..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Government - CLAS Services for Accreditation

commissum is a company one hundred percent focused on the provision of information security advice and services. Our team has been providing the full range of these services to a broad cross-section of businesses and government organisations for over twenty years.

commissum'ko-mis-sum, n. that which is entrusted [Latin]

CLAS Accreditation Consultancy - Government Blue Light Agency

commissum provided experienced CLAS consultancy and supporting technical services to assist in attaining accreditation.

Client

The agency is part of a major Whitehall department that works to prevent loss of life and improve safety in its area of responsibility.

Client Requirement and Business Drivers

As a consequence of the Gershon review findings the Whitehall department implemented a Shared Services Centre in order to reduce operational costs across the department and its agencies.

In order to derive these planned benefits from the Shared Services Centre the agency needed to be able to connect to it. This required the agency to become Accredited to demonstrate appropriate information security management in order to facilitate this connection.

The client therefore decided that it was essential to engage with an independent, expert CLAS consultancy provider to analyse the requirements to attain accreditation and assist in delivering the requirements. The business drivers for this engagement can be summarised as follows:

  • Cost reduction targets as part of Whitehall wide shared services initiative
  • Secondary benefits for agency in terms of managing their operational risk by improving their organisation’s information security to recognised government Accreditation standards
  • The client recognised the potentially disastrous impact on operations that could arise from any security related incident

Recognising the importance of the right specialist expertise, together with the need for objectivity and independence commissum was engaged to meet the strategic, business and technical security related objectives of the project within tight timescales set by the business.

commissum Services Provided 

The assignment delivered services in the following areas:

Accreditation strategy 

commissum thoroughly reviewed the existing draft Risk Management and Accreditation Document Set.

Interviews were conducted with business sponsors and key IT staff to establish objectives, both explicit and underlying, of the Accreditation requirements. 

An initial gap analysis was conducted to assess what was required to attain Accreditation and consultancy was provided to assist the Agency in turning this into an implementation plan.

Advise on implementation and management of controls

commissum provided business and technical CLAS consultancy to both review existing controls in place and advise and implement deficient and missing required controls.

Areas covered included: physical security requirements, personnel security requirements, protective monitoring, security operational procedures advice, ISMS implementation, 3rd party access management and controls, RMADS risk assessments and documentation.

The agency continues to successfully move forward with its accreditation targets.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
"From the start the project went very smoothly despite the short notice. commissum maintained excellent communication throughout ........ their flexibility and responsiveness right up to the end of the project was of great value to us.”

Mr Keith H, Senior Business Manager - UK Local Government

"Above all I value the responsiveness and flexibility shown by commissum in responding to my requirements. Faced with short notice requests they have always rapidly responded, delivering on time with consistently excellent quality and clarity of reporting.”

Sonya B, IT Security - UK Local Government

"commissum recently provided us with services to assess a web application and supporting infrastructure. I was impressed with the consultants throughout the project, by their technical knowledge, flexibility, open communication and willingness to go that extra mile. Of particular benefit was the sound advice given both during and after the engagement. By identifying vulnerabilities promptly, accompanied with practical recommendations on how to address them. We were able to implement improvements quickly. Good value, a job well done.”

JM, Infosec Analyst, International Investment Bank