IASME CYBER ASSURANCE
An alternative information assurance governance standard for SMEs
Although ISO27001 is the globally recognised benchmark for Information Governance, smaller organisations often find it challenging to get ISO27001 certified due to cost and effort involved.
The IASME (Information Assurance for Small and Medium Enterprises) Cyber Assurance standard aligns with the UK Government’s 10 steps to Cyber Security and includes additional Data Privacy controls. It provides smaller companies within a supply chain with a suitable and affordable method to demonstrate their level of information security.
IASME Cyber Assurance certification shows that you are taking the right steps to protect customer information. It includes an assessment of your General Data Protection Regulations (GDPR) compliance.
What are the benefits of IASME Cyber Assurance?
IASME Cyber Assurance demonstrates the integrity of your information security practices. A risk-based assurance, IASME looks at aspects such as physical security, staff awareness and data backup.
You can use IASME Cyber Assurance (also referred to as IASME Governance) as a stepping-stone to achieving the ISO 27001 at a later stage.
By engaging with us, you can rely on RightCue’s established methods to efficiently achieve the cyber assurance credentials. We provide you with all mandatory documentation and processes required by an IASME certification body.
What are the benefits of IASME Cyber Assurance?
IASME Cyber Assurance demonstrates the integrity of your information security practices. A risk-based assurance, IASME looks at aspects such as physical security, staff awareness and data backup.
You can use IASME Cyber Assurance (also referred to as IASME Governance) as a stepping-stone to achieving the ISO 27001 at a later stage.
By engaging with us, you can rely on RightCue’s established methods to efficiently achieve the cyber assurance credentials. We provide you with all mandatory documentation and processes required by an IASME certification body.
Our Expertise Includes:
Supply Chain Risk Management
Security Audits and Internal Audits
Knowledge of Industry Best Practices
Penetration Testing
Vulnerability & Cyber Threat Assessments
Global Data Privacy Regulations
Knowledge of Market Leading Security Tools
Knowledge of Major Cloud Platforms
Cyber Essentials & Cyber Essentials Plus
What makes us stand out?
“What I really like about the Right Cue team is their ability to distil complex and quite dry topics into accessible, easy to follow information. And that skill has enabled us to make sure all of our team are onboard and working the right way with data. Right Cue helped us to achieve our cyber security accreditations including Cyber Essentials and IASME. But it’s more than that – the protection and management of data is now very much at the centre of our business.”
Dan Curtis-Allen
European I.T. Director & GDPR Specialist, Frost & Sullivan
Our phased approach to implementation of IASME Cyber Assurance
If you choose to implement Cyber Assurance within your organisation, RightCue will work with you to define policies, establish industry best practices, embed risk management as a core of your security governance and management processes.
The standard covers 13 themes across 5 areas of control:
RightCue are experts in information assurance governance standards – and are here to help you get certified.
IASME Cyber Assurance: Level 1
The self-assessed IASME certification option requires you to complete an online questionnaire about the controls you have in place to govern information assurance.
Phase 1: Information gathering and risk assessment
We conduct workshops with heads of your functional areas to document information and personal data flows and convert these into asset registers, ensuring information security responsibilities are clearly defined. We also assist you with initial risk assessment, IT business continuity and disaster recovery plans.
Phase 2: Information Security Management System
We assist you with defining your information security and privacy management system by providing you with policies, procedures and other core documentation adapted specifically for your business and organisation culture. We assist you with implementing technical controls – at a minimum these include the controls required by the UK government’s Cyber Essentials Scheme as well as best practices to protect your key information and systems. We also work with you on change management to ensure a seamless transition to these new processes with as minimal disruption to your business and existing ways of working as possible.
At the end of phase 2, you will be ready to achieve self-certification to Cyber Essentials and IASME Cyber Assurance level 1.
IASME Cyber Assurance: Level 2
If you would like to move to the next step, we can provide an audit of your information governance to ensure the highest possible standards are achieved.
A third-party audit demonstrates to your customers and other stakeholders that your organisation’s security has been independently evaluated and verified by skilled experts, offering a similar level of assurance to ISO 27001.
Knowledge Hub
To find out more about how we work, ensuring cyber security compliance and data privacy, read our useful articles, guides and customer success stories: