IS Manager role
Please I will like to know the roles of IS Manager in any organization.
Assign topic to the user
First is important to note that ISO 27001 does not require a company to nominate a person to manage information security (for small companies a specific role would be overkill), so this role can be performed by an existing role.
Examples of what this person could do (divided by ISO 27001 sections) are:Compliance:
- Develop the list of interested parties related to information security
- Develop the list of requirements from interested parties
Documentation:
- Propose the draft of main information security documents
- Be responsible for reviewing and updating the main documents
Risk management:
- Teach employees how to perform a risk assessment
- Coordinate the whole process of risk assessment
These articles will provide you further explanation about the IS manager role:
- What is the job of Chief Information Security Officer (CISO) in ISO 27001? https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/
- Chief Information Security Officer (CISO) – where does he belong in an org chart? https://advisera.com/27001academy/blog/2012/09/11/chief-information-security-officer-ciso-where-does-he-belong-in-an-org-chart/
These materials will also help you regarding IS manager role:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Feb 12, 2020