Provided FCM Tools:
  • Source Database including 600+ searchable laws, frameworks and resources related to IT Regulatory Compliance
  • Enterprise Risk Management interface used to gather, review and map Risk to requirements, controls, assets and strategic milestones.
  • Assessment Portal used to identify 1000+ Standard Control Objectives including COSO, CobiT, NIST, ISO 27001, ITIL, PCI/VISA, BASEL II, and OCEG Framework.  Portal allows for selection of scope, maturity evaluation, mapping across multiple frameworks.
  • Policy Mapping Module allows review of all processes and policies, mapping their content to related areas of BS7799 Part 1 (27001) and accompanied by Statement of Applicability according to Annex 1.
  • Process Profile facilitates an ISO 9001 documentation framework and establishes baseline depiction for more than 200 standard processes.
  • System requirements are Microsoft Office 2003 or 2007, Visio Professional 2003 or 2007, Four Gig of Ram and 20 gig drive space.  It is also desirable to use an external drive of 250 gigs in size and this facilitates sharing the data with client and co-workers in optimal security.

Corporate organizations need objective benchmarks to measure and distinguish the quality of their own their security practices. While not perfect, most organizations respect and utilize some aspect of the evolved mapping of a combined ISO 27001 and CobiT 4.1 + CobiT 5 standard.  This hybrid and customized model provide a comprehensive catalog of topics that should be considered in designing, implementing, and operating a secure IT infrastructure.

The following sections provide images of tools and summary of the ISO/IEC domain areas.
  • Figure 1 Dynamic Process Documentation – Available on Intranet
  • Figure 2 Sample Process Profile – Meeting ISO 9001 standard
  • Figure 3 Change Management output showing all process and mapped controls
  • Figure 4 Risk Management Control Mapped Process Flow Diagram
  • Figure 5 Maturity Assessment tool – Tracking by CMM, CobiT or BASEL II assessment criteria
  • Figure 6 Interface allows for Mapping Policy and Control – set values from Policy Mapping Module
  • Figure 7 Policy Mapping tracks existing policy relative to ISO standard, related controls, owners and gaps
  • Figure 8 Application for Management and Reporting Enterprise Risk – Meets AS5 and OMB related requirements
  • Figure 9 Immediate High-Level Reporting – One of hundreds existing reports – Easily customized
  • Figure 10 Heat Map Shows Residual and Inherent Risk – Accounting Oversight Ready
  • Figure 11 Source Documentation shows Regulation and Standards – Instantaneous regulatory background reporting

clip image002

Figure 1 Sample output: Process Documentation and Controls Mapping - Dynamic Process Documentation – Available on Intranet

Figure 2 Sample Process Profile – Meeting ISO 9001 standard

Main Menu