|
SERVICES
IMPLEMENTATION
The initial phase of the GSS has as main objectives:
- Assess the environment's vulnerabilities
- Design an adequate and customized security level for the business
- Standardize and provide automated tools
- Deploy the desired security level
The main benefit of this phase is the standardization of the environment in relation to implemented security configurations and security processes.
The Security Implementation is composed by the Analysis, Design and Deployment phases.
Analysis
During the Analysis phase, all the vulnerabilities on the environment are detected, and key sensitive points to the business are identified. Such areas will receive special attention during the design of the security solutions, helping on the definition of the ideal security level.
The most critical vulnerabilities detected during the analysis will be immediately corrected inside the Emergency Corrections phase. Since the initial activities, a continuous service to monitor for vulnerabilities on the company's external perimeter is put in place, aiming to identify any critical exposures that can harm the company's services or data.
At the end of the Analysis phase, the most critical vulnerabilities will be mitigated or corrected, and a continuous process to detect exposure to the Internet will be in place.
Design
With the information gathered during the Analysis phase, Proteus teams will develop the proposed standards and security solutions that will define the customized security level to the customer. Such solutions will be discussed and explained to the administrative teams, aiming to address the real needs of the customer and to further customize the standards.
After the definition of the ideal security level, and the solutions needed, a project plan will be created to detail the actions needed to deploy such solutions, and the resources involved from both Proteus and the customer.
At the end of the Desgin phase, a series of reports are delivered describing the solutions agreed to remediate all the vulnerabilities found on the environment, together with the action plan to deploy them.
Deployment
This is the most important phase of the Security Implementation, where all the corrections and actions are performed on the environment to standardize the overall security level in the company and to deploy any changes on network architecture or infrastructure needed to improve the company's protection against threats.
As a result of the deployment activities, a series of automated tools and scripts responsible for automatically deploying the agree security standards to new servers or devices are delivered to the teams.
<back
|
 |