ESRM Program · Assets Cluster
Information Security
Know what information you hold, where it lives, and who can see it.
$2,500 fixed-fee assessment 3–4 weeks Credited toward the vCSO program
Measured against ISO/IEC 27001 and 27002. Led by Don Oxman, CPP, CISSP, CISM. Licensed by Texas DPS. In business since 2013.
Sensitive files end up in places nobody planned.
Information security is one of thirteen domains in our Enterprise Security Risk Management (ESRM) program, and part of the Assets cluster. Cybersecurity protects your systems. Information security protects the information itself, on paper or on screen: patient files at a Fort Worth clinic, personnel records in an HR cabinet, bid pricing on a contractor’s shared drive.
In most companies, nobody owns the information as such. IT owns the servers, HR owns personnel files, and the controller owns the financials, but no one decides what is sensitive, who may see it, how long to keep it, or how to destroy it. Old records pile up in shared drives and storage rooms. Privacy laws such as the Texas Data Privacy and Security Act assume someone is in charge. We help you sort information by sensitivity and set handling rules people will follow.
What can go wrong with your information
Oversharing
Shared folders open to everyone, links sent outside the company, and reports forwarded to personal email put sensitive files in front of the wrong people.
Paper & disposal
Files left on desks, cabinets left open, recycling bins full of records, and old copiers with hard drives inside are common sources of real disclosures.
Keeping too much
Records kept long past any business or legal need are still there to be lost, stolen, or subpoenaed. Many companies have no retention schedule at all.
Departing employees
People leaving for a competitor can take customer lists and pricing with them. Without handling rules, it is hard to show anything was taken.
Privacy obligations
Depending on your size and industry, the Texas Data Privacy and Security Act, HIPAA, and customer contracts set rules for how you collect, use, and protect personal data.
Data integrity
Records changed without a trail, kept in competing versions, or restored from a bad backup lead to wrong decisions and disputes you cannot settle.
Five questions for leadership
- Could you name the five most sensitive kinds of information you hold and where each one lives?
- Do employees know which files they may email, print, or take home, and which they may not?
- Is there a written retention schedule, and does anyone actually destroy records on it?
- How are paper records, old hard drives, and copier drives destroyed, and is there proof?
- If a customer asked what personal data you hold about them, who would answer, and how?
If you answered “no” or “not sure” to any of these, that is where we would start. Most of these gaps cost little to fix before an incident and a great deal to fix after one.
How an Engagement Works
Every ESRM domain starts with the same fixed-fee assessment. If you decide to continue, we credit the fee toward the program, and information security becomes part of your vCSO engagement alongside whichever other domains you need.
Information Security Assessment
- Interviews with HR, the controller, operations leads, IT, and the staff who handle customer or patient records.
- Structured review: a 15-question risk profile, a 25-point practices checklist, and a maturity score from 1 (Initial) to 5 (Optimized).
- Information inventory: what you hold, where it lives on paper and in systems, who can see it, and who receives it.
- Gap analysis against ISO/IEC 27001 and 27002, with a check of your obligations under Texas privacy law.
- Written report and prioritized roadmap, walked through with your leadership team. The report is yours whether or not you continue.
The fee is credited in full toward the program if you start within 90 days.
The vCSO / ESRM Program
- Assess (Q1): we start from your assessment findings.
- Build (Q2): an information security policy, a simple classification scheme, handling rules for each level, a retention schedule, and disposal procedures.
- Privacy: a review of your privacy notice, a process for requests from individuals, and data terms for vendors who receive your information.
- Training for the people who handle sensitive records, built around the files they actually work with.
- Operate (Q3+): we stay on as the named owner, with quarterly access reviews, spot checks, and reporting to leadership or your board.
Month to month. Cancel with 30 days’ notice. About the vCSO program →
Data & Privacy Projects
- Data mapping for one system or process, from collection to disposal.
- Records retention schedule, drafted for review by your counsel.
- Privacy request handling when someone asks about their data.
- Privacy review of a new system, app, or vendor before launch.
Why Total 360
Information and systems, one advisor
Information security covers paper, people, and process as well as technology. We handle both, so your written policy and your technical controls match.
Independent recommendations
We don’t resell software, shredding, or storage services, and we take no commissions. We recommend what fits the information you actually hold.
Experienced leadership
Led by Don Oxman: M.S. in Security Management, CPP, CISSP, CISM. U.S. Army and AT&T background. In business since 2013 and licensed by Texas DPS.
Common questions
What does a information security assessment cost?
$2,500, as a fixed fee. It usually takes three to four weeks from kickoff to the readout. If you start the vCSO program within 90 days, the full fee is credited toward it.
What do we get at the end of the assessment?
A written report with your maturity score from 1 (Initial) to 5 (Optimized), the gaps we found against ISO/IEC 27001 and 27002, with a check of your obligations under Texas privacy law, and a prioritized roadmap. We walk your leadership team through it, and the report is yours whether or not you continue.
Do we have to sign up for the full program?
No. The assessment stands on its own. If you continue, information security runs inside the vCSO program at $2,500 to $7,500 a month depending on scope. It is month to month, and you can cancel with 30 days’ notice.
Can we buy data & privacy projects without the program?
Yes. They are available to any client. Billed per project, quoted in advance.
Will you replace the people and providers we already use?
No. We work alongside your IT provider, attorney, insurer, and other advisors. We set the standard, help them meet it, and check that the work gets done.
Start with a 30-minute Risk Discussion
No deck and no sales pitch. Tell us what kinds of information you handle and what concerns you. We’ll give you an honest read on the gaps and send a scoped proposal within five business days.
Schedule a Risk Discussion Or call 817-677-0515 · info@total360security.com