The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Proposal
We assess your environment against the Cloud Security Alliance cloud controls matrix, which is written for cloud and deals with how responsibility splits between you and your provider. That split is exactly where the gap lives: the provider looks after the security of the cloud, you look after security in the cloud, and almost every serious exposure starts with one side assuming the other had it covered.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
What is misconfigured today, and whose responsibility it is.
We assess your environment against the Cloud Security Alliance cloud controls matrix, which is written for cloud and deals with how responsibility splits between you and your provider. That split is exactly where the gap lives: the provider looks after the security of the cloud, you look after security in the cloud, and almost every serious exposure starts with one side assuming the other had it covered.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Report
The findings consolidated, with the route to fixing them.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.