The National Technical Authority for Information Assurance
 
  ABOUT US   PRODUCTS & SERVICES   PUBLICATIONS   POLICY & TECHNOLOGIES   FIND A .....
CLAS Home
Finding a CLAS Consultant
Consultants Trained in Auditing Compliance with IA Standard No 6
CLAS Consultant Results
 
Abercrombie, Lawrence
Abercrombie & Abercrombie Ltd
Lawrie is an Information Assurance, Security and Intelligence professional and has worked on several programmes for the HMG and the MoD. He has extensive experience of:

  • HMG security policies
  • JSP440
  • RMADS
  • MPS / SPF
  • CESG InfoSec Memoranda
  • ISO27001
  • Security Policies and Procedures
  • Tactical / Strategic C4I
  • Security Assurance
  • Risk Assessments
  •  
    Adams, Dean
    Logica UK Ltd
     
    Alcock, John
    Fujitsu Services
     
    Ali, Mohammed
    Steria Ltd
     
    Allan, Peter
    Detica Ltd
     
    Allen, Steven
    Capgemini Plc
    Sixteen years of security specialism, with development background in trusted OS (Orange Book B3) and databases (ITSEC E3). In depth experience of healthcare, banking, media, car manufacturing, law enforcement and public sector, with specialism in biometrics, identity management, international data protection, information governance, ISO 15408 and evidential weight (BS 10008)
     
    Bakewell, Stephen
    MHA Security Ltd
    An independent security architect, experienced in:

  • Infrastructure
  • Applications, including Enterprise applications such as EDRMS, web portals, IdM
  • Service Oriented Architecture
  • Software development Lifecycle.

    RMADS development and review.

    Customers include Central Govt, Defence, Police, software development and investment banking. MSc Information Security, CISSP, ITPC HMG Practitioner, IISP membership.

  •  
    Balakrishnan, Ajith
    Logica
     
    Ball, Andrew
    Vistorm
    10 Years experience providing information security consultancy services across a range of government clients, including senior responsibility for security streams on large government bids and propositions. Recent projects have included CLAS assignments covering Security Management Contractual Transformation, HMG Security Accreditation Activities, Audit and Assurance against HMG Policies, Risk Analysis, Evaluation and Planning.

  • Strategic transformation, business development and business innovation are at the forefront of Andy's consultancy principles, seeking to drive efficiency and enhance the customer service delivery.

  • With a strong interest in niche and growing areas of security such as social engineering and new technologies Andy endeavours to stay at the forefront of an ever involving sector.
  •  
    Ball, Nigel
    Activity Information Management Ltd
    Nigel is a communications and information security consultant with over 25 years continuous employment in the IT industry. With extensive experience in a wide range of hardware platforms, operating systems and network protocols, as well as a proven track record in developing policies and architectures for enterprise integration.
     
    Ball, Richard
    Logica Reading
     
    Bamford, Mark
    Mark has over 15 years experience in Information Assurance (IA),first as a security evaluator and then as an IA consultant in MOD and HMG enviroments. He has experience of writing RMADS, SyOPs, and working with the OGC Model Contract. He is currwntly working on IA awreness with in HMG.

     
    Bance, Peter
    Rhye Internet Solutions Limited
    Peter SJF Bance (CEng MBCS CITP M.Inst.ISP) is an Information Assurance Consultant working Primarily in the South East of England,specialising in technical and other aspects of impact/threat/risk assessment,countermeasure definition and penetration testing.

    Extensive knowledge of JSP440 (MOD),Security Policy Framework (SPF,HMG) AND iso27000.

    Also a member of the BCS Register of Approved Security Practitioners,a chartered Engineer and full member of the Institute of Information Security Professionals (IISP).

     
    Barnett, Stephen

    Independent Information Security and Assurance with a solid technical background and extensive public and private sector experience, including Lead Security Architect for a major central government IT programme and Information Security Manager of a UK Plc. Key skills: Security strategy and architecture,RMADS authoring, accreditation planning and ISO 27001.

  • Qualifications: BA in Electrical and Information Sciences (Cambridge), MSc in Information Security (Royal Holloway), CISSP,A.Inst.IISP.

  •  
    Barraud, Steve
    Logica UK Ltd RG2 6UA
     
    Belfield, David
    Verizon Business Ltd
    10 years RAF secure information systems Officer. 8 years industry security experience across Finance, Telco & transport. Consultancy advice and bid management for vendors and customers. Experience with IAM from PKI to Biometrics. MPS & JSP440 experience MSc IT Security, Prince II practitioner & founding member of IISP.
     
