CASE STUDY Information Security Management System and Certification for VAS and Data Provider in Telecom Industry: A Case Study 1
Information Security Certification for a premier VAS and Data Solution Provider for Telecom Industry ABOUT VAS and Data Solution Provider Customer is India's largest VAS and data solutions provider for mobile, landline and media service providers. Phases and Deliverables: The phases and deliverables described above include:- Initiation Assessment Plan for alignment Secure and Align Certification Benchmark Continual Improvements Customer's innovative multimodal and multiservice platform integrates technologies like speech recognition, WAP, SMS, MMS, USSD, voice and location amongst others. This enables service providers, media houses, corporate, & merchants to offer interactive services on any network technology to provide an enriched end-user experience. In addition to providing technology, platform, applications and content, Customer also offers its customers a Managed Services operations model. Customer is headquartered in Bangalore, with offices in 9 countries, customers in over 20 countries, and employee strength of 1000+. Scope Customer in its strategic initiative of implementing Information Security controls and practices in alignment with global best information security practices, was looking at engaging with a capable IT Service Management partner to build a robust Information Security Management System (ISMS) and needed assistance to move towards ISO 27001 certification. The immediate focus was on securing the business environment of Customer by: Assessing the current infrastructure and practices for risks and vulnerabilities Mitigate the identified and prioritized vulnerabilities Plan and achieve the benchmarking through ISO/IEC 27001 certification. The Information Security Management System at Customer s environment encompasses VAS & Data solutions offered to its mobile, Landline & Media service providers. The IT Infrastructure setup at the Customer location has been configured with Client Server Systems. The VPN connectivity established between the various branches of Customer enables the users to access the business data remotely across WAN. The network setup includes multiple high-speed Internet links with access to client locations over the internet. There are two teams that support the IT systems infrastructure which are identified as the scope of the system to be established.. 2
Information Security Gap Analysis and ISMS organization As an VAS provider, Customer had vast product development team to develop and support its VAS and Data services. It was analyzed and made aware about the vulnerabilities and threats to the services in applications vis-a-viz their infrastructure. CEO/CFO/CIO Internal Audit HR Finance Administration Information Technology Information Security IT Operations L2 / L3 Support Software Development Information security is core need for the VAS provider and Information Security system adherence is a mandatory requirement for them to work with the telecom providers. In order to enable them to partner with the telecom service providers, ISMS governance, management and operational org. structure was rightly placed for effective management of the Information Security system 3
ISMS implementation and Certification The following sections enumerate the ISMS scope in terms of The relevant critical/key business processes of the organization The personnel directly involved in delivering the key business processes The Information level business functions which together comprise the business assets (categories of information) which are processed, stored or communicated in the delivery of the business processes/functions IT systems and components (including hardware and software) that are used by staff and relied upon in the delivery of the business processes The physical environments and locations in which the personnel are based and the IT components located Supporting business processes, e.g. other departments within the organization, that have responsibility for some aspect of security upon which the in-scope business process depends External third parties that provide a security-related service 4
Business Benefits Gave visibility into all potential information security threats and vulnerabilities which they can tighten the security levels over a period of time depending on business risks. Easy enablement to sign up as per information requirements of telecom providers. Customer could focus on their core strategic business initiatives with this selective outsourcing engagement. Product development functions now focus on building better secured product than earlier which increases its quality compliance against their competitors. Increase Growth, Revenue and Market Leadership. Capabilities of GLOPORE IMS GLOPORE IMS Information Security Management consultants understand the customer environment, requirements which are strategic business in nature and drive the vision of the customer into reality. This competency of GLOPORE IMS to always view the business objectives of customers has helped GLOPORE IMS to deliver services as expected by customers. About GLOPORE IMS GLOPORE IMS is a leading Indian ICT/ IT Infrastructure and Service Management (IMS/ITSM) company, headquartered in Bangalore, with its presence in tier 1 & tier 2 cities, as well as most of tier 3 cities in INDIA and global presence in UK and US. As long term strategic business partners, GLOPORE IMS delivers ITSM Excellence through Managed IT Services, Consulting & Training Services, Infrastructure & Technology Solutions and Service Management Consulting Solutions to its customers, globally. Its customers are medium to large businesses where IT function plays a vital role as business driver. As long term strategic business partners, GLOPORE IMS delivers ITSM Excellence through Managed IT Services, Consulting & Training Services, Infrastructure & Technology Solutions and Service Management Consulting Solutions across India and Globally.. Its customers are medium to large businesses where IT function plays a vital role as business driver. GLOPORE IMS has consistently helped businesses to integrate their business and IT strategy, which in turn, improves customer satisfaction, lowers IT total cost of ownership (TCO) and its customers achieves higher return on their investments (ROI). This has enabled its customers to sharpen focus on their core business, which has helped them reduce time-to-market, increase competitiveness & maximize revenue growth. As a pure-play IT Service Management (Introduction Company, on GLOPORE GLOPORE IMS) IMS offers comprehensive and unique mix of ITSM offerings, cost effectively, leveraging shared services model. ITSM service offerings encompass business and IT lifecycle covering strategy, design, transition, operations, governance and continual service improvement. GLOPORE IMS is the 1st company in India certified by BSI for ISO/IEC 20000:2011. It is the leading Managed IT Services provider, with a strong market leadership established in the Education segment as their ICT Managed Services growth partner. Is has been a preferred partner for Fortune 500 companies for their ITSM needs. It won the Best Startup Award in Services sector at Silicon India's Startup City 2009 & 2010 and has been recognized among the Top 10 Most Promising Companies in the IMS space in India" in 2010. GLOPORE IMS is a medium sized, fast growing company and has been identified as an exceedingly efficient entrepreneurial & agile ITSM partner. London, UK GLOPORE Corporation 60 Furrow Way, Maidenhead SL6 3NY, UK Ph : +44 (0) 1628566161/1628680791 Mobile : +44 (0) 7901514086 Contact : Ravinder Paul Singh 5 Boston, USA GLOPORE Corporation P O Box 929 Nutting Lake, MA 01865-092 Ph: 1-(617)-532-0021 / 1-(888)-744-3426 Contact : Satish Kumar Bangalore, INDIA GLOPORE IM Services Pvt. Ltd. SLA Arcade, #595, 2 nd & 3 rd Floor, 15th Cross 1st Phase, Outer Ring Road, J P Nagar Bengaluru - 560 078, India Ph: +91-80-3318 0000 Fax : +91-80-3318 0005