SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Managment representative for iso 27001

  Quote
Created:   Nov 12, 2016 Last commented:   Nov 14, 2016

Managment representative for iso 27001

MR is not a requirement by ISO 27001 but I would like to assign one who will be most suitable for it I have a security consultant who is mainly responsible about the complete 27001 and I have security specalist and both report to ciso and most of the ciso activities are being delegated to infosec consultant.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 14, 2016

Thank you for your question.

Please find my answers below:

To decide among your options (infosec consultant, security specialist and ciso) who would be the most suitable person for role of ISO 27001 MR, you must consider who currently has the responsibility and authority to: 1) Ensure the ISMS conforms with ISO 27001:2013; and 2) Report the ISMS performance to top management. Besides that, you also should consider their knowledge about the business processes and their interpersonal skills. While the first two items will ensure your MR role conforms with ISO 27001:2013 clause 5.3 (organizational roles, responsibilities and authorities), the last two will help the MR to better work towards integrating information security with the business and managing the commitment of the interested parties.

These articles will provide you further explanation about defining the MR for ISO 27001:
- What is the job of Chief Information Security Officer (CISO) in ISO 27001? https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/
- Chief Information Security Officer (CISO) – where does he belong in an org chart? https://advisera.com/27001academy/blog/2012/09/11/chief-information-security-officer-ciso-where-does-he-belong-in-an-org-chart/
- How to document roles and responsibilities according to ISO 27001 https://advisera.com/27001academy/blog/2016/06/20/how-to-document-roles-and-responsibilities-according-to-iso-27001/

These materials will also help you regarding defining the MR for ISO 27001:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your
Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/

Feel free to contact us for any further assistance.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 12, 2016

Nov 14, 2016

Suggested Topics