Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-01

External Security Officer

External performance of the information security lead role, with a policy, an annual plan, risk assessment and periodic reporting to the management body.

The problem it solves

Security is handled by whoever has time, not by whoever has the mandate. Investment decisions are taken without a risk assessment and nobody answers to the board for the state of information security.

Who it is for

  • Mid-sized organisations without an in-house CISO;
  • Public entities with contractual and certification obligations;
  • Suppliers that must demonstrate security to their clients.

Deliverables

  • Approved information security policy;
  • Annual security plan with priorities and budget;
  • A maintained and reviewed risk assessment;
  • Periodic report to the management body.

Method

  1. 01

    Assess

    Current state and gaps.

  2. 02

    Structure

    Policy, roles and plan.

  3. 03

    Operate

    Monitoring, advice and review.

  4. 04

    Report

    Indicators and decisions.

Regulatory basis

  • Article 32 GDPR, on security of processing;
  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
  • Contractual and certification requirements imposed by clients and public tenders.

Expected results

  • A role with a mandate and a method;
  • Security decisions grounded in risk;
  • A management body informed and accountable.
Note

Where the organisation is covered by the Portuguese Cybersecurity Act, the regulated cybersecurity officer role is covered at cybersecurityofficer.pt.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.