NCSC Compliance Bahrain
Deverra is a leading Risk & Compliance service provider in Bahrain, helping companies achieve NCSC Compliance using National Risk Management Framework.
What is NCSC?
NCSC is the abbreviation for National Cyber Security Center is authorised by the Bahrain government and is responsible for improving national cyber security by protecting its information and communications infrastructure.
As part of this mandate, NCSC has developed Information Assurance (IA) standards to provide security compliance requirements for entities that support critical national services across all sectors to have a minimum level of security. Deverra’s team of NCSC compliance experts helps organizations comply with the regulatory requirements of NCSC with ease.
NCSC GAP Assessment
NCSC Risk Assessment
NCSC Risk Treatment Plan
NCSC Policies & Procedures
Security Testing
Security Awareness
Technology Implementations
NCSC Progress Reviews
NCSC Internal Audits
Phase 1 – Assessment
The first phase of a NCSC Compliance project is to assess the current state of compliance.Identify Critical Assets
- Project Initiation
- Understand the organization
- Identify critical business services
- Identify information infrastructure
Gap & Risk Assessment
- Assessment of current state and mapping it to NCSC Standard
- Identification of threats and vulnerabilities exploiting the gaps resulting in risk.
NCSC Controls Identification
- Identify cybersecurity controls that can mitigate the risks and thereby result in NCSC Compliance.
- Define NCSC Risk treatment plan
NCSC Compliance Reports
- Develop the NCSC compliance reports
Phase 2 – Control Development
This second phase of the project is to develop the controls to treat the risks identified. NCSC Risk Treatment Plan provides the directions for this phase of the implementation.
Policies & Procedures
Security Awareness
Technology Controls
- Security Architecture
- Technology gaps
- Configuration advisory
Management Controls
- Operational controls
- Physical Security
- Managerial Controls
Phase 3 – Security Services
This phase of the engagement supplements existing security practices in the organization. Some of the key service performed by Deverra team are:
Periodic Security Testing
- Vulnerability Assessments
- Penetration Testing
- Security configuration reviews
SIEM & Incident Response
- SIEM Solution deployment
- 24×7 Security Monitoring
- Security Device Management
Managed Network Security
- Next-Gen Firewalls, UTMs
- URL Filter, Web Security
- Wi-Fi Security
- VPN and remote access security
Data & Endpoint Security
- DLP Solutions
- Patch Management
- Endpoint security
- Mobile Device Management
Phase 4 – Compliance Review
Periodic review of the NCSC Compliance status is critical for the success of the Information Security Management System.
ISMS Performance Review
NCSC Internal Audits
Mock Compliance Audit
External Audit Support
Assist the customer during the compliance audit to meet the required NCSC requirements.
Would you like to speak to a security analyst?
We understand the importance of approaching each work integrally and believe in the power of simple.