    Bellis, Mark
    Logica UK Ltd
     
    Bencard, Piers
    Logica
     
    Blackman, Stewart
    BT
     
    Boyce, Kenny
    Secdata Ltd
    Kenny is an experienced information assurance manager skilled in delivering business wide Information Security Strategies and Security Functions to clients across various business sectors.

    As well as being CISSP and IS0 27001 Lead Auditor qualified, Kenny has vast experience in Information Security Governance, Risk Management, Technology Reviews and Policy Design.

     
    Bradshaw, Gary
    CSC
     
    Bryce, Andy
    Steria Ltd
    Andy has over 30 years of IT experience including the last 9 years in Information Security. He specialises in Infosec consulting and in RMADS development for Central Government departments.

    Andy is a Certified Information Systems Security Professional, CISSP and holds the ITPC Certificate of Infosec Competency (Government Practitioner).

    Andy is also a Chartered IT Professional member of the British Computer Society,MBCS CITP,and a full member of the Institute of Information Security Professionals,M.Inst.ISP.

     
    Carroll, David
    IBM UK Ltd
     
    Chambers, Colin
    Hytec Information Security Ltd
     
    Channing, Richard
    Lynwood IA Ltd
    Dick Channing is an IT consultant with 25 years of experience, including 15 years in security. Dick has extensive knowledge of Government and Military security standards, architectures, networks and risk management. His experience includes Government, MOD and Military systems. Dick has a technical background in software design and data analysis.
     
    Christina, Glenn
    Logica UK Ltd
     
    Cole, David
    Atkins Limited
    All-round security practitioner with strong experience of BS7799/ISO17799/ISO27001 gap analysis, implementation, and certification. Knowledge of HMG standards and accreditation process (ITPC qualified). 2.5 years hands-on experience running an information security management system. Qualified HMG safety practitioner. Exceptionally coherent in expression and able to bridge the technical-business divide. CISSP certified
     
    Collings, Tony
    ECA Ltd
    28 years systems experience CLAS 7 years Resilience/Security of Data Centres hosting GSI/CNI services Accreditation for IA (HMG Accreditor) HMG Policy and RMADS, CoCos Data Handling and Privacy Impact Assessments Threat, Risk, Business Impact Assessments Identity Management Logical and Physical Protection Measures
     
    Collins, Ashley
    Logica (Leatherhead)
    Ashley works in Logica's Security and Identity Management Practice where he is part of the Governance, Risks and Compliance team. He offers over fifteen years of experience across the entire IT system development lifecycle. His technical specialisms include cryptography,security modelling/architecture and risk management (HMG IAS1 and HMG IAS2).Ashley holds the CISSP and ITPC certifications. In addition he is a Chartered Fellow of the British Computer Society and Associate of the Institute of Information Security Professionals.
     
    Colombo, Jonathan
    Capgemini Plc
    Jon is an Executive Consultant with 20 years of Information Security experience in both the public and private sectors. Jon specialises in Infosec Strategy, Governance, Management and organisational change. He has set up and run Infosec Departments in three large organisations.

    Qualifications: MBA, CISSP, CISM, MBCI.

     
    Cooke, Chris
    Coovers Infosec Limited
    Chris has fourteen years' applied experience in IT architecture, InfoSec, Technology Risk Management, IT Strategy and Policy, including a detailed knowledge of 7799, eGIF, MPS, PKI, secure forms and digital signature / encryption. He has delivered InfoSec and technical architecture advice / deliverables to Financial Sector, NHSIA, Aerospace Sector and Local Government.
     
    Coombes, Damian
    IBM UK Ltd
     
    Corbett, Christopher
    Computer Sciences Corporation
     
    Creane, Mick
    BT plc
     
    Cross, David
    DC Securitas Ltd
    Information Assurance, Protective Security and Military/Corporate Intelligence Consultant with over 30 years of experience. Specialist knowledge in all aspects of/Qualified:

  • MPS
  • JSP440
  • ISO27001/BS7799
  • Personnel Security and Vetting
  • Identity Management
  • Physical Security (Defence, Commercial, Data Centres, Retail )
  • Highly experienced Threat and Risk Management
  • Prince 2 Practitioner
  •  
    Curzon, Mark
    Symantec-LIRIC Ltd
    Mark is an Information Security consultant with 18 years experience within the MoD, Private and Public Sectors.

