Without a doubt since the turn of the century there has been a fundamental shift in the way companies do business and this trend will continue in the coming years. There is a need to be ready for new technologies, new systems and new business solutions in a changing world. Helping organizations come to grips with these challenges is what Bankshire does best.
Bankshire is proud to offer the following PKI services:
Policy development
The acquisition and use of any security products or technology should be driven by appropriate policies. This is even more important in the PKI world as its use is becoming prevalent throughout various levels of government and the private sector in Canada, North America and the world at large. It is quite important that policies be adopted that will allow cross-certification between various bodies while giving the security that each organization requires. Security policy and acceptable use statements detail the responsibilities and acceptable behavior for all system users.
Bankshire’s services entail the following:
- Determine current and future PKI security requirements,
- Evaluate current security policies and practices, and
- Develop a PKI information security policy for the organization.
Areas that will be covered include data categorization, roles and responsibilities, network and system access controls, confidentiality and integrity, intrusion detection, and incident response handling.
Application Security Review
This service is oriented towards organizations that are in the early stages of investigating the use of PKI for business applications and require business-oriented consulting to select the optimal approach. It provides an introduction to the issues and benefits of encryption, authentication and integrity services and develops a high-level action plan for moving forward.
The first step in assuring the successful deployment of a PKI is a security requirements analysis and development of a high-level planning architecture. An Application Security Review maps business requirements to information technology system, software, networking and messaging requirements, and determines the best use of a PKI and other security technologies for providing the required security services.
The end report provides the following to the client:
- Definition of requirements, assumptions and constraints
- High-level architecture for PKI deployment, including preliminary sizing estimates
- Recommendations for other security products and technologies that are required to meet the requirements, such as firewalls, intrusion detection, etc.
- Development of a business case showing the return on investment in a PKI
- Copies of white papers, policy development, operational issues, etc.
The report provides an action plan for acquiring, deploying and operating the Public-Key Infrastructure.