension administration October 2012 1 PASA s Version 1.11 1. Service Agreement 1.1 Agreement to provide administration services An appropriate

More information

CCE Channel Services. Partner Capability. Diverse, flexible and reliable service offerings.

CCE Channel Services. Partner Capability. Diverse, flexible and reliable service offerings. CCE Channel Services Partner Capability Diverse, flexible and reliable service offerings. Company overview About us CCE is one of the UK s largest independent IT support companies with offices in London

More information

Protect your organisation from money laundering and fraud to prevent reputational damage

Protect your organisation from money laundering and fraud to prevent reputational damage Protect your organisation from money laundering and fraud to prevent reputational damage Our Our organisation organisation was was founded on on four four key key values: innovation, quality, quality,

More information

TELSTRA HOSTED SAP SOLUTIONS WITH ACCENTURE A SMARTER SAP SOLUTION

TELSTRA HOSTED SAP SOLUTIONS WITH ACCENTURE A SMARTER SAP SOLUTION TELSTRA HOSTED SAP SOLUTIONS WITH ACCENTURE A SMARTER SAP SOLUTION TELSTRA HOSTED SAP SOLUTIONS WITH ACCENTURE ENHANCE YOUR ENTERPRISE RESOURCE PLANNING CAPABILITIES, DRIVE INNOVATION AND LOWER COSTS Innovate

More information

ISO 9001:2015 Your implementation guide

ISO 9001:2015 Your implementation guide ISO 9001:2015 Your implementation guide ISO 9001 is the world s most popular management system standard Updated in 2015 to make sure it reflects the needs of modern-day business, ISO 9001 is the world

More information

ISO/IEC INTERNATIONAL STANDARD. Corporate governance of information technology. Gouvernance des technologies de l'information par l'entreprise

ISO/IEC INTERNATIONAL STANDARD. Corporate governance of information technology. Gouvernance des technologies de l'information par l'entreprise INTERNATIONAL STANDARD ISO/IEC 38500 First edition 2010-06-01 Corporate governance of information technology Gouvernance des technologies de l'information par l'entreprise Reference number ISO/IEC 38500:2008(E)

More information

Services and Support. System design. Hardware. Installation. Peace of mind. Digital Signage

Services and Support. System design. Hardware. Installation. Peace of mind. Digital Signage A total solution from start to finish Services and Support System design. Hardware. Installation. Peace of mind. Whatever your digital signage requirement, we can provide a solution that meets your exact

More information

ISO INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 28001 First edition 2007-10-15 Security management systems for the supply chain Best practices for implementing supply chain security, assessments and plans Requirements and

More information

STREAM Integrated Risk Manager. ISO Application. How STREAM supports compliance with ISO 27001

STREAM Integrated Risk Manager. ISO Application. How STREAM supports compliance with ISO 27001 STREAM Integrated Risk Manager ISO 27001 Application How STREAM supports compliance with ISO 27001 Plan Do Check - Act STREAM provides support to all 4 stages of the international management system model

More information

MICROSOFT BUSINESS SOLUTIONS GREAT PLAINS. Release 7.5 Extensions

MICROSOFT BUSINESS SOLUTIONS GREAT PLAINS. Release 7.5 Extensions MICROSOFT BUSINESS SOLUTIONS GREAT PLAINS Release 7.5 Extensions M Business Solutions Pursue Your Business Vision with Confidence Designed for rapid time to benefit and low cost of ownership, Microsoft

More information

The table below highlights in bold those policies, plans and strategies which are of particular relevance to the Collections Information Policy:

The table below highlights in bold those policies, plans and strategies which are of particular relevance to the Collections Information Policy: Aim & purpose This collections information policy focusses on the provision of intellectual access to collections, both by users and by staff for management purposes. It will assist in decision making

More information

DQS AUDITOR Auditing software with meaningfull reports http://www.dqs.co.za/dqsauditorsoftware Flexible Solutions for your internal and second party Audits Download Demo Easy to Install Browse to the installation

