Visiminds Technologies, home

Security services

Governance, risk and compliance

Policies, risks and controls that your customers and auditors can check. Our GRC (Governance, risk and compliance. Security policies, the review of risks, and meeting the rules and standards that apply to you.) work helps with ISO 27001 (ISO/IEC 27001. The international standard for an information security management system.), SOC 2 (An audit of how a service company protects customer data.) and regional compliance, and with the security checklists (The questions a customer sends before it buys, to check how a supplier protects its data.) your customers send.

A security policy, a three by three risk grid with one risk marked, and a list of controls with ticks, each feeding a folder of evidence for the auditor

What we do

We shape the work to your company, to your customers, and to the rules of your country or region.

Governance

How your company decides on security and keeps control of it.

  • Security policies and procedures
  • Controls chosen and put in place

Risk

What could go wrong, and what you decide to do about it.

  • Risk assessment, and the risk you are willing to accept (The amount of risk a company decides it is willing to accept.)
  • High availability, disaster recovery and business continuity

Compliance

The standards and rules that apply to you, and your customers' checks.

  • Help with ISO 27001 and regional compliance
  • Internal security and process audits, and the changes SOC 2 needs
  • Your customers' security checklists, answered and approved
A bank sends a security checklist, each question is answered with its evidence attached, and the checklist comes back approved

Your customers' security checklists

Banks and insurers send security checklists before they buy. We answer them with you, with the evidence each answer needs, through to approval.

A virtual CISO (A fractional chief information security officer. Security leadership as a service. A virtual CISO sets your security direction, puts it in place with your team, and reports on it to management.) can also run your GRC with your team. About the virtual CISO

Standards, in two groups

What our GRC work helps with, and what Ivy Insight maps its findings to. We keep the two apart.

From our GRC work

Standards our GRC work has helped clients with.

  • ISO 27001
  • SOC 2
  • Regional compliance

Ivy Insight maps findings to

9 standards, as Visiminds' own mapping, not a statement of compliance. The mapping can be adapted to your needs and to the regulations of your country or region.

  • OWASP ASVS (OWASP Application Security Verification Standard. A list of security requirements a web application should meet, used to build it and to test it.)
  • PCI DSS (Payment Card Industry Data Security Standard. The security rules for any company that stores, processes or sends payment card data.)
  • NIST SP 800-53 (A large catalogue of security and privacy controls from the US National Institute of Standards and Technology.)
  • ISO 27001 Annex A (The list of security controls in ISO/IEC 27001. A company chooses the ones that apply to it.)
  • NIST CSF (NIST Cybersecurity Framework. A widely used framework from the US National Institute of Standards and Technology for organising security work.)
  • SOC 2
  • HIPAA (Health Insurance Portability and Accountability Act. A United States law that protects health information. Its Security Rule says how that information must be kept safe.)
  • MITRE CAPEC (Common Attack Pattern Enumeration and Classification. MITRE's catalogue of the ways attackers break into software.)
  • EU Cyber Resilience Act (The European Union law that sets security rules for products with digital parts, such as software and connected devices.)

Evidence for an audit, from the scans

A finding with the evidence it rests on, handed to an auditor who ticks the standard it answers and keeps the record

Each finding keeps its evidence

Each Ivy Insight finding keeps the evidence it rests on. Benchmark checks keep the command and its output.

Every report shows what it covered and what it left out, so an auditor can see both.

From our work

Case study 6

A startup's product made ready for banks

GRC leadership as part of virtual CISO work, for a large technology startup. The aim was to get its product through the security checks of the top 25 banks and insurers. We worked with its clients on their security checklists, and got the approvals.

Case study 4

Compliance for a system integrator's clients

Help with ISO 27001 and other regional compliance, as part of our security services for the clients of a large system integrator in the UAE.

Case study 2

A security and process audit for SOC 2

A security and process audit for a global cybersecurity company, and the changes needed for SOC 2 compliance. This was part of our joint development work with the company.

See also use case 7: Passing customer security checks, for startups, product companies and companies selling to banks.

Tell us what you need

An audit to prepare for, a customer checklist, or policies to write: tell us at info@visiminds.com.