Information Security Management System and Certification for VAS and Data Provider in Telecom Industry: A Case Study



Similar documents
E f f e c t i v e p r o c e s s - d r i v e n

Managed Desktop Support Services

Managed IT Services by

IT Governance: The benefits of an Information Security Management System

Benchmark of controls over IT activities Report. ABC Ltd

India USA South Africa

ASSET Connect. The next level in Critical Environment Operational Efficiency

EBS. Remote Infrastructure Managed Services. EBS Ltd. 12, Mihail Tenev Str Sofia Bulgaria office@ebs.bg

About Injazat Data Systems

Company Information. Company Mission, Strategies and Planning. A New Experience in Outsourcing: Change the way you outsource your Business.

Your Infrastructure. Our Responsibility.

Change is Good. By K. Yates. Figure 1: Why converged communications matters. IT/Telecom used to generate Enterprise top line growth

Cloud vision and capabilities

Web Performance Management 12 Steps To Ensure Successful SAAS Delivery How To Protect Revenue, Renewals & Customer Satisfaction

EXTENDING YOUR REACH GLOBALLY THROUGH OUTSOURCING

Managed Desktop Services. End-user workplace management solutions for your distributed-client computing environment. HP Services

AWS (Amazon Web Services) Managed

Managed Services. Business Intelligence Solutions

ISO/IEC IT Service Management - Benefits and Requirements for Service Providers and Customers

Productivity Gains for SMBs with OnCloud ERP PestBusters takes 1st mover advantage

Introduction. OUR MISSION We believe change is the only constant and we embrace it to provide world class services for our clients.

Galaxy Office Automation Pvt. Ltd. Listening to Business, Applying Technology

A guide to HP enterprise mobility solutions. Expanding the potential of your business with advanced mobility services

WHITE PAPER December, 2008

Intelligent Infrastructure Management System (IIMS)

At the Heart of Connected Manufacturing

Cisco Unified Communications and Collaboration technology is changing the way we go about the business of the University.

Information Security Managing The Risk

Mystery Shopping Proposal

ASE STUDY. Performance Testing & Security Testing for Web Applications.

Hva vil du med Service management i din organisasjon?

"Service Lifecycle Management strategies for CIOs"

Enterprise. Application Performance Optimization Services Boosting your application performance by optimizing network resources

Delivering Quality Service with IBM Service Management

Economic Benefits of Cisco CloudVerse

ramyam E x p e r i e n c e Y o u r C u s t o m e r s D e l i g h t Ramyam is a Customer Experience Management Company Intelligence Lab

Name: Lynda Cooper Date: November 24th. Revising ISO/IEC to fit the future of service management

On Demand Penetration Testing Applications Networks Compliance.

Outsourcing and Information Security

ITSM Process Description

SPAN. White Paper. Change Management. Introduction

ITSM/A Design & Optimization Services: ProvidING the Roadmap for IT Transformation

TURKEY BUSINESS ANALYSIS REPORT Thinking Like the Business

Reaping the Full Benefits of a Hybrid Network

TESCRA ICM (ICC) Case Study

CONSULTING SERVICES Managed IT services

Business Continuity Management Emerging Trends

AL RAFEE ENTERPRISES Solutions & Expertise.

The Advantages and Disadvantages of ITIL

AN OVERVIEW OF INFORMATION SECURITY STANDARDS

Call Center Services

Adopting ITIL Framework By Vinayak Ghadi

Enhancing Business Performance Through Innovative Technology Solutions

WHITE PAPER: STRATEGIC IMPACT PILLARS FOR EFFICIENT MIGRATION TO CLOUD COMPUTING IN GOVERNMENT

HI-TECH CO. SYSTEMS. Company Profile

Build-Operate-Transfer (BOT) Model

Ensuring security the last barrier to Cloud adoption

ISO/IEC 27001:2013 Your implementation guide

Prominent Solution. Take on Tomorrow INDIA S LEADING BPO, KPO & RPO SERVICE PROVIDER.

a quantum leap to new innovation

Strategies for assessing cloud security

ABOUT US WHO WE ARE. Helping you succeed against the odds...

