Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Please note that businesses have different organizational structures, so your focus shouldn't be on departments, but on roles and responsibilities.
Considering that, for ISO 27032 (Guidelines for cybersecurity), the roles responsible for information security, network security, internet security, and critical infrastructure should be trained (normally these roles are in the department which handles Information and Communication Technologies).
About ISO 27035 (Information security incident management), the above-mentioned roles, now including roles responsible for legal compliance also should be included.
For further information, see: