Practice

IT Governance

IT governance means keeping IT processes and systems performing against business priorities, managing the risks that threaten the information flows behind day-to-day operations, and protecting company know-how.

IT processes that support the business

Efficiency and return on investment

  • Recognised frameworks such as COBIT and ITIL to design efficient IT process management models
  • Organisational models that comply with specific regulations, such as Italian Legislative Decree 231/2001 on corporate liability, the Sarbanes-Oxley Act and Bank of Italy supervisory rules for credit institutions

Risk analysis

Countermeasures for continuity and security

  • Risk analysis and management with a methodology based on RiS, Risk Integrated Service, developed by the NIS software factory
  • Analysis by vertical sector, such as finance, healthcare and critical infrastructure, or by technology platform, cloud provider side or user side
  • Identifying the countermeasures that ensure business continuity and the security of end users

IT and security management systems

From set-up to certification

  • Business Continuity Management Systems (BCMS) to ISO 22301
  • Service Management Systems (SMS) to ISO/IEC 20000
  • Information Security Management Systems (ISMS) to ISO/IEC 27001
  • Consulting on implementing management systems and support through certification
  • First-party (internal), second-party (subsidiaries and suppliers) and third-party audits (on behalf of a certification body)
  • Vulnerability assessments and penetration tests by multidisciplinary teams, in line with mandatory and voluntary standards

Experience

Selected IT governance projects

  • ISO/IEC 27001 risk assessment to set up an information security management system: avionics sector, 34 airport sites and 5 head offices
  • Information security policies and procedures to ISO/IEC 27001: avionics sector
  • ISO/IEC 27005 risk assessment for ISO/IEC 27001 recertification: service provider
  • Risk analysis of network infrastructure and security management services: local public administration
  • ISO/IEC 27001 management system set-up and certification: document archiving system

Training

Qualification courses on COBIT, ITIL, ISO/IEC 20000 and ISO/IEC 27001, from Foundation level to Lead Auditor, taught by trainers with hands-on consulting and audit experience.

Our training
Contact

Let's talk about your project.

An IT process to govern, a risk to assess, software to evolve, a team to train. Tell us what you need.

Write to us
Office
Via XX Settembre 41
16121 Genova
, Italy