Expert Advice Community

Guest

Security organizations and security roles

  Quote
Guest
Guest user Created:   May 26, 2016 Last commented:   May 26, 2016

Security organizations and security roles

We are building ISMS based on ISO27001 standard. From ISO27001 point of view, Security Organization needs to be built.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic May 26, 2016

Answer: This is not entirely true - you have to build an Information Security Management System, the term "Security organization" is not mentioned in the standard. See this article: What is an Information Security Management System (ISMS) according to ISO 27001 https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/

How important are the roles? For example Can a person title be “Network Engineer” and role be information security officer ? Is this understanding correct organization should have security roles reflected as HR title as well.

Answer: It is very important to clearly define roles and responsibilities - in smaller companies it does make sense to give a role of information security management to an employee who will perform this role together with his other regular duties. The standard doesn't require this, but you can give a title to this security role - e.g. Chief Information Security Officer, Information Security Officer, Security Manager, or similar.

See also these articles:
- Chief Information Security Officer (CISO) – where does he belong in an org chart? https://advisera.com/27001academy/blog/2012/09/11/chief-information-security-officer-ciso-where-does-he-belong-in-an-org-chart/
- What is the job of Chief Information Security Officer (CISO) in ISO 27001? https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 26, 2016

May 26, 2016

Suggested Topics