Critical Infrastructure Protection
USSC provides consulting services in several fields related to Critical Infrastructure Protection:
- Critical Infrastructure (CI) requirements:
- CI identification and relevance estimation for Customer infrastructure.
- Internal Customer categorization committee consulting.
- CI objects categorization:
- Business level CI object categorization (enterprise IT systems and business-level telecom networks).
- Production line level CI object categorization (Industrial Control Systems and factory networks).
- Complex CI object categorization (enterprise IT systems, business-level telecom networks, Industrial Control Systems and factory networks).
- Existing IT Security system audit:
- Compliance audit for state and enterprise requirements & regulations.
- Technical audit including asset discovery and identification, penetration tests, incident analysis, threat assessment and security strategy development.
- Critical Infrastructure Security measures design and implementation:
- CI object assessments.
- Threat and attacker model development.
- Requirements specification development in accordance with global standards and best practices.
- Organizational documentation development for significant and insignificant CI object types.
- Project documentation development required for proper system design and implementation.
- Complex CI security solution design and implementation.
- Security measures deployment, acceptance and sign-off.
- Service support, incl. maintenance and technical support for deployed CI object security measures.
- CI Security management automatization.