    Well Versed in:

  • Risk Assessments
  • Security Policy and Procedure production
  • MPS, JSP440 and HMG Policy
  • IS027001 Compliance and certification
  • RMADS production
  • Gap Analysis
  • Mark is a certified IS027001 and BS25999 Lead Auditor.

     
    Davidson, Doug
    Computacenter (UK) Ltd
     
    Davidson, Peter
    Hewlett Packard Ltd
     
    Dawson, Barry
    CSC Computer Sciences Ltd
    22 years Military, Police and Commercial experience for Infosec work and consultancy. This has included RMADS production and review, ISO27001 implementation and audit. Training covering generic and course specific security requirements, Monitoring and Investigation with evidence preparation and presentation at court.
     
    Devine, Christopher
    CSC
     
    Dunne, Louise
    Parthen Loreli Ltd
    A client orientated CLAS, IA security, risk managing consultant and compliance specialist with in-depth knowledge of HMG standards, including RMADS/Hannigan/Data Handling Review/IS6/PIA's and the new Security Policy Framework (SPF). A Prince2 Practitioner and ISO 27001 Lead Auditor with Accreditation and Project Management experience in both the Public and Private sector.

     
    Edon, Ann
    Fujitsu Services
     
    Elcoate, Keith
    Vistorm Ltd
     
    Ellis, Richard
    Teknikally IT Ltd
    Richard has extensive hands-on experience in IT. Starting in software development he moved into operating system and network support with responsibilities that included infrastructure design and management. His experience covers network and system architecture, security architecture, system integration and technical project management. He is ITIL Manager and Prince2 practitioner qualified.
     
    Ellis, Adrian
    Logica UK Ltd RG2 6UA
     
    Eriksen, John
    4orge Ltd
    Working as an Infrastructure and Security Architect / Information Assurance Consultant. Extensive experience in delivering best practice information security management services to MoD and Central Government.
  • Experience in Defence, Police and Government Projects
  • Proven track record in security architecture and policy framework.
  • Skills in:

  • Implementation of HMG and Defence (JSP440) policy and Security Policy
  • CoCo (CJX compliance etc) & policy creation
  • Government security consulting, management and solution design.
  •  
    Erkadoo, Kamil
    Scorpion Securities Ltd
    Kamil Erkadoo has 15 years Infosec experience including the production of HMG Accreditation Document sets, risk assessments, policy development, security audit, business continuity and data protection.
    He is a software engineer, Prince2, ITIL, ITPC and has passed the ISO27001 lead auditor's course also holding the BCS ISEB certificate in information security management principles.

    Independent CLAS Consultant, ITPC Practitioner, ISO27001.

    Kamil has over 25 years of IT experience including the last 15 years in Information Security. He specialises in Infosec consulting having supported numerous Central Government departments. Kamil is an IT Professional member of the British Computer Society holding MBCS status and IISP as Associate Member.

     
    Evans, Mark
    Vistorm Ltd
     
    Ewart, Marc
    Advalus Ltd
     
    Excell, Michael
    Roke Manor Research Ltd
    Mike is a systems engieer and security consultant with over 14 years of experience. His experience includes:

  • Designing, implementing and accrediting secure systems from high level designs through to detailed configuration of devices and physical security
  • Embedding information assurance into the design of a product
  • Enterprise System Engineering.
  •  
    Feltham, David
    Endava (Managed Services) Ltd
    Senior security consultant and skilled implementer, with wide ranging experience of network and application security - in particular the design and implementation of high performance, resilient security gateways and certificate based application security. Technical specialist on firewall, VPN and PKI technology, with broader consultancy expertise and experience from performing security reviews and advisory assignments.
     
    Fowler, Max
    Detica Ltd
    Dr Max Fowler Security Architect. Max has 32 years experience in the Defence IT industry, the last 15 years of which involved work in network security (COMSEC and COMPUSEC). He has defined security architectures for a number of military networks with up to 10,000 users, obtained accreditation for a wide variety of operational and non-operational systems, conducted security risk analyses for future system enhancements, and managed small teams of security consultants engaged in security work.
     
    Freeman, David
    Activity
    Highly experienced IA consultant proficient in the development of security policies,information security management, communications security, service and project management. With extensive experience of various information system technologies, a proven track record in developing policies and architectures for enterprise integration,collaborative working architectures and information management including assuring personal data.
     