More information

Sarbanes-Oxley Compliance Kit

Sarbanes-Oxley Compliance Kit Kit February 2018 This product is NOT FOR RESALE or REDISTRIBUTION in any physical or electronic format. The purchaser of this template has acquired the rights to use it for a SINGLE Disaster Recovery

More information

QUALIFICATIONS WALES STRATEGY 2018 to 2022

QUALIFICATIONS WALES STRATEGY 2018 to 2022 QUALIFICATIONS WALES STRATEGY 2018 to 2022 JANUARY 2018 Contents Introduction 3 Our role within the qualification system 4 What we want to achieve 6 How we work 7 Our plans 11 Introduction Background Qualifications

More information

YOUR CERTIFICATION PROCESS EXPLAINED

YOUR CERTIFICATION PROCESS EXPLAINED ISO 22000 FOOD SAFETY MANAGEMENT SYSTEMS FSSC 22000 FOOD SAFETY SYSTEM CERTIFICATION This document outlines the audit process for the above referenced standard. It outlines the stages to audit and gives

More information

https://www.e-janco.com

https://www.e-janco.com E-mail: support@e-janco.com https://www.e-janco.com Summary Table of Contents IT INFRASTRUCTURE, STRATEGY, AND CHARTER SUMMARY...1 Benefits of IT Infrastructure Management...1 Base Assumptions and Objectives...2

More information

ISO/IEC JTC 1 N 10998

ISO/IEC JTC 1 N 10998 ISO/IEC JTC 1 N 10998 ISO/IEC JTC 1 Information technology Secretariat: ANSI (USA) Document type: Title: Status: Text for PDTR ballot or comment Text of 2nd PDTR 38502, Governance of IT - Framework and

More information

why Business Partner Because you can use it to liberate your company from paper and manage your processes faster.

why Business Partner Because you can use it to liberate your company from paper and manage your processes faster. ENTERPRISE INFORMATION MANAGEMENT EIM R DOCUMENT ERP INTEGRATION & PROCESS MANAGEMENT WORKFLOW ENTERPRISE CONTENT SPOOL RECOGNITION MANAGEMENT FAX SERVER BUSINESS PROCESS MANAGEMENT MAIL WEB & CLIENT/SERVER

More information

BACKGROUND DISCUSSION PAPER

BACKGROUND DISCUSSION PAPER Review of National Standards for Involving Volunteers in Not for Profit Organisations BACKGROUND DISCUSSION PAPER October 2014 This Discussion Paper provides a background to the Review of the National

More information

Temporary, contract and interim recruitment services Permanent and fixed term selection recruitment services Retained & executive recruitment services

Temporary, contract and interim recruitment services Permanent and fixed term selection recruitment services Retained & executive recruitment services QUALITY MANAGEMENT POLICY & PROCEDURES Policy Statement CDS Recruitment Limited specialises in the recruitment of Engineering, Technical and Scientific personnel in the Chemical and Pharmaceutical, Oil

More information

Health and Safety Management Profile (HASMAP)

Health and Safety Management Profile (HASMAP) Health and Safety Management Profile (HASMAP) Contents Introduction 02 HASMAP overview 03 Getting started 04 Indicator summaries A Leadership 07 B Planning for emergencies 15 C Health and safety arrangements

More information

IT MANAGED SUPPORT SERVICES

IT MANAGED SUPPORT SERVICES Making Technology Simple for over 12 years IT MANAGED SUPPORT SERVICES Dynamic Solutions, Trusted Service 2 Peach Technologies 4 Why have Managed IT - Case Study 6 Benefits of Managed IT Service 8 Business

More information

Aspire Europe Ltd. Rod Sowden Lead Author for MSP and P3M3. Slide 1 v4

Aspire Europe Ltd. Rod Sowden Lead Author for MSP and P3M3. Slide 1 v4 Aspire Europe Ltd Rod Sowden Lead Author for MSP and P3M3 Slide 1 v4 OGC Best Practice Common Glossary (updated) Models Guides In Development Updated 2008 Updated 2007 Updated 2007 Portfolio, Programme

More information

Look Ahead Care, Support and Housing: Anti-Slavery and Human Trafficking Statement

