| |
Penetration Test-Vulnerability Analysis
Simple Penetration Test
External Network Risk Audit
Internal Network Risk Audit
Web Application Penetration Test
Social Engineering Evaluation
Physical Security Assessment
External Vulnerability Scanning
Internal Vulnerability Assessments
Firewall Assessment
Encryption Assessment
Wireless Security Assessments
ERP/CRM SYSTEMS Assessment
Network-Layer equipment Assessment
Risk Assessments
Operating systems Assessments
- Unix
- LINUX
- AIX
- DIGITAL UNIX
- HP-UX
- SOLARIS
- Mainframe & VMS
- Novell 3-6.X
- Windows NT,2000,2003
...............................................
|
|
| |
Security Consulting Security policy
Network devices Layer 2-3
Information privacy consulting
Security Training & Lectures
Cyber-Risk insurance planning
Reverse engineering
Security audit and architecture review
System hardening
Spam Mitigation
Security component development
Product security reviews
Network Architecture & Design
Operating System Security
- Unix
- LINUX
- AIX
- DIGITAL UNIX
- HP-UX
- SOLARIS
- Novell 3-6.X
- Windows NT,2000,2003
Incident Response
Storage Systems Security
Security Plans
Writing Security procedures
Bs7799 compliances
Business Continuity Plan
PC & Laptops Security
Encryption/Decryption consulting
Steganography (Using/Detection)
...............................................
|
|
|
| |
HIPAA Security
.................................................................................
|
For more information
Contact Us.
| |
April
2005
The final HIPAA Security Ruling has
been released. There are three categories of requirements in the new
ruling: administrative safeguards, physical safeguards, and
technical safeguards.
The ruling applies to electronic protected health information (EPHI)
and all health plans, health care clearinghouses, or health care
providers who transmit any protected health information in
electronic form, must comply with the ruling.
The final ruling is effective as of April 21, 2003. Most Covered
Entities will have until April 21, 2005 to comply and those small
health plans with annual receipts of $5 million or less, will have
until April 21, 2006 to comply.
The importance of HIPAA (Health Insurance Portability and
Accountability Act) is evident in the fact that compliance is not an
option. It is a requirement of every entity involved with electronic
health care information.
|
|
| |
Security and privacy are especially important for healthcare
organizations leveraging the Internet and Web-based applications to
exchange PHI (Protected Health Information).
Given the potential penalties for HIPAA violations, it is essential
to take appropriate preventive measures before a breach occurs.
Our information security assessment
will allow you to determine your organization's current security
posture in regards to the above categories. Our security experts
will "cover all the bases" and provide a comprehensive remediation
roadmap for you.
IF your company is exporting to USA
health sector , you must have HIPAA compliance, contact us to
schedule appointment .
|
|
| |
How SecuriGo Fits Into a HIPAA-Compliance Plan?
Contingency
plan (all listed implementation features
must be implemented)
|
Applications and
data criticality
analysis.
Data backup plan.
Disaster recovery
plan.
Emergency mode
operation plan.
Testing and
revision. |
|
|
. |
|
|
Information
access control (all listed
implementation features must be
implemented).
|
Access
authorization.
Access
establishment.
Access
modification. |
|
|
Personnel security
|
Assure supervision
of maintenance
personnel by
authorized,
knowledgeable
person.
Maintenance of
record of access
authorizations.
Operating, and in
some cases,
maintenance
personnel have
proper access
authorization.
Personnel
clearance procedure.
Personnel
security
policy/procedure.
System users,
including
maintenance
personnel, trained
in security. |
|
|
Security configuration mgmt. (all
listed implementation features must be
implemented
|
Documentation.
Hardware/software
installation &
maintenance review
and testing for
security features.
Inventory.
Security Testing.
Virus checking. |
Training (all listed
implementation features must
be implemented)
|
Awareness
training
for
all
personnel
(including
mgmt).
Periodic
security
reminders.
User
education
concerning
virus
protection.
User
education
in
importance
of
monitoring
log
in
success/failure,
and
how
to
report
discrepancies.
User
education
in
password
management. |
|
|
|
|
|
|
|
|
|
|