CGFby i-Prot
- 01Assesscontext, assets, risks
- 02Prioritize
- 03Design
- 04Implement
- 05Operate & measure
- 06Improve
Problems
Start with the business problem, not the standard.
01«I don’t know my real level of exposure»Cybersecurity governance →02«I need to comply or certify without creating bureaucracy»Compliance & ISMS →03«I have scattered risks and decisions that aren’t traceable»Risk management →04«I lack continuous detection and response capacity»CyberSOC →05«I need senior leadership without adding a full-time role»CISO as a Service →
CGF cycle
One governance cycle. Six connected stages.
CGF doesn’t start by asking which standard must be met, but what the organization needs to protect, which risks to reduce and which capabilities to govern.
01
Assess
context, assets, risks
02
Prioritize
impact, exposure, value
03
Design
controls, processes, governance
04
Implement
plans, evidence, adoption
05
Operate & measure
services, indicators, response
06
Improve
review, audit, evolution
Solutions
Organized by business problem, executed end to end.
Compliance & ISMS
Implementation and upkeep of the management system, focused on certification.
Risk management & BIA
Identification, assessment and treatment of risks with impact analysis.
CyberSOC & response
Managed detection, monitoring and incident response.
Vulnerabilities & pentesting
Continuous discovery and offensive validation of the attack surface.
CISO & governance
Security leadership and board reporting, as a service.
Cloud security & infrastructure
Secure architecture and protection of cloud and hybrid environments.
Integrated view
From assets to decisions — a traceable chain.
Assets
Risks
Controls
Operations
Evidence
Indicators
DecisionsComplyze · a platform by i-Prot
Continuous governance and compliance with Complyze
Complyze centralizes frameworks, assets, risks, controls, action plans, evidence, audits and indicators in a single platform.
Discover Complyze →Compliance status
demo · sample dataISO/IEC 2700172%
SOC 258%
ISO 2230141%
Frameworks
The standards and frameworks we work with.
The eleven frameworks we work with, each with its own page.
Managed services
Capabilities operated, day after day.
CyberSOCContinuous monitoring and response. →CISO as a ServiceLeadership and board reporting. →
Vulnerability management
Discovery and remediation cycle.
ISMS management
Upkeep of the management system.
NOC
Network operation and availability.
CMDB & Service Management
Inventory and service management.
Security infrastructure
Technology deployment and operation.
Why i-Prot
Governance before technology. Results before noise.
Our own framework: CGF
A governance methodology developed by i-Prot that orders the work end to end.
24×7 operation
Managed services that sustain security continuously.
Multiframework
We treat standards as sources of requirements, not as ends in themselves.
Cases
Anonymized examples of how we work.
Path to ISMS certification
Design and implementation of the management system at a regional bank.
CyberSOC for a product company
Managed 24×7 detection and response operation.
Risk management and continuity
Impact analysis and continuity plan at a public agency.
Resources
Perspective on governance, risk and compliance.
Where to start a cybersecurity governance program
Preparing for an ISO/IEC 27001:2022 audit
Measuring maturity: from controls to decisions
Know your exposure level and define the next step.
An initial diagnostic session to map risks, priorities and next actions.
Request initial diagnostic