Security Officer
Services
Eight services covering the full cycle of the role.
Service sheet
Service catalogue
Each service has its own sheet, with deliverables, method and basis.
| Code | Service | Type | Who it is for | Format |
|---|---|---|---|---|
| SO-01 | External Security Officer | Recurring service | Organisations without an internal security lead | Performing the role, with an annual plan and reporting to the management body |
| SO-02 | Information Security Maturity Assessment | Assessment | Organisations that do not know where they stand | Assessment by control domain and executive report |
| SO-03 | Management System and Certification Readiness | Project | Organisations seeking certification | System implementation and audit support |
| SO-04 | Risk Assessment and Management | Project | Organisations deciding without a risk assessment | Methodology, asset inventory and treatment plan |
| SO-05 | Supply Chain and Procurement Security | Project | Organisations that depend on critical suppliers | Supplier assessment and contractual clauses |
| SO-06 | Business Continuity and Recovery | Project | Organisations with critical processes | Impact analysis, plan and test exercise |
| SO-07 | Awareness and Security Culture Programme | Recurring service | Every organisation with employees | Annual programme with campaigns, simulations and measurement |
| SO-08 | Internal Audit and Third-Party Audit Readiness | Project | Organisations audited by clients or certification bodies | Internal audit, report and corrective plan |
At a glance
External Security Officer
External performance of the information security lead role, with a policy, an annual plan, risk assessment and periodic reporting to the management body.
Open service sheet SO-02Information Security Maturity Assessment
An assessment of information security maturity by control domain, with a gap map and a prioritised improvement plan.
Open service sheet SO-03Management System and Certification Readiness
Implementation of the information security management system and preparation for the certification audit, with documentation proportionate to the organisation.
Open service sheet SO-04Risk Assessment and Management
Definition of the methodology, asset inventory, risk assessment and a treatment plan approved by the management body.
Open service sheet SO-05Supply Chain and Procurement Security
Supplier assessment criteria, security and incident-alert clauses, and a follow-up process throughout the contract.
Open service sheet SO-06Business Continuity and Recovery
Business impact analysis, definition of recovery objectives, a continuity plan and an exercise that tests it.
Open service sheet SO-07Awareness and Security Culture Programme
An annual awareness programme, with themed campaigns, phishing simulations and measurement of results by team.
Open service sheet SO-08Internal Audit and Third-Party Audit Readiness
Independent internal audit of the management system and its controls, with a report, a corrective plan and preparation for external audits.
Open service sheetSecurity that is not measured is not managed
Start with a maturity assessment or ask for a proposal to structure the role.