I have a question about the ISMS roles in a small organisation. We’re a company of about 20 employees, so naturally there are not many management layers. Basically we have COO and CEO above the ISMS team, and this makes assigning the roles a bit challenging. Do you have a recommendation what roles are needed for a small organisation for ISO 27k? We currently do not have formal roles of e.g. quality manager, or head of information security, but we can