Citicus
8 Case Studies
A Citicus Case Study
Humberside Police, a law enforcement organization in England with about 2,900 employees, needed to comply with the BS7799-based Community Security Policy by ensuring all information systems were formally risk assessed and their risks actively managed. After finding external consultants expensive and unwieldy for key systems, they turned to Citicus and its Citicus ONE product to handle the process internally.
Citicus ONE’s built-in BS7799 standard of practice enabled Humberside Police to run risk workshops with system owners, users, and technical staff to assess compliance and identify risks. According to the Information Security Officer, the tool made results immediate and understandable for non-security staff, while involving stakeholders in risk action planning made it easier to manage and monitor risks over both the short and long term.
Mick Adair
Information Security Officer