Galena IT ltd.

  Welcome to Galena

Galena IT Ltd are independent IT Strategists who provide specialist independent IT services.....

» IT Strategy Consultancy
» IT Strategy Training

» Information Security Consultancy
» IT Governance
» Independent ERP Consultancy
» IT Director Service

» Green IT Consultancy
» IT Service Management

Security Standards

The Information Security Standard is published in two parts:

ISO/IEC 27001:2005 - Information Security Management Systems - Requirements
more Information... 

ISO/IEC 27002:2005 - Code of Practice for Information Security Management more Information 

There is a need to establish a comprehensive Information Security Policy within all organizations. You need to ensure the confidentiality, integrity, and availability of both vital corporate information and customer information. The standard for Information Security Management System (ISMS) BS 7799-2 (the predecessor to ISO/ IEC 27001:2005) has fast become one of the worlds established best sellers.

Client Testimonials

"When we first decided that we needed to implement a set of Information Security standards to meet the needs of our clients we did not have a clue were to start. We contacted Galena who walked us through every step of the process and using sets of templates, tools and databases within a very short period of time we where ready for certification."

IT Manager - IT Company, North West


"We operate a very fast moving internet based business with offices across Yorkshire housing over 100 full time staff. When we approached Galena to take on our Information Security requirements, and we had no hesitation in employing them. They quickly and efficiently implemented a number of policies and procedures that had an instant effect on the business."

Managing Director - Internet Business, Yorkshire

Information Security

Galena IT Ltd provide consultancy and auditing services based on ISO 27001 the Information Security Standard.

Information is the lifeblood of all organisations large and small, be it your customer database, sales order book, accounts collections report or even drawings and computer programs.
"44% of all UK businesses have suffered at least one malicious security breach in the past year. The average cost of a serious security incident was £30.000”. This is quoted from the Information Security Breaches Survey compiled by the Department of Trade and Industry.

Information should be protected and secure from both internal & external threats and comply to all relevant legislation such as the Data Protection Act 1988 and the Computer Misuse Act 1990. Information Security Management enables information to be shared to the appropriate people whist ensuring the protection of that information.

  • Benchmarking - Assessment of the status of information security management within an organisation against ISO 27001, this will then allow the planning of the implementation of a Information Security Management Systems (ISMS).

  • Scope Study - Advice on the implications and suitability of ISO 27001 for an organisation. Assessment of the feasibility, costs and timetable for implementing ISO 27001 and, if required, achieving certification. The scooping exercise may identify areas of supplier or customers systems that may be included in the scope of the ISMS.

  • Gap Analysis - Comparison of existing information security arrangements with those required by the standard, identification of weaknesses and development of a ISO 27001 implementation plan.

  • Risk Assessment - Risk Analysis is the qualification and quantification of risks in a given system and the planning for the appropriate levels of resources to minimise those risks.

    To quantify risks, one can measure it as a combination of several viewpoints. Selected examples of such viewpoints are: the potential cost of damage, the vulnerability of the risk and the frequency of occurrence when a single point of security is breached. The analyst can choose to use other viewpoints appropriate to the nature of the organisation. So, the magnitude of a given risk can be perceived as a ‘volume’ based on the three dimensions. Each of the viewpoint can also be assigned weightings. For example, ‘cost of damage’ can be given a factor of two, which usually gives a more accurate reflection of the reality.

    Technologies do not sit still, with the continuing advances in computing power, it is becoming cheaper and faster to crack cryptographic algorithms. The means to protect data have to keep up with the adversary, akin to the evolutionary race between prey and predator. Risks in any given systems would have to be revisited and re-assessed periodically.

    Last but not least, it is important to note that no matter how many security mechanisms are in place, there will always be security risks in the long term. These risks, however, would be kept minimal with a well executed risk analysis and series of follow-up actions.


  • ISO 27001 Implementation - Delivery of an information security improvement program to achieve compliance with ISO27001, including independent security health check, ISO27001 compliance assessment, extensive security risk assessment, information security consultancy
    follow-up security audit and security awareness training.


  • Certification - Assistance in achieving formal certification through a third party certification agency.

  • Information Security Management - Project and quality management of ISO 27001 programmes.

  • Training and Education - Security awareness for staff and training on all aspects of ISO 27001.

  • Documentation - Writing and implementing security policies, statements of applicability, procedures, manuals and controls.

  • Technical Reports - Our technical staff are highly skilled we design, implement and consult on a wide range of technical information security issues.

 

Customer Login
Username: Password:



Galena Company Brochure

Free White Paper - Galena IT Law Fact Sheet

Useful Security Downloads

You may find the following downloads useful. To save the documents to your desktop, right click on the download link and select "save target as". You will need Adobe Acrobat Reader to view these files. Adobe Acrobat reader is available by clicking here (external site).

» DTi Information Security Survey 2008
» DTi Information Security Survey 2006
» DTi Information Security Survey 2004
» DTi Information Security Survey 2002

» IoD Information Security Guide
» IT Security Report Sample
» Risk Assessment Questionnaire

 


Email: sales@galenait.com
Phone: (+44) 0870 803 4556
Fax: (+44) 0870 803 4557
Galena IT Ltd, Technology House, University of Salford, Lissadel Street, Salford, M6 6AP

Copyright © 2007 Galena IT Ltd. All Rights Reserved.
Registered in England No. 05485219
VAT No. 881 0443 34
Terms of Use | Privacy Policy