IT Best Practice
Simplifying
IS Standards
Compliance can appear to be a complex and overwhelming issue. Its scope spans regulatory requirements, corporate policy, and industry standards. Quadrant with its vast expertise in the field can provide assistance in achieving the following compliance:
- ISO 27001 ISMS Build: The basic objective of the standard is to help establish and maintain an effective information security management system (ISMS), using a continual improvement approach in accordance with the ISO 27001 international standard.
- ISO 20000 IT Services Management System Compliance: ISO 20000 comprises two distinct documents: a specification for a service management system, and a code of practice. Together, these form a top-down framework to define the features of service management processes that are essential for the delivery of high quality services.
- ISO 19770 Software Asset Management System Compliance: The standard consists of two parts; part one describes the processes involved in Software Asset Management and part two defines a product identification that will simplify the software inventory process.
- BS 25999 Business Continuity Management System Build: The BS25999 series includes two standards. The first, “BS 25999-1:2006 Code of Practice for BCM”, establishes its processes, principles and terminology. The second, “BS 25999-2:2006 A Specification for BCM”, is a concrete standard on which certification would be granted, and specifies the requirements for the implementation of business continuity controls.
- PCI-DSS Compliance: This service focuses on assisting Banks and Merchants to comply with Payment card Industry Data Security Standards. This service is offered in conjunction with Standards Australia.
- ISO/IEC 21827:2007: specifies the Systems Security Engineering - Capability Maturity Model (SSE-CMM), which describes the essential characteristics of an organization's security engineering process that must exist to ensure good security engineering. ISO/IEC 21827:2007 does not prescribe a particular process or sequence, but captures practices generally observed in industry
