Information Security, Professional Services, Security Assessment
Cyber Security Assessments provide an effective way to determine the security posture of an organisation and identify areas for improvement through questionnaires, interviews and workshops against industry recognised security standards including ISO 27001 & 2, NIST, CIS Top 20 and the ISF Standard of Good Practice.
Features
- Benchmark organisation’s information security posture against industry recognised standards.
- Recommend areas for security improvement aligned to organisational objectives
- Provide a high level prioritised action plan to realise improvements.
- Engage with key stakeholders through questionnaires, interviews and workshops
- Support clients to develop more security aware culture and practices
- Opportunity to combine assessment process with penetration testing service
- SC and DV cleared staff to deliver outcomes if required
Benefits
- Capture and understanding of security posture through detailed report
- 2. Executive view of key findings and recommendations
- Better understanding of risks and vulnerabilities affecting information security
- Cost benefits of removing insecure or duplicated security processes
- Engagement of key stakeholders to ensure awareness and buy-in
- Recommendations and prioritised roadmap for security improvement
- Solutions joining technical and business process relating to cyber
- Produce outcomes through collaboration rather than templated solutions
- Experience of providing advisory support across all cyber domains
- Expertise to articulate risks to all levels of audience
Pricing
£1,100 a unit a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
7 5 5 1 8 9 3 8 1 8 8 5 2 8 8
Contact
SOPRA STERIA LIMITED
Sector Support
Telephone: 0370 600 4466
Email: sector-support@soprasteria.com
Planning
- Planning service
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security incident management
- Security audit services
- Certified security testers
- Yes
- Security testing certifications
-
- CREST
- Cyber Scheme
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- There are no service constraints to detail here. Any constraints would be discussed once requirements were fully understood.
User support
- Email or online ticketing support
- No
- Phone support
- No
- Web chat support
- No
- Support levels
- A Security Lead will be allocated for each engagement to provide a point of contact and escalation path for any questions or issues that arise during the service. The Security Lead will be contactable during UK business hours via email and telephone.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- DNV Business Assurance
- ISO/IEC 27001 accreditation date
- Date of last re-certification: 01 December 2023
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
Fighting climate change
Sopra Steria has committed to becoming Net Zero by 2028 and has been ranked in the top 1% of companies globally by CDP placing us on the A-list for our work tackling climate change over the past 5 years.
Our work has a direct positive impact on our client’s services, for example through lower emissions, reduced waste, and more sustainable supply chains.
Additional environmental benefits: We also provide contract-specific sustainability programmes for clients, which are designed & deployed by our team of Sustainability Consultants. During procurement, these experts will develop a sustainability programme based on a clients objectives, the material impacts, and opportunities within the service.
We have experience in…
• Undertaking service environmental impact assessments
• Measuring energy consumption, and emissions generated, required to deliver a particular service (e.g., office use, business travel, use of technology and supply chain)
• Evaluating the sustainability of technology products (e.g., GGICT, Energy Star, as well as product and service foot printing)
• Making business case-backed recommendations, implementation roadmaps for improvements
• Delivering improvement programmes
• Reporting performance, using recognised reporting standards, accounting methods
Influencing staff, suppliers, customers and communities: regarding our staff, we feature sustainability in our employee communications, and offer all employees paid volunteering time which can be used to support sustainability activities, such as beach cleans and climate hackathons.Covid-19 recovery
Employment, re-training and other opportunities: In the high-growth Digital sector, Sopra Steria is continually developing the skills of our workforce, including via upskilling and reskilling initiatives, e.g. via a new Career Coach, or by extending our apprenticeship programme.Through our ‘Tech for Good’ programme, and the various Social Value programmes we design and deliver for our customers, we focus on jobs and skills for disadvantaged and under-represented groups, including those disproportionately affected by Covid.
People and communities: Our ‘Tech for Good’ programme is designed to provide people, small businesses and VCSEs with skills they need to thrive and is focused on those from disadvantaged or under-represented communities. Since the beginning of the pandemic, we have transitioned to a hybrid-virtual programme to ensure continued accessibility. For example, we worked with ELATT, a digital skills charity, to create hybrid learning, ensuring those who were shielding or otherwise unable to access classroom learning, as well as those who most needed to be in a classroom to support their learning, could still participate.
Organisations and businesses: In the first year of the pandemic, we ran free training courses for charities and SME’s – offering Microsoft Teams training and modules on cyber security and resilience. We continue to offer pro-bono consulting for charities to help them use technology to better serve their communities.
Physical and mental health needs: Since the pandemic, we have put in place measures to prevent and manage risks to employee wellbeing – including the wellbeing of contracted staff – together with appropriate training and individual support, and initiatives to raise awareness of mental health issues at work. We have also trained ca. 60 Mental Health First Aiders.
Workplace conditions: All our office locations have strict Covid safety protocols, with considerations for cleaning, ventilation, and occupancy.
Pricing
- Price
- £1,100 a unit a day
- Discount for educational organisations
- No