The problem it solves
Security is handled by whoever has time, not by whoever has the mandate. Investment decisions are taken without a risk assessment and nobody answers to the board for the state of information security.
Who it is for
- Mid-sized organisations without an in-house CISO;
- Public entities with contractual and certification obligations;
- Suppliers that must demonstrate security to their clients.
Deliverables
- Approved information security policy;
- Annual security plan with priorities and budget;
- A maintained and reviewed risk assessment;
- Periodic report to the management body.
Method
- 01
Assess
Current state and gaps.
- 02
Structure
Policy, roles and plan.
- 03
Operate
Monitoring, advice and review.
- 04
Report
Indicators and decisions.
Regulatory basis
- Article 32 GDPR, on security of processing;
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
- Contractual and certification requirements imposed by clients and public tenders.
Expected results
- A role with a mandate and a method;
- Security decisions grounded in risk;
- A management body informed and accountable.
Note
Where the organisation is covered by the Portuguese Cybersecurity Act, the regulated cybersecurity officer role is covered at cybersecurityofficer.pt.