Look Ahead Care, Support and Housing: Anti-Slavery and Human Trafficking Statement Look Ahead Care, Support and Housing: Anti-Slavery and Human Trafficking Statement Introduction Look Ahead is committed to: Undertaking and promoting ethical practices and policies to prevent modern slavery

More information

Practising Certificate Training Record (PCTR) GLOBAL edition

Practising Certificate Training Record (PCTR) GLOBAL edition Practising Certificate Training Record (PCTR) GLOBAL edition Every effort has been made to ensure that the information in this booklet is accurate and up to date at the time of going to press. ACCA accepts

More information

INTRODUCTION WHO SHOULD ATTEND? SharePoint Implementation Best Practices: From Design to Integration September 2017, Dubai Fees : US$ 4,500

INTRODUCTION WHO SHOULD ATTEND? SharePoint Implementation Best Practices: From Design to Integration September 2017, Dubai Fees : US$ 4,500 HR CERTIFICATION INSTITUTE ISO 9001:2015 Certified ISO 29990:2010 Certified ISO 29990 An Intensive 5 - Day Seminar On SharePoint Implementation Best Practices: From Design to Integration DUBAI 17-21 September

More information

INTEGRATED RISK BUSINESS CONTINUITY CYBER-SECURITY THE RESILIENCE FACTORS THAT DRIVE YOUR REPUTATION

INTEGRATED RISK BUSINESS CONTINUITY CYBER-SECURITY THE RESILIENCE FACTORS THAT DRIVE YOUR REPUTATION CYBER-SECURITY BUSINESS CONTINUITY INTEGRATED RISK THE RESILIENCE FACTORS THAT DRIVE YOUR REPUTATION INTRODUCTION We all work hard to build and protect our reputation, and in today s world of 24/7 news

More information

Mobility, Wireless & FMC. Storage & Data Centre. Communications - for business

Mobility, Wireless & FMC. Storage & Data Centre. Communications - for business is a mature partner in the world of enterprise platforms and solutions. We engage with all markets and technology disciplines within the commercial mid-market to deliver results-focused advice and through-life-care,

More information

Introduction to SEND Assurance Tool

Introduction to SEND Assurance Tool Introduction to SEND Assurance Tool Table of Contents QuiqSolutions Background... 2 QuiqCare... 2 Policy Manager... 2 Surveys, Audits & Requests for Information (RFI)... 2 QuiqCare SEND Assurance Tool...

More information

GET MORE PAYMENTS WITH ACI VIRTUAL COLLECTION AGENT

GET MORE PAYMENTS WITH ACI VIRTUAL COLLECTION AGENT FEATURES AT A GLANCE EFFECTIVE Emulates the interactions of your best collection agent Strategy Manager lets you build and adapt collection strategies, based on rule sets and consumer information Live

More information

A tool for assessing your agency s information and records management

A tool for assessing your agency s information and records management A tool for assessing your agency s information and records management Copyright Commonwealth of Australia 2010 Updated on 14 June 2012 Copyright of Check-up 2.0 rests with the Commonwealth of Australia.

More information

ISO 9001:2015 Revision Frequently Asked Questions

ISO 9001:2015 Revision Frequently Asked Questions ISO Revisions Latest update New and revised ISO 9001:2015 Revision Frequently Asked Questions Introduction ISO 9001, the world s leading international quality standard has helped millions of organizations

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

REUTERS/Yuya Shino. Thomson Reuters Compliance Learning. Promoting a Culture of Integrity and Compliance

REUTERS/Yuya Shino. Thomson Reuters Compliance Learning. Promoting a Culture of Integrity and Compliance REUTERS/Yuya Shino Thomson Reuters Compliance Learning Promoting a Culture of Integrity and Compliance Thomson Reuters Compliance Learning Promoting a Culture of Integrity and Compliance Educate your business,

More information

JOB DESCRIPTION & PERSON SPECIFICATION. Director of Regulatory Assurance. REPORTS TO: Deputy Commissioner - Operations PURPOSE OF POST

JOB DESCRIPTION & PERSON SPECIFICATION. Director of Regulatory Assurance. REPORTS TO: Deputy Commissioner - Operations PURPOSE OF POST JOB DESCRIPTION & PERSON SPECIFICATION JOB TITLE: Director of Regulatory Assurance REPORTS TO: Deputy Commissioner - Operations SALARY: HOURS: Level G2 37 per week PURPOSE OF POST The Operations executive

More information

A practical one day course on SYSC for employees working within investment management, or in irms providing support services.

