Meet audit and regulatory
In a growing digital environment, we are always aware of the validity of laws and regulations that seek to promote data protection and the security of business activities.
At the same time, various sets of good security and privacy practices have emerged, designed to provide effective tools to mitigate new threats that accompany rapid technological advancement.
Given this complex reality, DM11® offers its expertise to assist your business in facing this challenge. This includes support in compliance with major laws and current regulations, as well as preparation to adopt the most suitable guidelines related to information security, data protection and cybersecurity.
DM11® is your partner in developing strategies that strengthen posture and adequacy in the face of these requirements, allowing your company to prosper with confidence in the rapid technological transformations.
ISO
International Organization for Standardization is a non -governmental organization that develops and publishes technical standards that are designed to standardize processes, products and services in various industries and fields, with the objective of ensuring quality, safety, efficiency and interoperability. Compliance with its ISO standards is seen as a demonstration of commitment to excellence and continuous improvement in a given area.
-
27.001
-
27.002
-
27.003
-
27.004
-
27.005
-
27.014
-
27.301
-
27.701
-
31.000
-
38.500
-
20.000
International standard that establishes requirements for an Information Security Management System (ISMS) and provides recommended guidelines and practices to help organizations establish, implement, maintain and improve information security within their structures.
ISO
27.001
Supplier audit service
We structure its processes for the care of information security audit required by financial institutions as well as other partner entities and/or suppliers rights or through external auditors such as:
Bacen - Central Bank of Brazil
CMN RESOLUTION No. 4,893 /2021
Resolution that provides for the cyber security policy and the requirements for hiring data processing and storage services and cloud computing to be observed by authorized institutions to operate by the Central Bank of Brazil (BCB).
BCB RESOLUTION No. 85 / 2021
Provides for the cyber security policy and the requirements for hiring data processing and storage services and cloud computing to be observed by the payment institutions authorized to operate by the Central Bank of Brazil (BCB).
Payment Card Industry - Data Security Standard (PCI DSS)
Talk to an expertSystem and Organization Controls (SOC) 2
Talk to an expertNational Institute of Standards and Technology - Cybersecurity Framework (NIST CSF)
Talk to an expertNIST Special Publication (SP) 800-171
Talk to an expertGeneral Personal Data Protection Law (LGPD)
Talk to an expertGeneral Data Protection Regulation (GDPR)
Talk to an expertCenter for Internet Security (CIS) Controls
Talk to an expertCloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
Talk to an expertControl Objectives for Information Technology (COBIT)
Talk to an expertInformation Technology Infrastructure Library (ITIL)
Talk to an expertVerband der Automobilindustrie-Information Security Assessment | Trusted Information Security Assessment Exchange (VDA-ISA | TISAX )
Talk to an expertInternational Automotive Task Force – Automotive Cyber Security (IATF)
Talk to an expertInternational Air Transport Association (IATA)
Talk to an expertHITRUST Cybersecurity Framework
Talk to an expertNational Cyber Security Centre | Cyber Assessment Framework (NCSC | CAF)
Talk to an expertTrusted Partner Network (TPN)
Talk to an expertWith NosConformes®, DM11® identifies and qualifies regulatory and compliance obligations to which your company needs to meet. Then all the requirements and structured congruences are studied to optimize a planning, service and monitoring model of compliance processes to which your organization applies, thus saving the time, reinvestments and wear and tear of your team.