Strategic Security Corp. A Risk Management Company. Home | Mission | Clients | Media
Information Technology Services.

Information Technology Services

Strategic Security Corp specializes in the following Risk Mitigation & Crisis Management Consulting Services:
Ethical Hacking
SSC's team of experienced IT professionals are trained across all disciplines - audit, legal, management, operations and security and specialize in the architecture, design and implementation of broad based e-commerce systems.

SSC delivers consulting services and integrated delivery systems, to minimize the threats to its clients' information systems and communication network. Clients are assisted in all phases of applications, including evaluations of security products and vendors, application design and implementation and continuing assistance in monitoring, administering and responding to problems in the operation of sites.

SSC determines categories of threats and risks to the critical systems, services and information resources of clients and recommend cost-effective countermeasures. In the event of misconduct, SSC is able to strategically respond with forensic investigation and insight.

Penetration Testing
Where catastrophes have previously occurred as a result of failure to deal with an initial crisis, Business Continuity Planning (BCP) offers a unique solution. BCP is the process of creating, testing, and maintaining an organization-wide plan to recover from any form of disaster. Every BCP strategy employed by SSC includes three fundamental components: risk assessment, contingency planning, and the actual disaster recovery process. BCP should encompass every type of business interruption - from the slightest two-second power outage or spike up to the worst possible natural disaster or terrorist attack.
 
Forensic Analysis
Physical Security and Vulnerability Assessments are systematic examinations of building elements, facilities, population groups or components of the economy to identify features that are susceptible to damage from the effects of natural, civil or technological hazard. SSC consultants will surpass client's expectations through a process of continuous innovation and by providing the highest quality service and personnel.
 
Disaster Recovery
SSC's design team leaders are knowledgeable in many disciplines to assist in developing multiple technology integrated security systems and incorporating crime prevention though architectural design.

Retrofitting a facility is extremely costly. Including security in the design phase of construction can provide a substantial return on your investment (ROI).

Security Risk Assessments
Many industries, and particularly financial services firms, are required to comply with information security regulations such as the Gramm-Leach-Bliley Act and other FFIEC regulations. SSC has developed a comprehensive Information Security review focusing on:
  • Physical Security
  • Access/Data/File Controls
  • Environmental Controls
  • Communications/Network Considerations
  • Personnel Considerations
  • Computer Usage
  • PBX & Voice Mail
  • Hardware Considerations
  • Contingency Planning
  • Software Considerations
  • Ancillary Applications
  • Social Engineering
  • Fedline
  • Penetration Testing (Additional)
In addition, we document existing information system controls, identify and document network devices and points of access to information (including modems and wireless connections), run a system vulnerability scan of all devices, and evaluate your financial institution's overall information security posture.

We use the collected information to produce an Information Security Review of your firm's information systems, along with a list of observations and recommended action items.

Cybercrime
SSC's Computer Crime and Intellectual Property Section (CCIPS) is responsible for implementing the strategies in combating computer and intellectual property crimes worldwide. SSC's Computer Crime Initiative is a comprehensive program designed to combat electronic penetrations, data thefts, and cyberattacks on critical information systems. CCIPS prevents, investigates, and prosecutes computer crimes by working with other government agencies, the private sector, academic institutions, and foreign counterparts. SSC works with attorneys to improve the domestic and international infrastructure-legal, technological, and operational-to pursue network criminals most effectively. CCIPS's enforcement responsibilities against intellectual property crimes are similarly multi-faceted. Intellectual Property (IP) has become one of the principal U.S. economic engines, and the nation is a target of choice for thieves of material protected by copyright, trademark, or trade-secret designation. In pursuing all these goals, CCIPS regularly run complex investigations, resolve unique legal and investigative issues raised by emerging computer and telecommunications technologies; litigate cases; provide litigation support to other prosecutors; train federal, state, and local law enforcement personnel; comment on and propose legislation; and initiate and participate in international efforts to combat computer and intellectual property crime.
 
Computer Security Architecture & Design
To be efficient and effective, facilities for authentication, protection of sensitive data, etc., must be designed in from the start and SSC IS specialists can help. Every major building block in the system should have a defined security goal, or a statement that no security is required. Doing security "later" is always more expensive - in the worst case, resulting in serious loss that triggers a security retrofit.
 
Computer Security Architecture & Design
Whether it is GLBA or the BSA compliance, SSC specializes in computer related compliance issues and in designing an Information Technology Risk Management Program (IT-RMP) and in PCI Data Security Standard Compliance. The Standard is a set of 12 data-security regulations that is designed to safeguard debit- and credit-card payment transactions through the use of firewalls, encrypted transmissions of cardholder data, and anti-virus software. Payment Card Industry Data Security Standard, a set of security requirements for merchants and payment processors that includes implementing strong access-control measures, regularly monitoring and testing networks, and maintaining an information security policy (ATM user plane, control plane and management flow).