A practical one day course on SYSC for employees working within investment management, or in irms providing support services. THE INVESTMENT ASSOCIATION UNDERSTANDING SYSTEMS AND CONTROLS (SYSC) IN INVESTMENT MANAGEMENT FIRMS 23 NOVEMBER 2016 A practical one day course on SYSC for employees working within investment management,

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 27004 First edition 2009-12-15 Information technology Security techniques Information security management Measurement Technologies de l'information Techniques de sécurité

More information

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation United Lincolnshire Hospitals NHS Trust Governance Statement 2015/16 Scope of responsibility As Accountable Officer, and Chief Executive of this Board, I have responsibility for maintaining a sound system

More information

HSE Audit Solutions 2017: Update Smarter Operational Risk, Compliance & Safety Decisions

HSE Audit Solutions 2017: Update Smarter Operational Risk, Compliance & Safety Decisions www.arkworkplacerisk.com Audit Solutions 2017; Update 2017 Ark Workplace Risk HSE Audit Solutions 2017: Update Smarter Operational Risk, Compliance & Safety Decisions HSE Audit Solutions are fast becoming

More information

Internal audit and risk management

Internal audit and risk management Strengthening governance worldwide Internal audit and risk management Adding value Practical Risk Management Techniques Two-week professional development workshop 2 to 6 July 2018 10 to 14 December 2018

More information

NATIONAL PERFORMANCE STANDARDS FOR MANAGING AND DELIVERING COMMUNITY LEGAL SERVICES

NATIONAL PERFORMANCE STANDARDS FOR MANAGING AND DELIVERING COMMUNITY LEGAL SERVICES NATIONAL PERFORMANCE STANDARDS FOR MANAGING AND DELIVERING COMMUNITY LEGAL SERVICES Issued by Legal Aid Services, Ministry of Justice 1 July 2011 Preface On 1 July the Legal Services Agency was disestablished,

More information

Higher National Unit Specification. General information for centres. IT Infrastructure: Service Delivery. Unit code: F0DY 35

Higher National Unit Specification. General information for centres. IT Infrastructure: Service Delivery. Unit code: F0DY 35 Higher National Unit Specification General information for centres Unit title: IT Infrastructure: Service Delivery Unit code: F0DY 35 Unit purpose: This Unit develops the candidate s knowledge and understanding

More information

Non-exclusive right to handle the marketing and distribution for sale of reference materials from the JRC world-wide

Non-exclusive right to handle the marketing and distribution for sale of reference materials from the JRC world-wide EUROPEAN COMMISSION DIRECTORATE-GENERAL JOINT RESEARCH CENTRE Directorate F Health, Consumers & Reference Materials Unit F.6 Reference Materials Non-exclusive right to handle the marketing and distribution

More information

Service solutions for peak performance. Flexible service plans, maximum productivity, expert engineers.

Service solutions for peak performance. Flexible service plans, maximum productivity, expert engineers. Service solutions for peak performance Flexible service plans, maximum productivity, expert engineers www.moleculardevices.com Choose the right service plan for your specific laboratory priorities Performance

More information

Athelbrae Ltd. Business Training, Coaching & Recruitment. Working in partnership with you to develop your staff

Athelbrae Ltd. Business Training, Coaching & Recruitment. Working in partnership with you to develop your staff Athelbrae Ltd Business Training, Coaching & Recruitment Working in partnership with you to develop your staff Athelbrae House, 10 Linnet Avenue, Paddock Wood, Kent. TN12 6XQ Tel: 01892 832059 info@athelbrae.co.uk

More information

Practising Certificate Training Record (PCTR) UNITED KINGDOM, REPUBLIC OF IRELAND AND CYPRUS EDITION

Practising Certificate Training Record (PCTR) UNITED KINGDOM, REPUBLIC OF IRELAND AND CYPRUS EDITION Practising Certificate Training Record (PCTR) UNITED INGDOM, REPUBLIC OF IRELAND AND CYPRUS EDITION Every effort has been made to ensure that the information in this booklet is accurate and up to date

More information

JOB PROFILE. Specialist Capabilities Programme - Capability Manager (Forensic Collision Investigation).

