Security certification services are used to provide assurance that products and services meet minimum standards of due care related to security programs and practices. These services include certification and attestation against voluntary or mandated standards and guidance, the most common of which are the: • International Organization for Standardization (ISO) 27001 • Payment Card Industry (PCI) Data Security Standard (DSS) • Health Information Trust Alliance (HITRUST) • Health Insurance Portability and Accountability Act (HIPAA) • Health Information Technology for Economic and Clinical Health (HITECH) • Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR) • System and Organization Control (SOC) 2
Security consulting firms are advisory and consulting services (see 'Definition: Cybersecurity' ) related to information and IT security design, evaluation and recommendations. These services are procured by various stakeholders in an organization, including boards of directors, CEOs, chief risk officers (CROs), chief information security officers (CISOs), chief information officers (CIOs), and other business and IT leaders for the purpose of obtaining and ensuring acceptable risk levels for a specific client organization.