Integral to any Information Security Management System (ISMS) is the process of “assessing” the control environment to understand where control gaps may be leaving the organization at unacceptable risk. PPS’s Information Security Assessment activities generally fall into one (or more) of the following types:
- Design Assessment activities which evaluate the appropriateness of controls by comparing the control design against the client’s control objectives, industry good practice, laws/regulations, and/or the auditor’s professional judgment (e.g., an Application Architecture Review).
- Compliance Assessment activities which validate that the control measures established are working as designed, consistently, and continuously (e.g., a Password Audit).
- Substantiative Assessment activities that provide assurance that the “net” control objectives are being achieved, and where they are not, provide a measure of probability and business impact (e.g., a Penetration Test).
Representative services are detailed below. However, the ideal information assurance activities for your organization may be as unique as the specific Information Security risks you face. Because we work with you, we can tailor services to meet your specific needs.




