ISO 27001 and Information Security manger
Assign topic to the user
Answer: ISO 27001 does not define a role such as Information Security Manager, but authorities and responsibilities that must be fulfilled:
- ensure that the ISMS conforms to ISO 27001 standard; and
- report on the performance of the ISMS to top management
These authorities and responsibilities can be designated to the role of Information Security Manger, if it exist in the organization, or to any other role the organizations sees as appropriated.
These articles will provide you further explanation about authorities and responsibilities for the ISO 27001 ISMS:
- What is the job of Chief Information Security Officer (CISO) in ISO 27001? https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/
- Chief Information Security Officer (CISO) – where does he belong in an org chart? https://advisera.com/27001academy/blog/2012/09/11/chief-information-security-officer-ciso-where-does-he-belong-in-an-org-chart/
- Role s and responsibilities of top management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/06/09/roles-and-responsibilities-of-top-management-in-iso-27001-and-iso-22301/
- How to document roles and responsibilities according to ISO 27001 https://advisera.com/27001academy/blog/2016/06/20/how-to-document-roles-and-responsibilities-according-to-iso-27001/
These materials will also help you regarding authorities and responsibilities for the ISO 27001 ISMS:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Oct 04, 2017