Practice
IT Governance
IT governance means keeping IT processes and systems performing against business priorities, managing the risks that threaten the information flows behind day-to-day operations, and protecting company know-how.

IT processes that support the business
Efficiency and return on investment
- Recognised frameworks such as COBIT and ITIL to design efficient IT process management models
- Organisational models that comply with specific regulations, such as Italian Legislative Decree 231/2001 on corporate liability, the Sarbanes-Oxley Act and Bank of Italy supervisory rules for credit institutions
Risk analysis
Countermeasures for continuity and security
- Risk analysis and management with a methodology based on RiS, Risk Integrated Service, developed by the NIS software factory
- Analysis by vertical sector, such as finance, healthcare and critical infrastructure, or by technology platform, cloud provider side or user side
- Identifying the countermeasures that ensure business continuity and the security of end users
IT and security management systems
From set-up to certification
- Business Continuity Management Systems (BCMS) to ISO 22301
- Service Management Systems (SMS) to ISO/IEC 20000
- Information Security Management Systems (ISMS) to ISO/IEC 27001
- Consulting on implementing management systems and support through certification
- First-party (internal), second-party (subsidiaries and suppliers) and third-party audits (on behalf of a certification body)
- Vulnerability assessments and penetration tests by multidisciplinary teams, in line with mandatory and voluntary standards
Experience
Selected IT governance projects
- ISO/IEC 27001 risk assessment to set up an information security management system: avionics sector, 34 airport sites and 5 head offices
- Information security policies and procedures to ISO/IEC 27001: avionics sector
- ISO/IEC 27005 risk assessment for ISO/IEC 27001 recertification: service provider
- Risk analysis of network infrastructure and security management services: local public administration
- ISO/IEC 27001 management system set-up and certification: document archiving system
Training
Qualification courses on COBIT, ITIL, ISO/IEC 20000 and ISO/IEC 27001, from Foundation level to Lead Auditor, taught by trainers with hands-on consulting and audit experience.
Our trainingThe other practices
Contact
Let's talk about your project.
An IT process to govern, a risk to assess, software to evolve, a team to train. Tell us what you need.
Write to us