TANATECH

CYBER SECURITY

CYBER RISK

Assessments

As a foundation to a cybersecurity program, it is critical for an organization to understand the current state of risk and how the organization is in alignments with industry frameworks, good security practices, and/or compliance-driven requirements.

Plan to Perform a Risk Assessment

  • Understand the operational model and the technology environment that supports critical functions.

Identify an Inherent Risk Profile

  • Identify the threat landscape and prioritize risks relative to business objectives and resources.

Evaluate the Risks

  • Assess the inherent risks profile using appropriate security controls from an industry framework in order to identify residual risks

Establish a Remediation Plan

  • Establish an actionable and prioritized remediation plan.

CYBER RISK

Our Services

As a foundation to a cybersecurity program, it is critical for an organization to understand the current state of risk and how the organization is in alignments with industry frameworks, good security practices, and/or compliance-driven requirements.

Strategy

READ MORE

Cybersecurity Strategy and Governance

  • Cybersecurity Strategy and Organization
  • Cybersecurity Policies and Procedures
  • Oversight, Reporting and Metrics
  • Security Training & Compliance

Management

READ MORE

Risk Management

  • Risk Assessments
  • Prioritized Risks
  • Stakeholder Communications
  • Accountability
  • Tracking & Remediation

Application

READ MORE

Asset & Application Management

  • Hardware and Software Asset Management
  • Endpoint Protection and Security Tools
  • Cloud Applications Management
  • Mobile Device Management

Vendor

READ MORE

Vendor Risk Management

  • Vendor Management Program and Processes
  • Minimum Security Baseline
  • SLA and Contractual Agreements

Access

READ MORE

Access Management

  • Access Management Tools (i.e. AD)
  • Access Provision & De-provision
  • Privileged Access
  • Multi-factor Authentication
  • Access Reviews

Data

READ MORE

Data Management

  • Data Governance, Classification & Retention
  • DLP and Data Protection Capabilities
  • Encryption

Infrastructure

READ MORE

Infrastructure Management / Security Architecture

  • Network Security Controls and Diagrams
  • Baseline Configuration Mgmt.
  • Firewall Configurations and Capabilities
  • Cloud Security (i.e. application security)

Vulnerability

READ MORE

Vulnerability Management

  • Patch Management
  • Vulnerability Scanning, Analysis and Tracking
  • Penetration Testing
  • Proactive/Reactive Vuln. Monitoring
  • Threat Intelligence

Incident Response

  • Incident Response Plan
  • Notification Requirements
  • Repository of Issues
  • Training and Re-evaluation

Cyber Security Resiliency

  • Backup and Recovery
  • Business Continuity
  • Disaster Recovery Planning
Scroll to Top