    Gausden, Christopher
    CSC Computer Sciences
    Chris has a UK MOD (RAF) Security and Police background with 30 years security experience working in both Public and Private Sector. He has a BSc in Computer Science is a MBCS CITP and has CISSP and 27001 Lead Auditor Qualifications.
     
    George, Russell
    Security Minds Ltd
     
    Gosnold, James
    Fujitsu Bracknell
     
    Greengrass, Christopher
    Amethyst Risk Management Ltd
    Chris has over 9 years Information Assurance experience, working with clients in Government, Defence, Financial and Commercial Organisations.

    Chris's particular areas of expertise lie in:

  • Public Key Infrastructure and Federated Identity Systems
  • BS7799 Compliance
  • Formal Risk Assessments and Gap Analysis
  • Security Policy and Procedure Definitions
  • Creation of RMADS
  • GSi. GCSx Code of Connections
  •  
    Grimshaw, James
    Cable & Wireless
    Security consultant with proven history of designing, selling and delivering innovative solutions to varied client base. Experience ranging from ITSEC evaluation, risk assessment and business continuity through large-scale architecture design and technical implementation. Working knowledge of PKI, web-based e-commerce, roaming, mobile commerce, VPN, firewalls, penetration testing. Former qualified CLEF evaluator.
     
    Grimshaw, Peter
    PGLB Consulting Ltd
     
    Guest, Paul
    Academy Solutions Ltd
    Paul is a technical consultant and trainer with over 15 years IT industry experience. Highlighted skills include:

  • Risk assessment and production of RMADS
  • Security architecture based on the Manual of Protective Security and HMG Standards, Manuals & Memos
  • Delivering security and technical training courses
  • Paul's qualifications include MSc Information Security (Royal Holloway), CISSP and a variety of vendor certifications.

     
    Hackney, Francoise-Marie
    Activity Information Management Ltd
    Francoise's particular areas of expertise lie in:

  • Formal Risk Assessments and Gap Analysis
  • Security Policy and Procedure Definitions
  • Accreditation Document Sets (RMADS)
  • ISO 27001
  •  
    Hall, John
    IBM UK Ltd (Hamps)
     
    Hamilton, Edward
    Anaysys Mason
    Over the last 18+years Edward has gathered a wealth of IA experience. With a strong technical background Edward has advised clients across many sectors. Specialities include Identity Management and confidential working within police,network and VPN design,protective monitoring,managing third parties, accreditation, audits and technical reviews.
     
    Hansford, Paul
    Logica (Leatherhead)
     
    Hatfield, Stephen
    ECIS Consultants Ltd
     
    Hawkins, Brian
    Vistorm Ltd
     
    Heathcote, Andrew
    Amethyst Risk Management Ltd
    Andy has over 21 years experience in security and information assurance, 18 years as an officer in the RAF security branch and the last 3 years as an IA consultant in the Public Sector, primarily MoD. He has considerable experience in producing RMADS ( using CESG IS1 & IS2 risk assessment/treatment methodologies, JSP 440 and DIANs 07 & 08 (Domain Based Security Modelling), ISAs and IMPs.
     
    Hendrick, Patrick
    IBM UK Ltd
     
    Hendry, Campbell
    Symantec - LIRIC Ltd Oxford
    An IS0/IEC 27001 Lead Auditor, CISSP and PRINCE2 he has 25 years IA experience including conducting risk assessments, gap analyses, implementation of 27001 and production of accreditation document sets for various Government departments. Consequently, he has comprehensive knowledge of the MPS, 27001, JSP440, CESG Manuals, Memoranda and associated documentation.
     
    Hogg, Martin
    Picasso HR Ltd
     
    Hood, Barry
    Vistorm Ltd
     
    Horan, Mick
    Atos Origin
     
    Huffer, Andy
    Business Technology Computers Ltd
    Security Consultant wih 10 years experience, 3 years infosec experience. Specialising in Public Key Infrastructure (PKI) and in particular PKI within Government. Secure E-mail and Secure Extranet, Mimesweeper, NT and messaging configuration. Cyberguard and Firewall-1 Installations. I also have experience with IT Health Checks, Intrusion Detection Systems and project management.
     
    Hughes, Michael
    Teeke Consulting Ltd
     
    Hunt, Alan
    Hytec Information Security Ltd
     
    Isaacson, David
    BAE Sys Christchurch
     
    Jackson, Simon
    Westminster Computing Ltd
     
    Jarvie, John
    Logica Reading
     
    Joseph, Dudley
    Fujitsu Services Ltd
     
    Jumpp, Robert
    Logica Reading
     
    Kenway, Bill
    Sy5 Ltd
    Bill has been involved in RMADS and policy work on a number of large government projects including both bid work and delivery on successfully won projects.
     
