# Cyber-Security

Ahieros mission is to provide information technology solutions today to make the best tomorrow.

Cyber-security is the body of technologies, processes and practices designed to protect networks, computers, programs and data from attack, damage or unauthorized access. Ahieros encompasses cyber-security from a holistic approach (360 degree protection spherical approach) utilizing information security best practices.

## SECURITY FRAMEWORK
### GUIDANCE, IT AUDITING AND (GRC)
Institute policies and procedures to ensure compliance with Basel, Blockchain, CMMI, CoBIT, DFARS (252.204-7012, etc.), DIACAP, FAA, FCC, FEMA 426, FEMA 428, FIPS (including FIPS 140-3, 199, 200, etc.), FISMA, FFIEC, GIG, GLBA, GISRA, HIPAA, HITRUST, ITIL, ISO 27000 series (e.g. ISO 20001, ISO 27002, ISO 27017, ISO 27018, etc.), NERC (CIP, BES Cyber Systems), NIST (e.g. 800-171, 800-53, NISTIR 8011) PMI, PCI, SAS-70, SSAE -16, SOX, WCO, RMF, eMASS, and other IT audit requirements.

NISTIR 8011 - Automation Support for Security Control Assessment

NERC Critical Infrastructure Protocols (CIP) for BES (Bulk Electric System) Cyber Systems.  
ISO 27017 / 27018 - Cloud Security Best Practices

## SECURITY ENGINEERING

- Security Solutions Development Strategies
- Expert implementation guidance with Business Continuity Planning/Disaster Recovery where solutioning close to 100% uptime
- Security Automation
- Identify, Analyze, Remediate, Implement, Review, Repeat (if necessary)
- Advanced Remediation & Patching Solutioning
- Expert InfoSec Consulting
- SIEM Implementation Strategies
- Security Architecture Strategy
- Security Tools Implementation from multiple vendors

## FEATURED SERVICES

Ahieros cyber-security services include, but are not limited to:

- **Information Security Policies**  
- **Organization of Information Security**  
- **Human Resource Security**  
- **Asset Management**  
- **Access Control**  
- **Cryptography**  
- **Physical and Environmental Security**  
- **Operational Security** - procedures and responsibilities, Protection from malware, Backup, Logging and monitoring, Control of operational software, Technical vulnerability management and Information systems audit coordination  
- **Communication Security** - Network security management and Information transfer  
- **System Acquisition, Development and Maintenance** - Security requirements of information systems, Security in development and support processes and Test data  
- **Supplier Relationships** - Information security in supplier relationships and Supplier service delivery  
- **Information Security Incident Management** - Management of information security incidents and improvements  
- **Compliance** - Compliance with legal and contractual requirements and Information security reviews