JOB PROFILE. Specialist Capabilities Programme - Capability Manager (Forensic Collision Investigation). JOB PROFILE POST TITLE: GRADE: DIRECTORATE: RESPONSIBLE TO: RESPONSIBLE FOR: LOCATION: JOB PURPOSE: Specialist Capabilities Programme - Capability Manager (Forensic Collision Investigation). I Chief Officers

More information

BIM in Hong Kong: Time to Leap. Ivan WONG Senior Manager Council Services

BIM in Hong Kong: Time to Leap. Ivan WONG Senior Manager Council Services BIM in Hong Kong: Time to Leap Ivan WONG Senior Manager Council Services 2013-11-9 Why is CIC here? Back to Year 2011.. CIC organised a seminar on Building Information Modelling in 2011 With overwhelming

More information

UNIVERSITY OF DERBY JOB DESCRIPTION. JOB NUMBER SALARY 35,634 to 38,268 per annum

UNIVERSITY OF DERBY JOB DESCRIPTION. JOB NUMBER SALARY 35,634 to 38,268 per annum UNIVERSITY OF DERBY JOB DESCRIPTION JOB TITLE DEPARTMENT LOCATION Operations and Response Centre Manager IT Services Kedleston Road JOB NUMBER 0812-17 SALARY 35,634 to 38,268 per annum REPORTS TO Head

More information

Exciting career opportunity

Exciting career opportunity Exciting career opportunity General Manager ICT Our client, a financial service provider, seeks to recruit an experienced General Manager ICT who will be responsible for developing organizational aligned

More information

Audio transcripts and lesson notes

Audio transcripts and lesson notes Chapter 2 Quick Overview, Steps in an ISO 27001 implementation Audio transcripts and lesson notes Hi and welcome. This is Anup Narayanan, your instructor. This chapter gives you a quick overview of the

More information

Professional Project Analyst

Professional Project Analyst An Intensive 5 Day Training Course Professional Project Analyst (an ILM-endorsed version of Project Analysis: Tls & Techniques for Managing Risk & Uncertainty ) 15-19 Jul 2019, London 16-20 Dec 2019, Kuala

More information

Revenew s Cost Recovery and Cost Containment services return dollars to your budgets. We recover over $100 million for our clients annually.

Revenew s Cost Recovery and Cost Containment services return dollars to your budgets. We recover over $100 million for our clients annually. Revenew s Cost Recovery and Cost Containment services return dollars to your budgets. We recover over $100 million for our clients annually. COST RECOVERY Contract Compliance Reviews Supplier Payment Reviews

More information

Read on» Service Definition OnBase Cloud Document Management

Read on» Service Definition OnBase Cloud Document Management Service Definition OnBase Cloud Document Management Overview Every day, thousands of organisations across the globe use OnBase by Hyland to manage their content. OnBase is one of the most flexible and

More information

t: +44 (0) f: +44 (0) e: w:

t: +44 (0) f: +44 (0) e: w: t: +44 (0)1355 593400 f: +44 (0)1355 579191 e: info@gaelquality.com w: www.gaelquality.com white paper Q-Pulse is a registered trademark of Gael Products Ltd. All rights reserved worldwide. Copyright 2009

More information

EURO. ENVIRONMENTAL Compliance, Protection, Peace of Mind. Occupational Hygiene Safety Consultants

EURO. ENVIRONMENTAL Compliance, Protection, Peace of Mind. Occupational Hygiene Safety Consultants EURO ENVIRONMENTAL Occupational Hygiene Safety Consultants Creating a safer working environment Do you comply? We ensure you comply with the latest health and safety regulations and take on the burden

More information

ISO INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 28001 First edition 2007-10-15 Security management systems for the supply chain Best practices for implementing supply chain security, assessments and plans Requirements and

