Security Consultancy - Implementation
Zenzero's GRC Consultancy Team can assist in implementing strategies into effect through designing and building security controls for clients. This typically relates to establishing overarching control frameworks or documented information security practices (e.g., policies, processes, procedures, standards), including those related specifically to cloud security, helping secure accreditation where required.
Features
- Supports organisation security design and building of risk management controls
- Governance documentation development, including security policies, processes, procedures & standards
- Assists in accreditation to reputable information security standards including ISO/IEC27001
- Implementation programme design and activity delivery project governance
- Compliance universe creation identifying business legal, regulatory, or contractual obligations
- Alignment of appropriate cloud governance, risk management, and compliance controls
- Baselining, development, refinement, and coordination of security control implementation
- Cloud Security Alliance Cloud Controls Matrix, ISO27001, and Cyber Essentials
- Tailored implementation of controls to business requirements
- Management of Business Continuity, Operations, Identity/Access, Suppliers, Incidents, Personnel etc
Benefits
- External trusted advisors providing proven security consultancy to achieve objectives
- Clearer definition of organisational information security roles and responsibilities
- Internal and external responsibility mapping for improved governance and assurance
- Improved compliance with legal, regulatory, and contractual obligations
- Documented control sets across policy, process, procedure and standards
- Improved information security cohesion, internal, and external confidence in controls
- Linkage to risk-based standard control frameworks to secure cloud environments
- Visibility over all security domains and related protections
- Security integrated across business processes to enable improved operations
- Ability to monitor and review controls to improve efficacy
Pricing
£800 to £1,250 a unit a day
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
8 7 3 5 3 9 5 1 6 3 3 3 7 1 3
Contact
ZENZERO SOLUTIONS LIMITED
Adam Crossling
Telephone: 03333209900
Email: tenders@zenzero.co.uk
Planning
- Planning service
- Yes
- How the planning service works
-
All modern organisations require defined information security governance to support organisation objectives and outline their approach to risk management, particularly in relation to cloud security.
Zenzero's GRC Consultancy Team collaborate with Clients to plan the implementation of security controls, having assessed the organisations value proposition, compliance and threat landscape, and key functional (and non-functional) requirements. Control frameworks are also utilised to help select key security controls for implementation, which are then documented within relevant security governance documentation - as delivered by Zenzero. - Planning service works with specific services
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security incident management
- Security audit services
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- N/A
User support
- Email or online ticketing support
- No
- Phone support
- No
- Web chat support
- No
- Support levels
- N/A
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 28/09/2023
- What the ISO/IEC 27001 doesn’t cover
- All sites outside of London and Coventry.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- ISACA Certified Information Security Manager (CISM)
Social Value
- Social Value
-
Social Value
Fighting climate changeFighting climate change
Zenzero is actively engaged in Environmental, Social, and Governance (ESG) work, demonstrating a strong commitment to sustainability and ethical practices. They are in the final stages of being a certified B Corporation, which means they meet high standards of social and environmental performance, accountability, and transparency. As part of their ESG efforts, Zenzero has joined the Tech Zero taskforce, aligning with other tech companies to tackle the climate crisis and drive progress towards net zero carbon emissions. They have pledged to become carbon neutral by 2027 and are implementing measures such as an electric vehicle salary sacrifice scheme and cycle to work schemes to reduce their travel emissions.
Pricing
- Price
- £800 to £1,250 a unit a day
- Discount for educational organisations
- Yes