Case Study 5 - Conducting an IT Security Health Check for a smaller Building Society
Background
Greig Ross Associates had been engaged to conduct an IT review which amongst other things raised a few issues with respect to IT security. The IT Manager had recently departed and this society needed some professional unbiased advice.
Approach
The assignment followed the guidelines within ISO27001 (formerly BS7799) and the review consisted of interviews, sample site viewing and some technical reviews.
The Result
A sizeable number of IT security issues were highlighted to the client at the technical, procedural and governance levels eg lack of a security policy, no backup security for email, customer security tapes being held far longer than appropriate, lack of DR planning and testing. We have been working with the client addressing these issues.
Case 1 | Case 2 | Case 3 | Case 4 | Case 5 | Case 6 | Case 7