Our team consists of information assurance experts with advanced degrees and technical certifications including CISA. Our consultants are expert in safeguarding information system and can help you effectively manage risk and protect your business critical data.
We provide full range of IS Audit and Consulting service which includes:
IS Audit:
We provide IS audit services in accordance with IS audit standards, guidelines, and best practices to assist your company in ensuring that your information technology and business systems are protected and controlled. Services available from Agile include:
- Develop and implement a risk-based IS audit strategy for your company in compliance with IS audit standards, guidelines and best practices.
- Plan specific audits to ensure that your IT and business systems are protected and controlled.
- Conduct audits in accordance with IS audit standards, guidelines and best practices to meet your planned audit objectives.
- Communicate emerging issues, potential risks, and audit results to your key stakeholders.
- Advise on the implementation of risk management and control practices within your company.
Operational Security Review
A total review of every security aspect of your organization's information processing systems is conducted on-site. Central computer operations, PC work-stations, communications networks, critical support systems, control practices and procedures are reviewed and personal interviews are conducted as required.
Threat and Vulnerability Risk Analysis
A critical analysis of the results of the Operational Security Review is performed to identify any security risks and the operational impact on the organization resulting from their occurrence.
Certified Report and Recommendations
A comprehensive written report is furnished, based upon the preceding Security Review and Risk Analysis. Alternatives are discussed and objective recommendations are made to solve the various security problems previously identified and a phased implementation plan is tailor-made for the organization.
Organizing the Information Security Function
For optimum effectiveness the information security function should receive a clear mandate from top management along with the resources, position and authority to act objectively in the organization's best interests. Based upon your requirements, we will structure the complete functional position and supply the necessary job descriptions, salary ranges, and responsibilities, conduct interviews, screen applicants and administer appropriate written examinations designed to test the candidates’ information security knowledge and skills.
Data Security and Control Procedures
A thorough review of all of your logical security and control features will be performed on-site. Particular emphasis is placed on your vulnerability to internal fraud and external computer hackers. The effectiveness of systems development controls, change management procedures and network security administration is reviewed.
Backup and Disaster Recovery Contingency Plans
Three modules will be developed to assist your organization in coping with a disaster. The emergency response plan, the operations backup plan and the operations recovery plan wilI provide the timely and correct response needed for successful operations recovery from a wide range of natural and man-made disasters.
Security Practices and Procedures Manuals
To assist your personnel and provide them with concise and accurate security guidelines, we can design two excellent security manuals specifically for your organization. Volume 1 is designed to provide guidance to the Department Manager and Administrators on security practices and procedures regarding personnel and operations. Volume 2 functions as an operational aid to the technical security staff and deals with a wide range of contingencies which could be encountered during the normal performance of their security and control duties.
Network Security
A complete security review of your telecommunications networks is performed by our team. Networks carrying data, voice, facsimile, e-mail, etc., via microwave, metallic or fibre optic cables, or satellite, are examined for security threats and vulnerabilities in both intranet and internet operating environments. Recommendations, costs and options are provided to protect your valuable information.