SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Security Manager Position

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Security Manager Position

0 0

Assign topic to the user

ISO 27001 IT SECURITY POLICY

Define the detailed security rules for everyone in the company.

ISO 27001 IT SECURITY POLICY

Define the detailed security rules for everyone in the company.

Guest
AntonioS Jan 12, 2016

I'd like to get your advice regarding the following aspect:
Consider you have been selected to occupy in Information Security Manager position, what is the first task of your job you will do? I think making Gap analysis for all department. But I need to get your say please.
Furthermore, I need your support to provide me with tool or technique that helps me writing Gap analysis for the first usage? Then what's the next step after been hired in this position and after furnishing the Gap analysis?
Also, Do you have any documentation for Fruad management and Anti Fruad compliance? and Contractual agreements forms?
 

Answer:

If you are the Information Security Manager in a company that wants to implement the ISO 27001, one of the firsts things that you need effectively is to perform a gap analysis, because it can give you information about the status of the company in relation to ISO 27001 (but keep in mind that it is not a requirement in the ISO 27001, although is very recommendable). To do this, you can use our free tool “Free ISO 27001 Gap Analysis Tool” : https://advisera.com/27001academy/free-iso-27001-gap-analysis-tool/
Regarding to the next steps in the implementation, I think that this article can be interesting for you “ISO 27001 implementation checklist” : https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/
Regarding your question about “fruad”, I suppose that you mean “fraud”, and we do not have specific information about this, but maybe this free ebook can be interesting for you “9 Steps to Cybersecurity” : https://advisera.com/books/9-steps-to-cybersecurity-managers-information-security-manual/
Finally, regarding your question about contractual agreements forms, we do not have this, but this template about security clauses for suppliers and partners can be interesting for you (you can see a free version of the document clicking on “Free Demo” tab) “Security Clauses for Suppliers and Partners” : https://advisera.com/27001academy/documentation/security-clauses-for-suppliers-and-partners/

Quote
0 0
Guest
Guest post Jan 12, 2016

Thanks Antonio for your reply, it is really valuable info. I need to update my question please.

 

Consider the same question that I asked but this time the company is certified ISO 27001, so what's the first job I should do once hired in this position?

Quote
0 0
Guest
AntonioS Jan 12, 2016

There are some tasks that you need to perform in the maintenance of the ISMS, for more information, please read this article "How to maintain the ISMS after the certification" :

https://advisera.com/27001academy/blog/2014/07/14/how-to-maintain-the-isms-after-the-certification/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics