GRC
GRC
We manage your security

GRC is a management model combining the functions of Corporate Governance, Risk Management and Regulatory Compliance, and it deploys them together to make them as effective and efficient as possible, thereby boosting the capacity of companies to address their challenges, maximise their opportunities, optimise their performance and achieve their business targets and bring about the success of the organisation.

At Áudea we help you implement this management model and improve your company’s security and organisation.

IMPLEMENTATION OF ISO 27001

We implement the ISO 27001 standard, a systematic process of policies, planning of activities, responsibilities, procedures, processes and resources focusing on minimising the risk associated with your company’s information assets. We analyse your company’s risks, and help you establish a Security Master Plan.

IMPLEMENTATION OF ISO 22301

We implement the ISO 22301 standard so that, in the event of an incident or a disaster at the organisation, you can continue to offer your services and continue production processes, and resume normal service within the shortest possible period of time. We help you draw up a Business Impact Analysis, and establish a Continuity and Contingency Plan.

PROTECTION OF CRITICAL INFRASTRUCTURES

We advise on establishment of the Operator Security Plan (OSP), which must be drawn up by each critical operator and regularly updated with the approval of the National Centre for Protection of Critical Infrastructures.

ADAPTATION TO THE NATIONAL SECURITY SYSTEM (ENS)

We help businesses comply with the National Security System by implementing regulations.

IMPLEMENTATION OF PCI-DSS

We implement and audit the standard for the payment card industry security (PCI-DSS) for the purposes of validation of compliance with the standard by the proper body, Qualified Security Assessors (QSAs).

GOVERNANCE

We ensure that both the activities of the organisation and management of IT operations are aligned to support the company’s business objectives.

ES-CIBER

We offer training for professionals in the ISO 27001, ISO 22301, PCI-DSS, ENS standards etc., and we also assist you with countless resources to generate a genuine culture of awareness among your employees.