|
Modulo Risk Manager™ enables the management of risks and evaluates the compliance with industrial standards and regulations by implementing CiSACS methodologies, industrial standards, and knowledg bases.
This consists of mapping organization’s assets, business processes and threats. The inventory structure is easily implemented by defining organizational, physical or process perimeters, as well as using tools that automate the entire activity.
Supported by a knowledge base that is constantly updated by a MSLAB research team, Module Risk Manager™ helps perform risk analysis of several kinds of assets. The analysis can be automated by using automatic data collectors, manual data collection, and through Web and off-line based questionnaires. There are more than 4,000 automated collectors for distinct types of assets that are distributed in several knowledge bases, comprising more than 11,000 controls. With the integration of CiSACS processes and methodologies, Module Risk Manager™ can analyze risk from both a controls perspective, examining existing or missing controls, as well as a vulnerability perspective, targeting actual known vulnerabilities. 3rd party data such as Nessus and Bandolier can also be integrated into Module Risk Manager's analysis.
Each resource is identified according to its relevance to the business. Risk evaluation is performed by generating objective and practical reports, with executive, tactical and operational views. These reports can be presented in different views such by assets type, perimeters, business processes and threats. This enables the verification of which assets or business processes run higher risks. Through a specific module, risks can be classified as acceptable or targeted for treatment.
Risk treatment is performed by observing recommendations and best practices. Through a web module, it is possible to asign tasks to your staff and manage the controls implementation process.
Module Risk Manager™ provides an objective methodology that offers qualitative and quantitative results that can effectively prioritize actions and support decision-making.
|