-
 

Solution Experience

  • Role based access control proof of concept (Insurance)
  • Single-Sign on with strong authentication feasibility study (Banking, Telecom, Retail)
  • PCI-DSS implementation support (Financial Services)
  • IDM strategy definition (Media)
  • Web Access Management Proof of Concept (Financial Services, Government)
  • Identity Management product comparison/evaluation (Government)
  •  
     

    Security and Compliance Management

    How to address Security and Compliance Management challenges to achieve competitive advantage

    Compliance is a word that is in everyone's thoughts these days. Over the past couple of years, it has most often been used in the same sentence as "regulatory". Regulations such as Sarbanes-Oxley, Basel II, PCI-DSS, IKS are forcing companies to put their houses in order, or they will face penalties if any non compliance is uncovered. In many organizations compliance also has a broader meaning related to the policies and procedures used to protect the company's IT equipment, data, and other assets. These policies, which include security and other business policies (often based on standard or best practice frameworks like ISO 27001, ISO 20000 or COBIT), generally prescribe minimum standards for use of information and IT equipment, definitions of misuse, and rules for enforcing the standards that have been set. Security and compliance policy standards are, however, notoriously difficult to enforce. Over the past decade corporate information systems have grown exponentially, encompassing thousands of systems running on heterogeneous computing platforms. Those environments are constantly undergoing changes, with new devices added or removed, applications deployed or upgraded, and a constant stream of user profiles being created, modified or de-provisioned. Every access change request is a potential security and compliance loophole. It is no longer enough just to record the changes because compliance is not just about filling out forms. It is about proactively managing the risks.

    Cambridge can help you to organize and structure your Security and Compliance requirements into feasible solutions that not only mitigate the associated risks, but enable companies to streamline their security and compliance management processes and save money through a value added approach of security and compliance management.

    CAMBRIDGE SECURITY AND COMPLIANCE MANAGEMENT SERVICES ARE THE RIGHT SOLUTION FOR YOU IF YOU WANT TO...

    • Align your security and compliance requirements with the strategic business objectives
    • Define a common integration framework and implementation roadmap for your regulatory and security policies
    • Ensure the evaluation of compliance and security programs, that provide most business value

    • Link your security and compliance initiatives with business process improvement activities

    • Bridge the gap between your security and compliance policies and your operational IT infrastructure

    • Model, validate and enforce your security and compliance models in your IT environment
    • Reduce the effort of administering manually security, compliance and audit requirements
    • Allow your internal employees and your business partners by giving them secure and compliant real time access to the information resources they need
    • Assess the effectiveness, consistency and completeness of your user access management to business critical information assets

    Cambridge's solutions and service offering

    Cambridge's Business Consultants have the competencies and experience to provide you services in the following security and compliance management domains

    Assess the current situation

  • Detailed current state assessment based on personal interviews with users, administrators, and managers in addition to reviewing existing documentation
  • Evaluation of the gap to best practice models and approaches, collect and prioritize objectives and needs

  • Structured collection and prioritization of demands
  • In addition to our Business Consulting offerings, we are able to provide technology implementations through partnerships with product leaders in service level management.

    Business justification for security and compliance management projects

    Strategy and roadmap definition that includes business objectives proposed goal-state architecture, recommendations on initial use cases, success metrics and high-level project plan