    Kirkham, Richard
    Detica Ltd
     
    Lathar, Kamal
    Rapier Computers Ltd (Oxon)
    Highly experienced IT Security Consultant,CLAS, certified BS7799 lead auditor, involved in security Designs, IT Architecture, Infrastructure, complete project lifecycle, processes and procedures, 16yrs+ in security; commercial and government.

    All aspects of Accreditations; applications to network infrastructures, technologies,defence in-depth, RMADS IS1 analysis,mitigation and treatment for compliance against ISO27001, gov-standards.

     
    Le Riche, Philip
    Steria Ltd
    CEng MBCS CITP ITPC M.Inst.ISP, and CLAS member since 2004, Philip has worked extensively on accreditation,risk assessment,policy development and ISO27001 conformance since 1999, and has mainly worked on security-related projects since the late '80s, in Central Government and Defence, Local Government and Police. (Direct approaches cannot be entertained).
     
    Ledermann, Mark
    Fujitsu Services
     
    Lewis, David Mark
    Computer Network Defence Ltd
     
    Lewis-Painter, Colin
    Logica
     
    Lidbetter, Kevin
    Steria Ltd
     
    Lord, Steve
    Mandalorian Security Services Ltd
    A principal technical security professional with 10+ years experience including the technical aspects of:

  • Penetration Testing
  • Application Security
  • Enterprise Applications (SAP.Siebel,WebsphereMQ etc). 3rd Party Supplier Technical Controls
  • Procurement Support
  • Tailored assessment
  • Manual T,V,Y
  • Thin Client Security
  • Anti-malware response, investigation and reverse engineering.
  •  
    Lovett, Richard
    Richard Lovett & Associates Ltd
    Six years experience in Information Assurance (IA) including GSi and BS7799 accreditation. Formerly RN Commander with one appointment as Fleet security officer. Clients since January 2000 include: Land Registry, Customs & Excise, Compaq, Kellogs, CWS, Amey Group, a Borough Council, DFID, Police IT Organisation (PITO), Metropolitan Police.
     
    Markworth, Mamta
    Detica PLC
     
    Martinez, Leslie
    C&W
     
    McBrearty, Clare
    QinetiQ Farnborough
     
    McCann, Sonia
    Pentura
  • Sonia is an Information Security professional and certified ISO27001 Lead Auditor with over five years IT and security experience in private and public sector organisations. Sonia is a CLAS Consultant experienced in Security Risk Management and the production of RMADS. Her expertise covers the development of Infosec policy and strategy guidance including security risk assessments and the application and use of the SPF, Infosec assurance standards, and Good Practice Guides.
  •  
    McGrath, Daniel
    Logica Reading
     
    McKay, William
    Information Assurance (UK) Ltd
    Information Assurance/Security Professional with 20+ years management and technical experience of security standards, architectures, networks and risk management covering Military, Home Office, Police, Health and Commercial environments including:

    "ISO 27001/BS7799:2 certification of MessageLabs UK/USA HR environments" NHSnet/N3 Infrastructure Manager specializing in accrediting Third Party Connections.

    M. Inst.ISP, CISSP, CISA and ISO27001 Lead Auditor qualified.

     
    McLean, Paul
    GT Classics Ltd
     
    Merritt, Daren
    Teamwork IMS Ltd
    Daren has been a member of the CLAS scheme since its inception and has extensive experience in both the public and private sectors.

    Areas of exprtise include:

  • ISO27001, PCI DSS, RMADS, IGSoC
  • Business analysis and planning (Daren has an MBA)
  • Gap Analysis and Certification Project Management
  • Risk Assessment (including a large recent IS1 project)
  • Business Continuity Planning (to BS25999 certification)
  • Experience within the Telecommunications and Networking Sectors
  •  
    Moir, Deborah
    BT
     
    Morgan, Terry
    Terana Consulting Ltd
    Terry Morgan has specialised in Information Assurance for HMG since 1990 and joined the CLAS Scheme in 2002.

    He has worked on both major delivery projects and consultancy assignments for defence and civil government clients, with emphasis on meeting the requirements for achieving and maintaining security accreditation.

     
    Morgan, Blake
    CIA Consultancy Ltd
    A Senior InfoSec Consultant skilled in providing professional advice and services to customers who need to protect their business information assets.