WAN Migration Techniques

IT Governance Regulatory. P.K.Patel AGM, MoF

Telegenisys. White Paper Choosing the Right Business Service Provider (BSP) Outsourcing Excellence

Blue Fire Thames Court 1 Victoria Street Windsor SL4 1YB enquiries@bluefire-uk.com

White Paper. What the ideal cloud-based web security service should provide. the tools and services to look for

Tecknodreams Software Consulting Pvt. Ltd. Managing global IT operations using SapphireIMS

The Future of Best Practices in IT Service Management - ITIL Version 3 Explained

Network Test Labs Inc Security Assessment Service Description Complementary Service Offering for New Clients

MANAGED SERVICES. A partnership for cost efficient operations and service quality

Enterprise Cloud Services HOSTED PRIVATE CLOUD

SMS Based Sales Tracking Solution

Locus IT Services Bangalore INDIA. *MS Dynamics *MS SharePoint *RMS Consulting *Staff Augmentation *Learning

Bunzl Distribution. Solving problems for sales and purchasing teams by revealing new insights with analytics. Overview

Oracle Advanced Customer Support Services Slavko Rožič Support Director

Solutions for Communications with IBM Netezza Network Analytics Accelerator

ISO20000: What it is and how it relates to ITIL v3

DIXIT INFOTECH SERVICES

Case Study: Financial Credit Union

Security Testing for Web Applications and Network Resources. (Banking).

Things You Need to Know About Cloud Backup

WhitePaper. Private Cloud Computing Essentials

Logicalis Managed Service Strategy & Support. Geraldine Moatti Proposition Manager, Services

Cisco Remote Management Services for Financial Services

Transcription:

CASE STUDY Information Security Management System and Certification for VAS and Data Provider in Telecom Industry: A Case Study 1

Information Security Certification for a premier VAS and Data Solution Provider for Telecom Industry ABOUT VAS and Data Solution Provider Customer is India's largest VAS and data solutions provider for mobile, landline and media service providers. Phases and Deliverables: The phases and deliverables described above include:- Initiation Assessment Plan for alignment Secure and Align Certification Benchmark Continual Improvements Customer's innovative multimodal and multiservice platform integrates technologies like speech recognition, WAP, SMS, MMS, USSD, voice and location amongst others. This enables service providers, media houses, corporate, & merchants to offer interactive services on any network technology to provide an enriched end-user experience. In addition to providing technology, platform, applications and content, Customer also offers its customers a Managed Services operations model. Customer is headquartered in Bangalore, with offices in 9 countries, customers in over 20 countries, and employee strength of 1000+. Scope Customer in its strategic initiative of implementing Information Security controls and practices in alignment with global best information security practices, was looking at engaging with a capable IT Service Management partner to build a robust Information Security Management System (ISMS) and needed assistance to move towards ISO 27001 certification. The immediate focus was on securing the business environment of Customer by: Assessing the current infrastructure and practices for risks and vulnerabilities Mitigate the identified and prioritized vulnerabilities Plan and achieve the benchmarking through ISO/IEC 27001 certification. The Information Security Management System at Customer s environment encompasses VAS & Data solutions offered to its mobile, Landline & Media service providers. The IT Infrastructure setup at the Customer location has been configured with Client Server Systems. The VPN connectivity established between the various branches of Customer enables the users to access the business data remotely across WAN. The network setup includes multiple high-speed Internet links with access to client locations over the internet. There are two teams that support the IT systems infrastructure which are identified as the scope of the system to be established.. 2

Information Security Gap Analysis and ISMS organization As an VAS provider, Customer had vast product development team to develop and support its VAS and Data services. It was analyzed and made aware about the vulnerabilities and threats to the services in applications vis-a-viz their infrastructure. CEO/CFO/CIO Internal Audit HR Finance Administration Information Technology Information Security IT Operations L2 / L3 Support Software Development Information security is core need for the VAS provider and Information Security system adherence is a mandatory requirement for them to work with the telecom providers. In order to enable them to partner with the telecom service providers, ISMS governance, management and operational org. structure was rightly placed for effective management of the Information Security system 3

ISMS implementation and Certification The following sections enumerate the ISMS scope in terms of The relevant critical/key business processes of the organization The personnel directly involved in delivering the key business processes The Information level business functions which together comprise the business assets (categories of information) which are processed, stored or communicated in the delivery of the business processes/functions IT systems and components (including hardware and software) that are used by staff and relied upon in the delivery of the business processes The physical environments and locations in which the personnel are based and the IT components located Supporting business processes, e.g. other departments within the organization, that have responsibility for some aspect of security upon which the in-scope business process depends External third parties that provide a security-related service 4

Business Benefits Gave visibility into all potential information security threats and vulnerabilities which they can tighten the security levels over a period of time depending on business risks. Easy enablement to sign up as per information requirements of telecom providers. Customer could focus on their core strategic business initiatives with this selective outsourcing engagement. Product development functions now focus on building better secured product than earlier which increases its quality compliance against their competitors. Increase Growth, Revenue and Market Leadership. Capabilities of GLOPORE IMS GLOPORE IMS Information Security Management consultants understand the customer environment, requirements which are strategic business in nature and drive the vision of the customer into reality. This competency of GLOPORE IMS to always view the business objectives of customers has helped GLOPORE IMS to deliver services as expected by customers. About GLOPORE IMS GLOPORE IMS is a leading Indian ICT/ IT Infrastructure and Service Management (IMS/ITSM) company, headquartered in Bangalore, with its presence in tier 1 & tier 2 cities, as well as most of tier 3 cities in INDIA and global presence in UK and US. As long term strategic business partners, GLOPORE IMS delivers ITSM Excellence through Managed IT Services, Consulting & Training Services, Infrastructure & Technology Solutions and Service Management Consulting Solutions to its customers, globally. Its customers are medium to large businesses where IT function plays a vital role as business driver. As long term strategic business partners, GLOPORE IMS delivers ITSM Excellence through Managed IT Services, Consulting & Training Services, Infrastructure & Technology Solutions and Service Management Consulting Solutions across India and Globally.. Its customers are medium to large businesses where IT function plays a vital role as business driver. GLOPORE IMS has consistently helped businesses to integrate their business and IT strategy, which in turn, improves customer satisfaction, lowers IT total cost of ownership (TCO) and its customers achieves higher return on their investments (ROI). This has enabled its customers to sharpen focus on their core business, which has helped them reduce time-to-market, increase competitiveness & maximize revenue growth. As a pure-play IT Service Management (Introduction Company, on GLOPORE GLOPORE IMS) IMS offers comprehensive and unique mix of ITSM offerings, cost effectively, leveraging shared services model. ITSM service offerings encompass business and IT lifecycle covering strategy, design, transition, operations, governance and continual service improvement. GLOPORE IMS is the 1st company in India certified by BSI for ISO/IEC 20000:2011. It is the leading Managed IT Services provider, with a strong market leadership established in the Education segment as their ICT Managed Services growth partner. Is has been a preferred partner for Fortune 500 companies for their ITSM needs. It won the Best Startup Award in Services sector at Silicon India's Startup City 2009 & 2010 and has been recognized among the Top 10 Most Promising Companies in the IMS space in India" in 2010. GLOPORE IMS is a medium sized, fast growing company and has been identified as an exceedingly efficient entrepreneurial & agile ITSM partner. London, UK GLOPORE Corporation 60 Furrow Way, Maidenhead SL6 3NY, UK Ph : +44 (0) 1628566161/1628680791 Mobile : +44 (0) 7901514086 Contact : Ravinder Paul Singh 5 Boston, USA GLOPORE Corporation P O Box 929 Nutting Lake, MA 01865-092 Ph: 1-(617)-532-0021 / 1-(888)-744-3426 Contact : Satish Kumar Bangalore, INDIA GLOPORE IM Services Pvt. Ltd. SLA Arcade, #595, 2 nd & 3 rd Floor, 15th Cross 1st Phase, Outer Ring Road, J P Nagar Bengaluru - 560 078, India Ph: +91-80-3318 0000 Fax : +91-80-3318 0005