I am the Quality Manager at *** and I am in charge of implementing ISO 27001 in the company. For this purpose, we have purchased the ISO 27001 Toolkit from Advisera, exactly ISO 27001 Documentation Toolkit English (with extended support).
In our case, we have a question that we would like to clarify with you, as we are sure you have seen more cases like this in many other companies.
*** is a small company (around 20-30 people) that is in a growth and expansion phase (in the next few years). As we are a manufacturer of custom-made medical devices, we have a Quality Management System according to ISO 13485 (applicable to medical device manufacturers) in place in the company.
Now, in defining and implementing ISO 27001 using the materials provided by Advisera, we see that there are many overlapping aspects between ISMS and QMS.
In all the material that Advisera provides in the ISO 27001 toolkik you mention the figure of the CISO or Information Security Manager. In *** all these tasks are being managed by the QARA Manager, which is me in this case.
Does ISO 27001 require the presence of a CISO or an Information Security Manager in the organizational chart?
What are the roles that must appear in the organizational chart by ISO 27001 requirement and that we should include in the current *** organizational chart?
Could all these roles be covered by Spentys’ current QARA Manager?
What do you recommend in this regard?