|
Sph3r3, LLC. consults with both governmental and commercial sectors including a multi-client base of corporations, public utilities, financial institutions and healthcare organizations. Sph3r3 provides assistance and architectural support for many information security projects including integrating compliance requirements associated with SOX, HIPAA and the NERC CIP standard. Recent projects include architecting and integrating protective controls for financial market transactions, virtualized environments and SCADA systems. Please peruse our consultation offerings. If you have any further questions that need to be addressed or if you are interested in engaging Sph3r3 as a business partner, please contact us.
System Architecture System architecture covers a complex set of activities which enable the customer to procure the most efficient way of using information sources, linking them to work procedures and developing & implementing applications as well as to secure failure-free operation of IT infrastructure, data backup, recovery & protection against misuse or damage. As an integral part, system integration activities involve design of the entire application solution, suggestions regarding the potential of further system development, operation support and IS/IT maintenance and upgrades. The system architecture composes the framework for a robust application delivery environment. System Integration Sph3r3 provides expert implementation of particular subsystems of the customer's complex information system including its plans and procedures, pilot testing, tuning hardware performance, software installation, database optimization and users training. IT Project Management Sph3r3 project managers ensure that the resources allocated to a project are used in an effective and efficient manner. Project managers follow a well-defined approach that helps identify key risk that threaten the success of a project as early as possible and help to mitigate those risks to eliminate or greatly reduce their impact on the engagement. Project managers, effectively facilitate communication with the team members participating in the engagement with senior executives responsible for ensuring that the client’s budget helps drive business results. Network Management Most organizations utilize some form or subset of network management software; however a majority of them also do not adequately understand what exactly is occurring within their architecture environment. Sph3r3 has devised several solutions utilizing both commercial and GPL open source software to automate incident notification and event identification as well as provide proactive mechanisms to identify potential issues prior to them becoming severe or even occurring. Infrastructure Design Design solutions must be tailored for the company for which it is to be implemented within. Some situations may require high availability and security, while others may need access to bleeding edge technologies. Regardless of the application and environment all designs must leave adequate room for growth and must be able to leverage a majority of the existing components. In some instances new technologies may require a complete infrastructure overhaul; however this process can be implemented in phases so that the company does not have a disastrous financial implication. Sph3r3 provides complete infrastructure designs to meet your digital enterprise’s requirements. Architecture Inspection Information architecture inspection is performed to verify infrastructure devices (servers, workstations, firewall(s), routers, etc.) are running the appropriate software revisions and architected to provide optimal application performance. Critical software components are manually inspected for implementation details and the findings are provided in an audit report. We specialize in Cisco Systems, Microsoft, Checkpoint, Sun Microsystems, Linux and several Open Source products. IT Education / Writing Sph3r3, LLC. constantly maintains its high proficiency rating by employing individuals that can convey solutions to our customers not only through professional technical design, but also in conjunction with expert analysis and documentation. In doing so, our consultants continue to speak, author and technical edit manuals and design guides for DePaul University, InfoSec, NetSec, the SANS Institute, Sybex Corporation, Cisco Press, MacMillan Publishing, Global Knowledge and Que Publishing. IT Policies An information system policy maintains several facets of an organizations documented digital founding principles. Sph3r3 provides guidance in development and review of your existing written and informal policies, including Disaster Recovery, Acceptable Use, Privacy, System Protection, Change Management, Baseline System Architecture, Critical System Definitions and Incident Response. Mobile Systems The demand and available technologies for computing mobility continues to expand at an unprecedented rate. This highly fluctuating environment has created, and continues to create an undirected, volatile workforce that is not effectively using the technology that is at our disposal. Information Technology must guide mobile knowledge workers in the correct direction based upon their functional business requirements. These business requirements are much more stable in nature and can be referenced throughout the IT life cycle to provide adequate growth and evolution. We are calling this relationship, outside-in thinking. Sph3r3 provides consultation services to help develop and integrate your mobile strategy for the immediate solution and for future goals. Security Components Security is often addressed as three main requirements: Confidentiality, Integrity, and Availability. It is the breakdown of these requirements that leads to problems requiring resolution. Loss of confidentiality may result in corporate espionage, embarrassment, or potentially destroyed credibility. Loss of integrity may cause the organization to lose control over its business processes and data warehouses. Loss of availability may limit the organization's ability to perform its business in a timely manner. Digital Forensic Computer forensics can be a very painstaking task involving hours of attempting to identify the cause and extent of malicious activity. Sph3r3 provides low-level end system analysis coupled with netflow data [if available]. Immediate and concise inspection can sometimes provide near identical reconstruction of the events which transpired and help to identify the extent of the theft and potential remediation techniques. There is never a guarantee that all data will be recovered and the means of which entry was gained can be identified, this is generally related to the class of the intrusion and the availability of key data. For example, with netflow data one can identify near real-time and historically the exact traffic flows that have operated on an infrastructure. This data can be used to verify threats, historically track an attack and to verify potential outsider liability. Netflow data can be obtained from most infrastructure devices and can utilize open source software. |