    Experienced in providing guidance in accordance with HMG InfoSec Policies and standards, UK legislation and the MOD's JSP 440. Including the provision of Supplement 12 Risk Balance Cases.

     
    Morrell, Richard
    Logica UK Ltd RG2 6UA
     
    Morris, David
    Vistorm Ltd
     
    Moye, Tamsin
    Actica Consulting Ltd
    Key areas of expertise include:

  • Central civil Government, Local Authorities, Emergency Services, Law Enforcement
  • ISO 27000 series compliance assessments
  • Codes of Connection-development, assessment, compliance, gap analysis and compliance plans, including for Airwave, GSI, GCSX, CJX
  • Mobile technologies including Emergency Services solutions
  • IS2 RMADS development, including Business Impact Assessments, in-house Threat Assessments, risk assessments, risk treatment/security plans and security operating procedures
  • IS1 technical risk assessments and risk treatments to the latest IS1 parts 1 and 2
  • Security requirements specification and compliance
  • Accreditation planning and support for complex systems.
  •  
    Murphy, Michael
    Semca Ltd
     
    O'Connor, Neil
    Activity
    A senior IT management and information security consultant with over twenty years experience in all aspects of computer and communications security. Neil has provided IT strategy, security, risk, project and programme management advice to a number of major HMG and MOD procurements. Expert in IS1 risk assessments and ISO27001 implementation.
     
    Ollier, Ian
    Integralis
     
    Page, Mark
    Better Network Solutions Ltd
    Mark is a MOD (JSP440) and Government Agency Architect and Security Specialist across all classifications.

    Specific experience: design of secure OS, audit and accounting, ID&A, Mandatory Access Control, anti-virus, and IMPEX.

    ADS writing: using both BS7799 and IS2 templates, and has experience of CRAMM risk assessment methodologies, specifically IS1 calculations.

     
    Palmer, David
    IBM (UK) Limited
     
    Peters, Stephan
    SLR Infosec Limited
     
    Pitman, Darren
    Pasporte Ltd
     
    Poland, Keith
    Ion Solutions Limited
    I have over ten years experience in Information Security ranging from evaluation of secure systems, the definition of security policies, to the provision of strategic information security consultancy within Government and the commercial arena. I have worked on Office Automation, Command and Control, secure communications systems and financial transaction systems.
     
    Powell, Chris
    Atos Origin
    I have over 15 years experience mainly in the finance and telecoms industries. Principal tasks that I have performed are:

    1. Security Assessments Reviews and Audits based on BS7799
    2. Definition, implementation and review of public key infrastructure solutions for e-business
    3. Security risk analysis
    4. t-scheme consultancy
    5. Security policy writing and implementation.
     
    Pringle, John
    Boldon James lTD
    Principal Consultant, Boldon James. 15+ years experience in military, secure government (MPS/JSP440), wider public sector and CNI sectors, in system accreditation, risk analysis, security strategy, business continuity, forensic readiness, and security education training and awareness. Experienced in BS7799 strategy, gap analysis, compliance and accreditation projects. Professionally qualified Internal and Quality Auditor.
     
    Race, John
    Vistorm Ltd
     
    Richards, Daniel
    IT Defence Ltd
    Experienced CLAS security consultant providing services to Defence, Central Government and Private sector clients.

    Application of HMG MPS, Infosec Standards 1,2 and 3 and JSP440 to existing and emerging projects.

    Production of RMADS in accordance with IS2 and JSP440 (DBSy in accordance with DIAN 07/08)

    Security accreditation lifecycle and security risk management

    Development of security architectures

    ISO/ IEC 17799 compliance audits and development of ISMS

     
    Ritchie, Bill
    Quintec Associates Ltd
    Bill is an experienced systems engineering consultant with in depth background in systems security. He is able to bring together systems engineering skills and security requirements in order to provide sensible, cohesive and workable security solutions.
     
    Rizvi, Syed
    Logica Reading
     
    Robson, Mark
    RAMA Consulting Ltd
    Infosec Specialist/Security Architect with over 15 years extensive experience including Defence (particularly MOD/DII) at all protective marking levels, JSP440, MPS, development of Accreditation Document Sets (ADS), Domain Based Security, Operational Security Management planning and delivery, domain interconnectivity including GSI & xGSI, application of CND (including IDS, anti-virus, zero-day protection).
     