More information

Introduction to IT Governance. IT Governance CEN 667

Introduction to IT Governance. IT Governance CEN 667 Introduction to IT Governance IT Governance CEN 667 1 Lectures Schedule Week Topic Week 1 Introduction to IT governance Overwiev of Information Security standards - ISO 27000 series of standards Week 2

More information

NZQA registered unit standard 5555 version 6 Page 1 of 5

NZQA registered unit standard 5555 version 6 Page 1 of 5 Page 1 of 5 Title Arrange and manage a visitor conference Level 5 Credits 20 Purpose People credited with this unit standard are able to: plan operations for a visitor conference; manage monetary, human

More information

IP Australia s Approach to Competency Based Training and Assessment. Baahini Sivakumar RPET Manager, Mentor & Trainer

IP Australia s Approach to Competency Based Training and Assessment. Baahini Sivakumar RPET Manager, Mentor & Trainer IP Australia s Approach to Competency Based Training and Assessment Baahini Sivakumar RPET Manager, Mentor & Trainer Competency Based Training & Assessment Mastery of knowledge and skills Skills Clear

More information

DRAFT ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance

DRAFT ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance INTERNATIONAL STANDARD ISO/IEC 27003 First edition 2010-02-01 Information technology Security techniques Information security management system implementation guidance Technologies de l'information Techniques

More information

NARU. NHS Ambulance Services Emergency Preparedness, Resilience & Response. Quality Assurance Framework. National Ambulance Resilience Unit

NARU. NHS Ambulance Services Emergency Preparedness, Resilience & Response. Quality Assurance Framework. National Ambulance Resilience Unit National Ambulance Resilience Unit NARU NHS Ambulance Services Emergency Preparedness, Resilience & Response Quality Assurance Framework Page 1 of 45 Document Name National Ambulance Resilience Unit National

More information

Risk Management Using Spiral Model for Information Technology

Risk Management Using Spiral Model for Information Technology Risk Management Using Spiral Model for Information Technology Rajendra Ganpatrao Sabale, Dr. A.R Dani Student of Ph.D., Singhania University, Pacheri Bari, Dist. Jhunjhunu( Rajasthan), India International

More information

Pipelines Safety Regulations 1996

Pipelines Safety Regulations 1996 Pipelines Safety Regulations 1996 ACoP and Guidance to support amendments to Regulations 25 and 26 covering Pipeline Emergency Plan Testing and Charging Pipelines Safety Regulations 1996 ACoP and Guidance

More information

Service Description Cloud Expert Services

Service Description Cloud Expert Services Service Description Cloud Expert Services Table on contents 1 DEFINITIONS... 2 2 PURPOSE OF THE DOCUMENT... 2 3 OVERVIEW OF THE SERVICE... 2 3.1 OVERALL DESCRIPTION... 2 3.2 GEOGRAPHICAL FOOTPRINT... 2

More information

ENSURING QUALITY THROUGH COMPLIANCE [ COMPLIANCE ]

ENSURING QUALITY THROUGH COMPLIANCE [ COMPLIANCE ] ENSURING QUALITY THROUGH COMPLIANCE [ COMPLIANCE ] BEING IN COMPLIANCE HAS NEVER BEEN MORE IMPORTANT Quality encompasses more than meeting regulatory requirements. It extends throughout your organization

More information

THE OFFICE PROFESSIONAL AND RECORDS MANAGEMENT MASTERCLASS

THE OFFICE PROFESSIONAL AND RECORDS MANAGEMENT MASTERCLASS ISO 9001:2015 Certified ISO 29990:2010 Certified ISO 29990 THE OFFICE PROFESSIONAL AND RECORDS MANAGEMENT MASTERCLASS 25 Nov - 06 Dec 2018, Dubai 29-MAY-18 EuroMaTech is proud to be associated with the

More information

Version 2 November Code of Practice. Consignment Based Conformity Assessment (CBCA) Services

Version 2 November Code of Practice. Consignment Based Conformity Assessment (CBCA) Services Code of Practice Consignment Based Conformity Assessment (CBCA) Services November 2012 PREFACE Many developed countries have strong National Standards and Technical Regulations supported internally with

More information