[Draft] Entry Level is DISP’s baseline tier. It was designed to bring organisations up to modern information security standards, and approval clears your organisation for information up to and including OFFICIAL: Sensitive.
What it involves
[Draft] An Entry Level engagement covers four areas:
- Governance: Security Officer and Chief Security Officer selection, and custom governance documentation
- Personnel: insider threat awareness training
- Physical: a physical security audit
- Cyber: implementation consultancy against the required controls
Is it enough for us?
[Draft] In our experience, Entry Level is sufficient for the majority of companies in the supply chain. If you need to self-sponsor security clearances, or handle PROTECTED information or above, you will need a higher level.