GTIA Cybersecurity Trustmark

IT service providers (ITSPs) sit at a unique intersection of risk and cybersecurity management. For decades, frameworks designed for other businesses—facing different risk landscapes—have been attempted to fit the scope of the ITSP. The results have been frustrating.  

Not every ITSP is in the same place in their risk and cybersecurity management maturity. Establishing a starting point and milestones to guide that journey is where the GTIA Cybersecurity Trustmark enters. 

 

We took a new approach. We scanned the globe for as many risk and cybersecurity frameworks as we could find. We collected questionnaires from dozens of cybersecurity insurance providers to understand the needs of underwriters. Ultimately, we discovered the safeguards and controls that would best meet the needs of an ITSP were all out there, just not in one place. 

Foundationally based on the Center for Internet Security’s 18 Critical Security Controls IG2, and supplemented by controls from other globally recognized frameworks, the Cybersecurity Trustmark standard identifies industry-accepted best practices unique to IT service providers. Your journey through this assurance program will be ongoing. There is no time at which the “box is checked” and the job is done. 

The Cybersecurity Trustmark is based on a true maturity model. It is designed to provide scaffolding to support your business’s growth in understanding risk and cybersecurity management. It requires a shift in thinking, an embrace of continuous improvement. Each organization seeking Trustmark Assurance will have a different path. The program helps you tailor your plan of action to not only mitigate risk by implementing and strengthening safeguards but capitalize on the opportunities risk can provide. 

Join the Readiness Program today! 

  •  

The Cybersecurity Trustmark Readiness Program provides 24-month access to the Trustmark safeguards, guidance, implementation prompts, education, peer resources and GTIA industry partners all in place to help you understand, embrace and implement industry best practices for risk and cybersecurity management. A small program fee, subscription with an approved governance, risk and compliance (GRC) vendor, and GTIA membership are required to join the program. While the program allows for 24 months, most companies are ready for their initial assessment within 10 months. 

When you are ready for assessment, a CREST accredited assessor will be made available through GTIA at a cost-controlled, negotiated price point unique for GTIA members.

Resources for the GTIA Cybersecurity Trustmark Program

Interested in the GTIA Cybersecurity Trustmark? Take a look at this list of free resources to help you better understand the broad expectations of the Cybersecurity Trustmark program.

If you have questions, please contact [email protected].