    Rolfe, Jon
    Steria Ltd
    Jon is a Senior Technical Architect with over 14 years experience in the IT industry. He specialises in designing secure Microsoft based infrastructures for clients in the UK public sector and currently holds various professional qualifications including CISSP, CEH and MBCS CITP.
     
    Ryan, Phil
    Detica
    In addition to the normal areas of expertise for a CLAS consultant Philip has specialist experience in the following areas:

  • Defence Accreditation (JSP440 etc)
  • Domain Based Security
  • Data Gateways
  • Voice and VoIP Systems
  • Video Teleconferencing
  • Alert Warning and Response
  • Computer Network Defence
  • Higher Protective Markings
  •  
    Sanders, Mark
    BT Plc
     
    Sanderson, Samantha
    Lockcode Ltd
     
    Segelov, Mark
    Quantainia Ltd
    Information Assurance Consultant with extensive experience across public and private sectors,including:

  • Information Assurance/Security Strategy
  • Application of ACPO/HMG/MOD policies
  • ISO27000 seri
  • RMADS production (IS1,IS2....)
  • Security Architecture and Risk Assessment
  • Programme and project management

    Qualifications:CISSP-ISSAP,ISSMP-CISSP,CISA,ISO27001 Lead Auditor,Prince 2 Practioner,CLEF evaluator.

  •  
    Sharman, Robin
    EBOS Ltd
    Sixteen years experience in Infosec. MoD, Local Government, Central Government, Police, Security Services. BS7799 Lead Auditor, ISO17799 Implementor,intimately familiar with IS1 etc, CESG Memos, JSP440, MPS, BS7799, Data Protection, Computer Misuse, FOI, RIPA. Research and production of RMADS. GSI connectivity.
     
    Shaw, David
    BT Fleet
     
    Singh, Malcolm
    Sopra Group
     
    Slessenger, Peter
    BT
     
    Sloan, Kevin
    Amethyst Risk Management Ltd
    I have 21 years IT and Infosec experience. I have prepared Accreditation Documentation Sets and have considerable experience in undertaking risk assessments against BS7799 and CRAMM. I have knowledge and practical experience of Public Key Infrastructure (PKI) and have worked in the defence, government and private sectors.
     
    Smalley, Nicholas
    Activity Information Management Ltd
    Over 20 years IT experience advising on and implementing secure systems including Healthcare, Financial, HMG and MOD providing:

  • Design and implementation (including Smartcard management)
  • Partnership with TDA to accredit solution's
  • Risk analysis and producing ADS's
  • Advise on implementing MPS, JSP440, BS7799 and HMG policy.

    Projects include: DTI, Cabinet Office, GSI, DMICP, DII.

  •  
    Smith, Andy
    AIS Infosec Ltd
    Senior Infosec specialist with 20 years experience in IT & the Internet, 18 years with Information Security and a member of CLAS for 7 years. Specialising in Security Architectures, risk assessments, risk management,Standards compliance (ISO/IEC 27001), legal and regulatory compliance and policy development.

    Qualifications: MSc (Infosec). CEng, FBCS, FSyI, CITP, CISSP, CISA, CISM, SMIEEE, M.Inst.ISP, ITPC, ISO27001 Lead Auditor.

     
    Smith, Steven
    Logica UK Ltd
     
    Standing, Henry
    Academy Solutions Ltd
     
    Staniforth CEng MBCS, Bernard
    LOGISEC Ltd
    Trouble-shooter producing usable systems with security-engineering and software design.

    Clientele:

  • international finance
  • telecommunications
  • utilities
  • SME/partnerships
  • Government (GSI)
  • police

    Services:

  • policy (BS7799)
  • risk analysis/management
  • architecture
  • product selection
  • assurance
  • cost benefits
  • get-well health check
  • security case advocacy

    Technologies:

  • distributed systems (web)
  • message
  • combat systems
  • payment systems
  • networks (firewalls)
  • smartcards
  • cryptography (PKI)
  •  
    Steele, Andrew
    IBM UK Ltd
    CESG approved as best qualified for assisting HMG/CNI with developing Manual V solutions.
     
    Stezycki, Alexander
    CSC
     
    Straw, Julian
    Primasec Ltd
    Experienced CLAS consultant specialising in security assurance and accreditation.

    Strong knowledge of security evaluation (Common Criteria), FIPS 140, CTAS, defence and civil government.

     
    Swalling, Scott
    Logica (Leatherhead)
     
    Swift, Nick
    Selex Galileo
     
    Taylor, Adrian
    Zone Consulting Ltd
    A highly experienced and commercially aware Security Consultant, building upon some 20 years of security, IA and technical skills and having worked in a cross section of industries as a technician and security consultant.

