i2Sustain

Once an organization achieves full compliance with a NIST 800-171/172 or CMMC mandate, they must commit to ongoing efforts to remain in compliance – or sustain compliance. Imprimis i2Sustain includes a "Security Stack" of services which include:

  1. Continuous Sustainment Services
    • Endpoint Protection
    • Multifactor Authentication
    • Monitoring
    • Vulnerability Scanning/Remediation
    • GCCH Maintenance
    • Training
    • Backups
    • Security Information & Event Management (SIEM)
    • Secure Access Service Edge (SASE), as applicable
    •  
  2. Additional On-Demand Services
    • CISO Advisory Services
    • Incident Response Exercises
    • Forensic Analysis
    • Annual Assessments

Imprimis also provides support as needed, or on demand. These services include incident response, forensic analysis, annual reassessments and advisory services, to name a few.

Though most, if not all, of these services will be required at some level, the client’s specific organizational network structure and budget will dictate which platform or service selected.  Our access to numerous service suppliers allows us to customize sustainment solutions to fit any organization.


Continouus Monitoring

The continuous activity includes continuous monitoring of the system, frequent vulnerability scans, part-time CISO (Chief Information Security Officer) support and training.

Imprimis provides continuous monitoring via a cloud-based SIEM (Security Information & Event Management) which collects logs and network information from multiple devices and can correlate activities and identify anomalies. The analysis also includes behavioral analysis utilizing a UEBA (User or Entity Behavioral Analysis) program. Logs and data are collected from key devices within the network and stored in a cloud-based SIEM where the UEBA analysis takes place. Alerts are issued for anomalies, and the logs are maintained for at least 12 months. One of the primary benefits of continuous monitoring is tracking logins and failed login attempts. With proper network segmentation activities within the network can be tracked as well. 


Vulnerability Scanning

Another very important requirement is scanning the network for vulnerabilities and to remediate them when found. Vulnerabilities exist within the software used for operating systems and applications. They can also include open ports and exposed network segments. Imprimis installs scanner software within the network to provide the scanning information -- the internal scans show open ports and any un-remediated software vulnerabilities on all devices within the network

The scanning software also performs a discovery scan which is important for asset management - both software and hardware assets. Vulnerability scans of externally facing IP addresses are scanned periodically to ensure no vulnerabilities are exposed outside of the network.


Training

Training is a mandatory compliance requirement and is one of the most important activities a company can provide as part of their cybersecurity program. More than 3 out of 4 successful attacks involve the compromised accounts of someone who is authorized to be on the system.

Imprimis can provide training to staff and executives on policies and procedures of the company, and to key personnel whose responsibility is to manage risk. This training could include the role and responsibilities of data owners or network owners. Imprimis, as a KnowBe4 Certified Partner, provides KnowBe4 training for employees, IT technical personnel, privileged user, remote workers, HR and management helping to improve awareness and stress the importance of observation, due diligence and reporting.

Imprimis is a Knowbe4 Certified Partner

KnowBe4's Security Awareness Training (KSAT) is the world's largest security awareness and simulated social engineering product. It combines an expansive content library localized in 35 languages, AI-driven simulated phishing and training, and enterprise-grade reporting. On average, KSAT reduces an organization's Phish-prone Percentage from 30% to less than 5% after 12 months.


On Demand Services

Imprimis also provides support when needed or ‘on-demand’ at an hourly rate.  These services include incident response and mitigation, forensic analysis, annual reassessments and advisory services. 


Contact US

Contact Imprimis at 719-463-0333 or visit https://www.imprimis-inc.com/contact-us  to take the first step toward true cybersecurity resilience.