Industry: Biotech & Life Sciences
Company size: 1,000+ Employees ($4 Billion Market Cap)
Location: South San Francisco, California
A $100-million-a-year biotech company was seeking compliance based on the ISO 27001:2013 standards published by the International Standards Organization (ISO) located in Switzerland. The ISO 27001 standard is the framework that quantifies the vulnerabilities and threats of the ISMS (information security management system) of an international organization. It includes assessing the processes and policies of how a company uses and controls data. ISO 27001 is considered one of the toughest compliance certifications to obtain and maintain.
This synthetic biology company hired ICE Consulting for help with the IT-related portions of both the preparation and evidence gathering phase, and the audit phase of the ISO certification process beginning in 2018. ICE provided the necessary documents for:
With the help of ICE Consulting’s compliance specialists, our biotech client became ISO 27001 certified in late 2019, and we have continued to help the company maintain its certified status every year since then. We also assisted our client in obtaining an additional ISO certification for the manufacture of medical equipment, ISO 13485.
Industry: Medical Device
Company size: 75+ Employees
Location: Walnut Creek
A medical technology company was seeking compliance based on the Hi-Trust standards. Hi-Trust represents to patients and physicians that the technology provider has met the standards for identity and medical data protection. Hi-Trust has been called “HIPAA on Steroids” due to the requirements dictated for protecting patient information.
ICE Consulting provided assistance in the following areas:
The company became Hi-Trust certified in late 2021. Moving forward, we will help them maintain their certified status by supporting this client with our Security Operations Center (SOC) using tools such as Securonix Security Incident and Event Management (SIEM), User and Endpoint Behavior Analysis (UEBA), and network Traffic Analysis (NTA) offerings and CheckMK.
Industry: Department of Defense (DOD) Prime Contractor
Company size: 300+ Employees (Private company)
Location: Palo Alto
This US government contractor is required to comply with the standards of NIST regulation 800-171. The Cybersecurity Framework (CSF) details the policies, procedures, and steps necessary to protect an organization from possible threat situations that government organizations and contractors face from bad actors both internal and external.
ICE worked with the contractor to make the necessary changes to their IT infrastructure. We worked with the customer’s security personnel to set up the right hardware including new next-generation firewalls, advanced management software, and compliant VPN services to meet the standards.
Thanks to ICE Consulting, the government contractor met the standards to become NIST 800-171 compliant. ICE is currently assisting the customer on the CMMC (Cybersecurity Maturity Model Certification) process.