Expert Advice Community

Guest

Defining roles and responsibilities

  Quote
Guest
Guest user Created:   Jan 08, 2019 Last commented:   Jan 08, 2019

Defining roles and responsibilities

We are a small company and while we have competent people, we do not have individuals for every role e.g. Risk Manager to manage the SOA etc. Can you please explain how we can define roles and responsibilities, taking into account we need to define skills and competencies for every role and the person appointed for each role?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 08, 2019

Ideally we need you to guide us with the minimum team we need to implement the ISO 27001 standard 'in-house' and also what roles can be combined.

Answer:

ISO 27001 does not prescribe a "minimum team" for running an ISMS, so organizations are free to define the size of their teams according to their needs.

For very small organizations just one person with the proper competencies and authority is able to run an ISMS. For organizations up to 50 employees you may consider one person at top management level and one person to run daily activities. For bigger organizations you should consider including information security responsibilities on existing roles like IT manager, HR manager, and training them to perform relat ed activities.

These articles will provide you further explanation about roles and responsibilities:
- What is the job of Chief Information Security Officer (CISO) in ISO 27001? https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/
- Roles and responsibilities of top management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/06/09/roles-and-responsibilities-of-top-management-in-iso-27001-and-iso-22301/
- How to document roles and responsibilities according to ISO 27001 https://advisera.com/27001academy/blog/2016/06/20/how-to-document-roles-and-responsibilities-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 08, 2019

Jan 08, 2019

Suggested Topics

Guest user Created:   Jun 02, 2021 ISO 27001 & 22301
Replies: 1
0 0

Annex A.16

Guest user Created:   Jan 20, 2018 ISO 27001 & 22301
Replies: 2
0 0

Organizing IT area