Browse
Search
2023-653-E-AMS-CTCH Security Business Consulting-Facility Assessment
OrangeCountyNC
>
Board of County Commissioners
>
Contracts and Agreements
>
General Contracts and Agreements
>
2020's
>
2023
>
2023-653-E-AMS-CTCH Security Business Consulting-Facility Assessment
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
11/21/2023 10:21:23 AM
Creation date
11/21/2023 10:14:13 AM
Metadata
Fields
Template:
Contract
Date
11/7/2023
Contract Starting Date
11/7/2023
Contract Ending Date
11/11/2023
Contract Document Type
Contract
Amount
$30,832.00
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
99
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
View images
View plain text
<br /> <br />P a g e 11 <br /> <br /> <br />Orange County <br />Facilities Security Assessment <br />RFP#: 367-OC 5403 <br />CTCH Security Business Consulting – www.ctchconsulting.com <br />Security Risk Assessment Management Framework (SRAMF) <br /> <br />In an effort to identify the security risk levels associated with each site, physical <br />security vulnerabilities and site security flaws, the team will evaluate each site using the <br />following SRAMF methodology: <br /> <br /> <br />The first step in the SRAMF Model would be to identify security policies, <br />procedures and supporting documents that are in place throughout OC. The <br />documented policies and procedures will outline the existing security protocols, what <br />areas of security are currently covered under the policies/procedures and how security is <br />managed (through governance and response). All identified supporting documents will <br />help add context to the existing policy and procedures, will help identify documented <br />agreements and will help identify individual site infrastructures. <br /> <br />The next step in the SRAMF Model would be to identify what are the critical <br />assets areas associated with each site. Assets fall into two categories: tangible and <br />intangible assets. Tangible assets are those assets that stakeholders can label with a <br />dollar value (equipment, building areas, vehicles, etc.). Intangible assets are assets that <br />stakeholders cannot label with a dollar value (loss of life, business model, public <br />reputation, etc.). By ranking assets and conducting a Security Business Impact Analysis, <br />the team can begin to formulate the final Mitigation Matrix. The team will rank critical <br /> <br />DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB
The URL can be used to link to this page
Your browser does not support the video tag.