SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Setup of Governance, Risk and Security department

  Quote
Guest
Guest user Created:   Sep 30, 2020 Last commented:   Sep 30, 2020

Setup of Governance, Risk and Security department

I have been tasked to setup the IT Governance, Risk and Security department from zero and was wondering what approach to take to make it easy to adopt as well as practical being practical and allow me to introduce polices, guidelines to mitigate risks as I go along.

0 1

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 30, 2020

Broadly speaking, to set up a new department in an organization is very similar to the implementation of a management system, and you should consider:

  • the identification of a clear reason why you need this new department (e.g., it will fulfill a business need, it will give a market advantage, it will comply with legal requirements, etc.).
  • the definition of objectives, goals, and targets
  • the performing of risk assessment, to identify relevant risks related to the achievement of objectives, goals, targets.
  • the definition of an action plan, considering the activities the department must perform (e.g., risk management, audit, controls implementation, employees training, etc.), which competencies you need (i.e., job descriptions), how many people will be required, and how it will be its internal organization (i.e., hierarchy). At this point, you will define which policies, guidelines, and controls to implement to mitigate risks to the achievement of objectives, goals, and targets.
  • the identification of requirements related to space, equipment, and facilities.
  • how to fill job vacancies (e.g., internal placement, or external hiring)
  • the definition of a specific budget
  • top management approval of the proposed department

For further information, see:

The concepts in these articles, although applied to ISO 27001, can be used to set up a new department from zero.

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Sep 30, 2020

Sep 30, 2020

Suggested Topics