Description of services provided

  • To conduct an internal assessment on all controls using Gartner security assessment tool and a Risk Dashboard.
  • Facilitated communication and collaboration between IT teams, security personnel, and business units to gather relevant information and insights.
  • Gathered data and documentation related to existing security controls, policies, procedures, and incidents.
  • Conducted interviews with subject matter experts to gather insights into the effectiveness and implementation of security controls.
  • Configured the Gartner Security Assessment Tool according to the organization’s specific requirements, including customization of assessment criteria and scoring mechanisms.
  • Developed and implemented a Risk Dashboard using Auditboard, integrating data from the internal assessment and other relevant sources.
  • Created a gap analysis document within Auditboard to highlight areas of improvement based on the assessment findings.
  • Identified and opened risks in the Auditboard for all identified gaps, ensuring visibility and accountability for risk management.
  • Work with ITS team to create a DLP plan as a delivery for Zero Trust project.
  • Implemented Risk dashboard.
    • Build risk registry.
    • Build risk by framework.
  • Implemented Cross Comply dashboard.
    • Dashboard for Fedramp
    • Dashboard for NIST
    • Dashboard for SOC2
  • Ad-hoc reports
  • Reports generated out of Microsoft Purview application for DLP monitoring.
  • Monitored data loss prevention activities and reported on key metrics to track effectiveness and compliance with security policies.
  • Provided timely insights and recommendations to stakeholders based on DLP monitoring reports.
  • Configure data classification labels and auto-labeling policies to ensure compliance with regulatory standards.
  • Implement sensitive data tagging on platforms like SharePoint to enhance data visibility and governance.
  • Deploy Endpoint DLP solutions using Microsoft Purview/Defender to safeguard sensitive data across user devices.
    • Design and implement DLP policies to monitor and restrict unauthorized actions on confidential data.
    • Prevent data leakage by enforcing robust controls on data handling and sharing practices.