Security organization

Risk management

  • Attendees: 12 people maximum
  • Length: 2 days
  • Audience: auditors, staff managers

This training program targets an audience aware of the corporate information assets' crucial value.
The consultant defines, with concrete examples, the notion of risk, and presents methods on how to evaluate, analyze, classify and put into a hierarchy all these risks. Thus, with the attendees, it is possible to determine solutions in the framework of predefined scenarii.
This program provides practical models, which can be easily implemented or adapted. These tools allow to get a global vision of security issues, which may appear within the company, and a fast return on investment.
 

Getting ready for the security audit

  • Attendees: 12 people maximum
  • Length: 3 days
  • Audience: auditors, information system managers, information security managers, risk managers, users

Whether it is in a legal framework (SOX, financial security laws, certification), or in order to provide potential investors with guarantees, or to ensure
the company's durability, there is several reasons for carrying out a full security audit or one focused on a particular issue (i.e. audit of the disaster recovery plan).
This session prepares the company for the IT security audit and its compliance.
At the end of this program, all the attendees will know the good practices in order to implement a security complying with the current standards.
 

Security strategy

  • Attendees: 12 people maximum
  • Length: 1-2 days
  • Audience: auditors, information system managers, information security managers, risk managers, users

This program explains: what a security policy is, how to implement it, control its application and update it.
The must-use tools and the must-apply methodology are detailed in order to get a global strategy of the corporate information security.
The goal is the control of the security policy's evolution.
 

Contingency plan

  • Attendees: 12 people maximum
  • Length: 2 days
  • Audience: staff managers

Whether a contingency plan has been implemented or not prior to the beginning of the program, it may be necessary to remind how useful, if not essential, such a plan is. Thus the methodology to build it is examined. Next, the plan is checked and the possible modifications are carried out by the attendees helped by our consultant. After validation, it is essential to determine how to implement this plan and what means (human, technical, financial) are required to do it.
The company will be able to efficiently intervene in case of a disaster.
 

Mesca – 2006, March 6 – 7:23pm