Datasec - IT Security & Control

Meycor KP (Knowledge Provider) Print









MEYCOR KP is a software specifically designed to develop, implement and host ISO Management Systems, particularly the ISO/IEC 27001:2005 standard. In addition to this, the product offers a wide range of uses, from hosting Quality and Environmental Management Systems, COBIT, and ITIL to the maintenance of Business Continuity Plans and Security Policies.

The software was specifically designed to facilitate the implementation and maintenance of any system that requires managing documents and events. MEYCOR KP also includes specific modules for the ISO/IEC 27001:2005 standard for Information Security Management Systems.

The flexible design comprises the following modules:

Central

The central module allows you to manage users, user groups, events, news, log display and to configure all the relevant technical aspects of the software.

Document Management

This module allows you to manage documents, questionnaires and data, making it possible to control the status or transitions these items may experience during their life cycle (draft, finished, approved, published, and version history). Documents can be created directly in the module or imported regardless of their format.

Risk Management

This module allows you to manage and follow-up Risk Analyses according to the requirements of the ISO/IEC 27001:2005 standard. It also enables you to identify assets, threats and vulnerabilities, producing current and residual risk outcomes. The software includes the objectives and controls of the ISO/IEC 27002 standard to facilitate risk treatment, and you can also generate the Statement of Applicability for treatment controls and plans.

Event Management

This module allows you to define and manage different types of event logics and workflows. Each event category includes a customizable group of data fields, status and transitions predefined by the Administrators, and each category can be addressed and treated using different customizable actions. In addition to this, the module allows you to manage Security Events, Non-compliances, Remedial and Preventive Actions, Change Requests and many other events.

Control Self-assessment

This module allows organizations to self-assess themselves against well-known best practices such as ISO/IEC 27002, ISO/IEC 20000, COBIT, COSO and any other relevant evaluation frameworks. Assessments are performed for specific periods and in line with the access permissions granted to users by the Administrators.

Communications

This module allows you to generate e-mail alerts for predefined users triggered by several customizable situations. For example, notifications can be sent when a document needs to be approved or published, a document expires, a reported event needs treatment, and many more.

Minimum Hardware Requirements

  • PC with at least a 300 MHz Pentium Processor.
  • 256 MB RAM.
  • A minimum of 20 MB hard disk space for installation and related files.
  • CD-ROM Unit.

Minimum Software Requirements

  • Windows® 2000/XP/2003 with IIS on the web server.
  • SMTP Server.
  • Microsoft .NET Framework 1.1.
  • Microsoft SQL Server 2000/2005.

Additional Technical Information

This product was developed using .NET technology with the VB.NET language.
The web interface was developed using ASP.NET running on a IIS web server.
Database access is performed with ADO.NET and a connection can be established using native SQL, ODBC or OLEDB.
E-mails are sent using the IIS's SMTP server or any other SMTP server.