IT risk analysis according to BSI 100-3
Even in mid-size companies, today's operative IT environments are extremely heterogenuous and complex. Although often reported otherwise, this circumstance is not due to the negligence of those who are responsible for technical matters. Usually, nowadays' complexity is the result of long-lasting developments, where IT systems and applications where fine-tuned to meet the organization's specific requirements perfectly, providing a valuable competitive advantage.
But - to tell the truth - all too often there is no person in the organization knowing which of the IT systems are most business critical and which threats are most likely to endanger the business processes. An approach driven purely by a technique point of view does not provide helpful answers here.
2B Advice developed a consulting approach addressing the involved IT systems, information assets and the threats against them from the business process point of view.
As a deliverable from this approach, the customer is getting an asset inventory showing location and values of the real "information diamonds" in the organization.
As a second deliverable, the customer is getting valuable information about the threats the organization is facing - and appropriate countermeasures.
Last, but not least, the customer is getting valuable input for decisions with respect to business contingency planning (i.e., when struck by a disaster, which are the systems that have to be brought back into operative status with highest priority).
