ASE.LT
Information security management services
MainServicesNews and eventsAboutDownloads
Information security management services
What we do

in information security management

  • Facilitate information security management system (ISMS) practice implementation within your environment based on ISO standards (ISO27002 / ISO17799);

  • Facilitate information security governance implementation based on CobIT and ValIT frameworks.

  • Formal certified audit of your information security managment system (ISMS) for ISO27001 compliance;

  • Autit of suppliers for compliance to your information security policies and contractual requirements;

  • Information security risk assessment of asset/project/busines process/practice/organization;

  • Identification and classification of information assets;

  • Identification of information owners, custodians and users;

  • Information security risk analysis based on business's value chain anlysis;

  • Facilitation of information security governace's strategy development;

  • Development and implementation of information security policy;

  • Development and implementation of policies and procedures within ISMS based on ISO27000/ISO17799 or CobIT controls;

  • On-site customised information security training for your managment and employees (on specific topic, like acceptable use policy, information security policy; information ownership; asset clasification; use of classified inofrmation; access manamegement; business continuity; security crisis management, etc) based on your specific needs and budget;

  • Business continuity/disaster recovery planning and testing;

  • IS continuity/disaster recovery planning and testing;

  • Systems restoration planing and testing;

  • Assessment of security controls in formal contracts (outsourcing, hosting, IT support, data exchange);

  • Facilitation of managment buy-in for information security;

  • Access managment practice review and implementation;

  • Assessment for the compliance to EU Data protection directive and/or Personal data protection Law of Lithuania;

  • other activities, related to information security managment practice field.

in project management

  • 4 hour customised on-site workshops on specific PM topic (project initiation; defining requirements; planning for closure; project control and conflict management; forecasting problems; responsibilities and stakeholders) and specific target audience ( managment, administrators, developers, users, project teams);

  • facilitation in collection of project's definition and requirements: project's concept definition; project's charter; analysis of stakeholders; terms of reference (TOR); work breakdown structure (WBS); risk management plan; quality management plan; communication plan; project closure plan; budget; schedule; statements of work(SOW).

  • project's quality control.

What we do
What we do not do
Request references