Cyber-Security

!

Ahieros mission is to provide information technology solutions today to make the best tomorrow.

!

Cyber-security is the body of technologies, processes and practices designed to protect networks, computers, programs and data from attack, damage or unauthorized access. Ahieros encompasses cyber-security from a holistic approach (360 degree protection spherical approach) utilizing information security best practices.

!

SECURITY FRAMEWORK

GUIDANCE, IT AUDITING AND (GRC) GOVERNANCE RISK & COMPLIANCE

Institute policies and procedures to ensure compliance with Basel, Blockchain, CMMI, CoBIT, DFARS (252.204-7012, etc.), DIACAP, FAA, FCC, FEMA 426, FEMA 428, FIPS (including FIPS 140-3, 199, 200, etc.), FISMA, FFIEC, GIG, GLBA, GISRA, HIPAA, HITRUST, ITIL, ISO 27000 series (e.g. ISO 20001, ISO 27002, ISO 27017, ISO 27018, etc.), NERC (CIP, BES Cyber Systems), NIST (e.g. 800-171, 800-53, NISTIR 8011) PMI, PCI, SAS-70, SSAE -16, SOX, WCO, RMF, eMASS, and other IT audit requirements.
NISTIR 8011 - Automation Support for Security Control Assessment
NERC Critical Infrastructure Protocols (CIP) for BES (Bulk Electric System) Cyber Systems
ISO 27017 / 27018 - Cloud Security Best Practices

SECURITY ENGINEERING

  • Security Solutions Development Strategies
  • Expert implementation guidance with Business Continuity Planning/Disaster Recovery where solutioning close to 100% uptime
  • Security Automation
  • Identify, Analyze, Remediate, Implement, Review, Repeat (if necessary)
  • Advanced Remediation & Patching Solutioning
  • Expert InfoSec Consulting
  • SIEM Implementation Strategies
  • Security Architecture Strategy
  • Security Tools Implementation from multiple vendors

FEATURED SERVICES

Ahieros cyber-security services include, but are not limited to:

  • Information Security Policies
  • Organization of Information Security
  • Human Resource Security
  • Asset Management
  • Access Control
  • Cryptography
  • Physical and environmental security
  • Operation Security - procedures and responsibilities, Protection from malware, Backup, Logging and monitoring, Control of operational software, Technical vulnerability management and Information systems audit coordination
  • Communication security - Network security management and Information transfer
  • System acquisition, development and maintenance - Security requirements of information systems, Security in development and support processes and Test data
  • Supplier relationships - Information security in supplier relationships and Supplier service delivery
  • Information security incident management - Management of information security incidents and improvements
  • Compliance - Compliance with legal and contractual requirements and Information security reviews