Implementation of
information systems spans across business functions
and affects a number of processes. Normally, information
systems implementation is a result of a well planned
business strategy. It is therefore critical to understand
the goals of a technology implementation and the business
needs it aims to satisfy. The current state assessment
aims at understanding the current information technology
infrastructure, its application in the business functions
and its future direction.
::
Security Need Analysis ::
Scope
Dependence on Information
Technology
Existing control
framework
Planned security
objectives
Description
How much security
is 'adequate security'? An organisation's IT security
need is determined by the extent of dependence on information
technology. Complex IT structures require more emphasis
on systemic controls compared to simple IT structures.
It is critical that a holistic view of the security
requirements is obtained to develop the required security
practices and principles. Security need analysis aims
at understanding the IT security infrastructure according
to current needs and future requirements.
::
Threat and Risk Assessment ::
Scope
Analysing existing
control measures
Identifying control
weaknesses
Recommending control
measures
Description
Security measures
should be properly targeted, and directly related to
potential impacts, threats, and existing vulnerabilities.
Failure to achieve this could result in inadequate security
measures and excessive or unnecessary expenditure. An
appropriate threat and risk assessment promotes better
targeting of security measures and facilitates better
decision-making.
::
Computer Forensics ::
Scope
Discover all files
on the subject computer system
Analyse all relevant
data
Provide expert
opinion / consultation
Description
Computer crime or
misuse includes theft of trade secrets, theft of or
destruction of intellectual property, financial fraud
etc. Unlike paper evidence, computer evidence can often
exist in many forms, with earlier versions still accessible
on a computer disk. Computer specialists can use a variety
of tools and techniques for discovering data that resides
in a computer system, or recovering deleted, encrypted,
or damaged file information