Milliman Security Management System MS2 Home | Contact | Site Map | Milliman    
Milliman Security Management System
Overview
MS2
MS2:VM
 

Compliance FAQs

 

How does MS2 help ensure that the proper security safeguards are in place?


Experienced and certified information security professionals developed and tested MS2 control surveys to meet generally accepted industry security standards and practices. The applicability of these controls has been validated in work with many customers concerned with security and compliance. 

 

Standards and practices include, but are not limited to, those published by:

  • National Institute of Standards and Technology (NIST)
  • Information Systems Audit and Control Associations (ISACA)
  • Information System Security Association (ISSA)
  • International Standards Organization (ISO)

MS2 assesses 28 administrative, physical technical security topics ranging from human resource practices, to information disposal to wireless networks and web hosting. It contains over 750 optional survey questions about safeguarding security in different business circumstances and IT environments. These questions are regularly updated to reflect “best practices” and “generally accepted security practices.”

 

MS2 is a complete security compliance solution that also includes robust threat and vulnerability risk assessments and security safeguard gap assessments. It categorizes gaps, provides guidance in how to address gaps, tracks compliance activities, and produces a comprehensive set of easy-to-use compliance reports.

 

 

Compliance FAQs

How does MS2 help implement and maintain an effective security compliance program?


How does MS2 help ensure that the proper security safeguards are in place?


How does MS2 help your organization comply with Sarbanes-Oxley?


How does MS2 help with Gramm-Leach-Bliley Act (GLBA) compliance?


Are all the elements of the GLBA Safeguard Rule included in MS2?


What kind of security risk assessment methodology does MS2 use and does it conform to NIST (National Institute of Standards) protocols?


Why does MS2 map controls to standards such as NIST and ISO?


What is the ISO 17799 standard, and why is it so important?


Does MS2 calculate a Return of Investment (ROI) for the security gaps identified during the risk and gap assessment?


How does MS2 help achieve HIPAA compliance?


Which features in MS2 help organizations achieve HIPAA Security compliance?


What is the definition of common control?

 

If my vendor says that the system we are using is HIPAA Security compliant, does that mean we are also HIPAA Security compliant?