Security certification services are used to provide assurance that products and services meet minimum standards of due care related to security programs and practices. These services include certification and attestation against voluntary or mandated standards and guidance, the most common of which are the: • International Organization for Standardization (ISO) 27001 • Payment Card Industry (PCI) Data Security Standard (DSS) • Health Information Trust Alliance (HITRUST) • Health Insurance Portability and Accountability Act (HIPAA) • Health Information Technology for Economic and Clinical Health (HITECH) • Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR) • System and Organization Control (SOC) 2
Risk management is a continuous and integrated process that supports and informs the creation of an entity's overall business strategy. It provides a mechanism for ensuring that important business processes and behaviors remain within the entity's overall risk appetite and adhere to the relevant policies, procedures, laws and regulations. The RM process is a strategic and holistic treatment of all strategic, operational, financial reporting, and legal/compliance risks, including the IT and information management components of those risks. Gartner defines risk management (RM) consulting services as the bundle of expert-driven consulting services directed at helping enterprises mitigate the impact of uncertainty on business performance. Management consulting firms offer a variety of RM services