    Qualified as CISSP and ISO27001 Lead Auditor.

     
    Tegg, Nicholas
    Logica Reading
     
    Thomas, Philip
    PDK Consultancy Ltd
    Provides CLAS Consultancy to both public and private sector clients working to standards, JSP440 and IS1v3.

    Excellent technical background (14 years), covering server and network infrastructure and security, cryptography and telecomms for MOD, Blue Chip, Govt.

    Skillset includes Risk Assessments, RMADS, SRD, RAM, BoE, Technical Design and Evaluation.

     
    Thomson, Ross
    Amethyst Risk Management Ltd
    5+ years of Information Assurance experience, working with clients in central government defence and commercial organisations.

    His expertise includes:

  • RMADS Development (IS2 and JSP440)
  • Web application security (n-tier environment)
  • Security Policy and Procedures Definition
  • ISO27001 Compliance (BSi Lead Auditor)
  • Information Assurance Training
  •  
    Tomlinson, Gary
    Quintec Associates Limited
    Gary is a former Royal Signals CIS Manager who has provided cross spectrum capability at all levels. Has since provided C4I and IA expert advice on projects such as AirTanker, FIST and Watchkeeper. He is highly regarded and will travel if necessary.
     
    Tompsett, Gerald
    Fujitsu Bracknell
     
    Treeby, Steven
    2e2 uk Ltd
    A highly security cleared, ITPC and CLAS registered Government Security Consultant with substantial IT security experience gained over 25 plus years within both the private and public sectors in companies such as EDS, LogicaCMG, the MoD and AIG.

    Has a background as an EMEA network manager and an accreditor, but since becoming CLAS accredited has worked on various projects for the MoD, Cabinet Office, Home Office, Office of Security and Counter-Terrorism, Security Industry Authority, Department of Business Innovation & Skills and many others.

     
    Turnbull, Gordon
    IBM UK Ltd (Hants)
     
    Twallin, Richard T
    Pondergrove Ltd
    Richard has more than 20 years experience of information security, having first worked with CESG in 1980. He now specialises in infosec management systems, advising organisations on the business processes needed to manage security effectively and how to achieve ISO 17799 certification. He is a Strategic Assignments Consultant with the Office of Government Commerce.
     
    Umoren, Edet
    Logica Reading
     
    Vinnicombe, Richard
    QinetiQ, Farnborough
    Nine years experience in government and commercial sectors, Richard specialises in security architectures and project support, particularly secure satcom/satnav, network and crypto design. Working with accreditors he has written complete ADS solutions. A background in military research promotes a focus on innovative solutions, which combines well with Richard's business-focused outlook.
     
    Walsham, Martin
    Info-Assure
     
    Warrington, Neil
    Logica Reading
     
    Watson, William
    Vistorm Ltd
     
    Wellsted, Simon
    Capgemini Plc
     
    Wickramasinghe, Himanshu
    IBM UK Ltd (Herts)
     
    Wilkinson, Neville
    Selex Sensors & Airborne Systems
     
    Wilkinson, William
    Security Minds Ltd
     
    Williams, David M
    Lockheed Martin UK Transport & Security Solutions
     
    Wood, Mike
    Secure Information Technology Ltd
    Mike has been an independent security consultant since 1994, specialising in security accreditation, security management and security analysis/design on major IT projects. Mike always aims to deliver feature-rich yet cost-effective solutions that meet both the demands of the business and the regulations that are imposed upon it.
     
    Worley, Jessica
    Logica UK Ltd RG2 6UA
     
    Wren, Christopher
    Innocent Solutions Ltd
    Information Security Consultant with 14 years experience, a strong technical background with the ability to communicate complex issues and ideas, across all levels.

    Experienced practitioner, working to public and private sector internal, contractual and regulatory requirements, frameworks and documentation sets.

    CBCI, CGRCP-IT, CISSP, CISSP-ISSMP, CISM, CISA, BSI ISMS Lead Auditor.

     
    Younger, Kevin
    Capgemini Plc
    Kevin has over 5 1/2 years experience working with large Central Government clients.

  • IA Lead on complex multi agency projects
  • RMADS review and creation using the latest v3 standards
  • Security Working Groups
  • Client side supplier management for IA.
  • ISO 27001 Lead Auditor
  • CLAS
  • CISSP
  • CISM
  • Associate Member of the IISP.
  •