Expert Advice Community

Guest

Senior management does not want to spend money and resources

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Senior management does not want to spend money and resources

The sr. management does not want spend $ and bring additional resources on sight! [As an IT Sec. consultant I am  in a catch 22.]
0 0

Assign topic to the user

ISO 27001 LEAD AUDITOR COURSE

Become an ISO 27001 certification auditor.

ISO 27001 LEAD AUDITOR COURSE

Become an ISO 27001 certification auditor.

Guest
DejanK Jan 12, 2016

Of course they won't if they do not see a reason why they should do it. See also this article: ISO 27001 project – How to make it work https://advisera.com/27001academy/blog/2013/04/22/iso-27001-project-how-to-make-it-work/

What level of training a Business Owner [who is in charge of many applications] is required to manage the risk in the applications with PII, with many partners?

Answer: In my view, business owners should be trained in the following: (1) to understand why the risk assessment and treatment are important for their job, and (2) how to assess the risks (i.e. which scales to use), and (3) how to treat the risks (i.e. which options exist). See also this article: How to organize initial risk assessment according to ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/04/29/how-to-organize-initial-risk-assessment-according-to-iso-27001-and-iso-22301/

How to I bring these Business Owners on board to manage risk in their applications?
[Frankly they will attest any documentation that I ask for..., without understanding the full implications;  but that do not mitigate data security specially under PII].

Answer: You must teach them what the benefits for their job are - once they accept this, everything else will be easier. Read this article: Four key benefits of ISO 27001 implementation https://advisera.com/27001academy/knowledgebase/four-key-benefits-of-iso-27001-implementation/

Poor Compliance (just signing the documents..) does not mitigate risks. How to educate these sr. managers - VPs, Div. heads, div. presidents., etc.)

Again, find the benefits of information security implementation and communicate those to your top management. This webinar will teach you the techniques: ISO 27001 benefits: How to obtain management support https://advisera.com/27001academy/webinar/iso-27001-benefits-how-to-get-management-buy-in-free-webinar-on-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics