Cyber-Security
Ahieros mission is to provide information technology solutions today to make the best tomorrow.
Cyber-security is the body of technologies, processes and practices designed to protect networks, computers, programs and data from attack, damage or unauthorized access. Ahieros encompasses cyber-security from a holistic approach (360 degree protection spherical approach) utilizing information security best practices.
SECURITY FRAMEWORK
GUIDANCE, IT AUDITING AND (GRC)
Institute policies and procedures to ensure compliance with Basel, Blockchain, CMMI, CoBIT, DFARS (252.204-7012, etc.), DIACAP, FAA, FCC, FEMA 426, FEMA 428, FIPS (including FIPS 140-3, 199, 200, etc.), FISMA, FFIEC, GIG, GLBA, GISRA, HIPAA, HITRUST, ITIL, ISO 27000 series (e.g. ISO 20001, ISO 27002, ISO 27017, ISO 27018, etc.), NERC (CIP, BES Cyber Systems), NIST (e.g. 800-171, 800-53, NISTIR 8011) PMI, PCI, SAS-70, SSAE -16, SOX, WCO, RMF, eMASS, and other IT audit requirements.
NISTIR 8011 - Automation Support for Security Control Assessment
NERC Critical Infrastructure Protocols (CIP) for BES (Bulk Electric System) Cyber Systems.
ISO 27017 / 27018 - Cloud Security Best Practices
SECURITY ENGINEERING
- Security Solutions Development Strategies
- Expert implementation guidance with Business Continuity Planning/Disaster Recovery where solutioning close to 100% uptime
- Security Automation
- Identify, Analyze, Remediate, Implement, Review, Repeat (if necessary)
- Advanced Remediation & Patching Solutioning
- Expert InfoSec Consulting
- SIEM Implementation Strategies
- Security Architecture Strategy
- Security Tools Implementation from multiple vendors
FEATURED SERVICES
Ahieros cyber-security services include, but are not limited to:
- Information Security Policies
- Organization of Information Security
- Human Resource Security
- Asset Management
- Access Control
- Cryptography
- Physical and Environmental Security
- Operational Security - procedures and responsibilities, Protection from malware, Backup, Logging and monitoring, Control of operational software, Technical vulnerability management and Information systems audit coordination
- Communication Security - Network security management and Information transfer
- System Acquisition, Development and Maintenance - Security requirements of information systems, Security in development and support processes and Test data
- Supplier Relationships - Information security in supplier relationships and Supplier service delivery
- Information Security Incident Management - Management of information security incidents and improvements
- Compliance - Compliance with legal and contractual requirements and Information security reviews