logo buildings
RGW Associates LLC is a member of ISACA and IIA

News & Events

Mass General Law c 93H 201 CMR 17.00
Download a copy of the law here and the checklist put out by the Commonwealth of Massachusetts here
Subscribe to RGW Associates' Blog covering IT Governance and Risk issues RGW Blog Feed

Services


IT Governance
Risk Assessment and Gap Analysis
Unified Vulnerability Management
Web Consulting
Technology Needs Analysis

IT Governance

RGW Associates LLC is a recognized name in providing organizations and government agencies comprehensive compliance and IT governance solutions. Through the use of our �Best Fit� purpose-built process, RGW Associates is able to deliver a high value, customized framework that fits the requirements of our customer. Following strict guidelines set forth by industry recognized Risk and Governance standards, RGW Associates implements solutions according to the National Institute of Standards and Technology (NIST), (specifically Special Publication (SP) 800-30, SP 800-27 and SP 800-14) as well as CobIT (CobIT 4.1) and other directives issued by the IT Governance Institute. RGW Associates is an active member of ISACA and therefore is bound by all principals, standards and guidelines and the Code of Ethics set forth by that organization.
Back to Top


Risk Assessment and Gap Analysis text

RGW Associates LLC categorizes a risk assessment into three (3) major components. RGW Associates classifies these as follows:

Administrative Safeguards

These include, but are not limited to, those control measures that ensure:
o classification of data handled by the unit and determination of controls to protect those assets;
o documentation of procedures, standards, and recommended practices to ensure that applicable policies and controls are implemented appropriately for a given business process;
o identification of personnel who are authorized to access systems;
o assurance that appropriate authorization controls are implemented;
o security awareness training and education for all personnel; and
o background checks prior to the selection and hiring of new personnel into critical positions.

Logical Safeguards
These encompass the range of technical controls that:

o ensure access by only authorized users and session termination when finished;
o enforce secure password management;
o manage tracking of development, maintenance, and changes to application software and information systems;
o manage access to the network;
o ensure event logging;


Physical Safeguards
These protect physical resources through controls that:
o allow access by only authorized individuals, through the use of physical means, such as locks, badge readers, or access cards;
o ensure the prevention, detection, early warning of and recovery from emergency disruptions, such as flooding, power failures, or earthquakes
o govern the receipt and removal of hardware and electronic media, including equipment reassignment, and final disposition of equipment

Back to Top


Unified Vulnerability Management text

With our partnership with Rapid7 (a leading Vulnerability Management Specialist), RGW Associates is in a unique position to perform every type of vulnerability test available using state of the art technology

Back to Top


Web Consulting

The RGW Associates team understands that sales drives profits. We provide web design services for layout, design and hosting advice to site integration and custom web application development. Your needs dictate the solution that best fits our web design recommendations.


Back to Top


Technology Needs Analysis

The RGW Associates team members have over sixty year of combined experience in technology services. Whether your needs are departmental or enterprise in scale, RGW is able to provide the direction and solutions needed to provide cost effective solutions.


Back to Top

   
Copyright © 2009 RGW Associates LLC. All Rights Reserved.