Owner of general procedures
We are discussing the ownership of general procedures. We have a classification of information in my organization and we are pretty much ISO27001 compliant. I, as an IT auditor, consider that the "head" of the organization is the owner of the general procedures, which are applied throughout the organization. Do you find it correct?
Assign topic to the user
ISO 27001 does not prescribes which role must be responsible for policies and procedures, so an organization can define these responsibilities as better fits it.
Considering that, the "head" of the organization is one good option when the ISMS scope is the entire organization. When the ISMS scope covers only part of the organization, this responsibility can be delegated to the person with the highest hierarchical level in the scope. In both cases, this responsibility can be delegated to the person responsible for the information security, if such a role exists.
Please note that this makes sense only for general policies and procedures. For more operational policies and procedures, a person in charge of particular department or process will be the best owner - e.g. Head of human resources for HR security procedures.
These articles will provide you a further explanation about the top management responsibilities:
- Roles and responsibilities of top management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/06/09/roles-and-responsibilities-of-top-management-in-iso-27001-and-iso-22301/
- What is the job of Chief Information Security Officer (CISO) in ISO 27001? https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/
This material can also provide further information:
- Managing ISO Documentation: A Plain English Guide https://advisera.com/books/managing-iso-documentation-plain-english-guide/
Comment as guest or Sign in
Mar 11, 2020