Aphari Information Assurance and Security Capability Set-up
Aphari helps organisations transform their digital/technology operating model, adopt cloud services, establish system and service integration capabilities, and manage multi-supplier delivery. Our Information Assurance capability setup service helps clients adapt their information assurance, risk management and security architecture approach to support transformation/migration to cloud services sourced from multiiple suppliers.
Features
- Defines Information Security and risk management approach for cloud/multi-supplier environment.
- Framework enables end to end management of Information Security risks.
- Defines the Information Security obligations of in-house and external providers.
- Helps determine security controls to be delivered by different suppliers.
- Establishes common approach to risk management and accreditation across suppliers.
- Holistic approach across security and interrelated functions.
- Integrates security activities with the operating model and delivery lifecycle.
- Approach based on pragmatic application of public-domain best practices.
- Framework includes MSP, PRINCE, COBIT, TOGAF, HMG Security Policy, ITIL.
- Can combine with other Aphari services including Set-up, Health Checks
Benefits
- Helps organisations transform their digital/technology operating model and supply chain.
- Helps clients build in-house capability needed to manage cloud/multi-supplier delivery.
- Mitigates specific information risk management challenges arising from cloud/multi-vendor models.
- Provides approach for maintaining information security compliance throughout the transformation.
- Minimises overheads of managing security compliance activities in large programmes.
- Highlights cross-functional inter relationships and lays foundations for structured collaboration.
- Helps minimise delay costs arising from unforseen information security risks.
- No lock-in to proprietary or 'branded' methodologies.
- Our experienced team speaks to stakeholders in their own language.
- Aphari services based on extensive public sector Information Security experience.
Pricing
£350 to £1,650 a unit a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
2 6 9 1 8 2 3 4 0 7 1 4 5 6 1
Contact
Aphari Ltd
Andrea Williams
Telephone: 07734 723044
Email: enquiries@aphari.com
Planning
- Planning service
- Yes
- How the planning service works
-
Our Information Assurance and Security Capability Setup service helps clients adapt their information assurance, security architecture and security risk management approach to support transformation/cloud adoption and multi-source programmes.
As part of this service, we provide assistance with the following aspects:
• Definition of Information Assurance and risk management approach for the cloud services and multi-supplier environment, enabling end to end management of Information Security risks.
• Definition of the Information Security obligations of each supplier.
• Determination of the security controls to be delivered by different suppliers.
• Establishing a common approach to risk management and accreditation across suppliers.
• Ensuring a holistic approach across security and interrelated functions.
• Integration of security activities with the operating model and delivery lifecycle.
Ambiguities regarding security policies and accountabilities between different suppliers can result in delays or significant risk decisions being required, coupled with significant increases in costs and/or risk exposures. An effective Information Assurance and Security regime can mitigate significant risks to the programme success and protect the programme business case. - Planning service works with specific services
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
-
As with all our Setup Services, our Information Assurance and Security Capability Setup Service can help buyers in the migration and setup stages of their transformation/cloud migration programmes, by ensuring the programme is setup for success, doing the right things in the right ways and able to support the achievability of the business case.
Each setup service is focussed on setting up the specific capabilities needed to succesfully deliver a transformation/cloud migration programme. Whilst these are focussed on the planning stage of a transformation/cloud migration programme, each setup service and can be used during the sourcing and delivery stages of the programme to address gaps or weaknesses in the programme capabilities. - Setup or migration service is for specific cloud services
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- We aim to respond to all queries regarding our services within 1 business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
- Our support and account management arrangements for all our services includes the following: establishment of clear and agreed reporting lines; pairing our engagement lead with the appropriate client stakeholder; formal and regular reporting of our services provided. All our services are subject to a standard set of internal and customer-facing quality checks. Our directors take an active role in assurance and delivery of our services which ensures that we understand how we are performing against your requirements; and provides an escalation route in case any issues are encountered with our service provision.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Security Clearance (SC)
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Our services help clients to achieve their transformation/cloud migration programmes more quickly. By adopting cloud services, our clients will typically be enabling energy-hungry and under-utilised legacy systems to be decommissioned, and so reduce the need for associated on-premise cooling systems. The transition to cloud services typically moves computing workloads to more efficient, higher utilised systems, hosted in modern facilities with reduced cooling requirements. Delivery of cloud migration programmes therefore delivers significant overall reduction in energy consumption. Our services help clients to deliver these benefits more quickly and with more certainty.
In addition, subject to client preferences, the majority of our services can be delivered remotely, significantly reducing the need for our team to travel to our client's premises, and the associated carbon footprint.Covid-19 recovery
Our services help clients to achieve their transformation/cloud migration programmes more quickly. In adopting cloud services, and moving applications and data from on-premise legacy systems to cloud-hosted solutions, our clients will typically be enabling these to be 'accessed from anywhere on any device'. By helping our clients to deliver such changes in a more timely and reliable fashion, we are enabling them to better support a wider variety of working styles including flexible working and remote working. These in turn have been shown to provide significant benefits to staff who are responding to the impact of the Covid pandemic on themselves and their teams.
Our own team is fully enabled to work flexibly and remotely, and a number of our consultants work part-time. We have the ability to flex workloads between our consultants as needed to adapt to the different constraints that have arisen during the pandemic. This is coupled with a strong ethos of collaborative working, which helps us support each other and our clients. Through our first-hand experiences of flexible working, we are able to provide real-world advice and guidance to clients who are making changes to their ways of working.Tackling economic inequality
Our services support innovation and adoption of new technologies, improved productivity, and better supply-chain relationships. As an independent consultancy, we have no ties to particular vendors or service providers. This means we are able to assess new service providers, new services and new technologies objectively and provide candid advise on the benefits and risks of their adoption. Furthermore, in bringing our 'supply-side' delivery expertise to our clients, and helping them to more clearly define their programme objectives, requirements, 'to-be' architectures and delivery management processes, we typically help to establish improved communications and relationships throughout the supply-chain.Equal opportunity
Our services help clients to achieve their transformation/cloud migration programmes more quickly. As part of our ethos, we take special care to ensure that end-users are not unfairly disadvantaged by the changes in technology which we help to deliver. As part of this we can provide support and guidance to our clients on ways to manage the impact of the programme upon the workforce, and to take into consideration those with particular needs. This may often include assistance with meeting occupational health requirements, management of technical issues related to maintaining or adding support for specialist end-user IT equipment, assistance and advice regarding individual training/skills enhancement needs, and support for wide scale training needs analysis. In all such matters, our service are provided in full support of the client's diversity and equality policies.Wellbeing
Our services help clients to achieve their transformation/cloud migration programmes more quickly. However, we understand that technology change programmes have a human aspect. An ill-defined, over-ambitious, or poorly-executed change programme can cause significant wellbeing issues, often arising from conflict and stress - both within and between teams. We believe that clear definition of programme objectives, requirements, solutions and delivery plan, coupled with senior stakeholder support, effective governance, and open communications, all help to orientate the project teams and supply-chain towards common and achievable goals. In turn, this fosters collaborative and supportive working relationships; which help the project teams and end-user community through the change lifecycle.
Pricing
- Price
- £350 to £1,650 a unit a day
- Discount for educational organisations
- No