# Cybersecurity Strategy and Operational Assurance

## Cybersecurity Strategy and Operational Assurance

### Keep moving forward

* * *

Designed to be final phase of the CCS Cybersecurity Development Program series, the CCS Cybersecurity Strategy and Operational Assurance offering can take the place of dedicated in-house cybersecurity expertise for the short, medium, or even long-term. Depending on client needs, the service can include:

1. **Continued alignment of cybersecurity to corporate strategy and business goals** – _Often called ‘virtual CISO’ or other buzz-phrase, it is nevertheless a fact that few organisations require a full-time employee at this level. The role must be fulfilled however;_
2. **Cybersecurity representation in the Governance meetings** – _Most organisations already have representatives for Sales, Operations, Legal, HR etc, few have dedicated in-house cybersecurity expertise. It is critical that security is in on everything;_
3. **Operational Assurance / Internal Audit** – _Every Key Domain entails the periodic maintenance of some process, some have several. From quarterly vulnerability scans to annual penetration tests, security controls must be operationalised and measured in order to be effective_.

_The service is designed to be completely flexible in terms of tasks, deliverables and longevity. In an ideal world this service would not be required, so the service will provide only what is required, for as long as it is required and no more._

## Our Methodology

## Completely dependent on clients needs, it can nevertheless include the following:

- **Governance** – _Bi-weekly/monthly/quarterly Governance Committee Meetings;_
- **Policy Set** – _Annual review of Policies, changes to Standards after patching etc;_.
- **Legal** – _Review of adherence to regulatory and contractual obligations;_
- **Human Resources** – _Review of on-boarding procedures, access control, SAT etc;_.
- **Asset Management** – _Comparison of asset register to vulnerability scan results etc_.
