Aims
Create an ISMS in ISMSOnline from scratch, ensuring integration with the existing integrated management system. Ensure all appropriate Annex A Controls are assessed against asset threats to ensure proper compliance and implement required controls. To be completed in 2 years for a major client.
Role
Project manager and lead implementer
Key Points
- Develop all aspects of the ISMS to ensure successful certification to ISO 27001.
- Implement risk management for information security
- Develop robust procedures to encapsulate requirements of Annex A Controls
- Update existing integrated management procedures to cover requirements of ISO 27001
- Project manage implementation using resources from the client as required.
- Ensure ease of navigation within the ISMS
Successes
- Implementation has been completed independently to allow the client to focus on business needs.
- Certification was achieved with no findings.
- Implementation has supported a successful SOC1 type 1 audit,
- Implementation is ready to support GDPR compliance and extension to SOC2.
Skills
- ISO 27001 requirements and controls
- ISO 27001 implementation
- Project Management
- Gap analysis
- Process Mapping
- Process creation and update
- Presentations
- Security risk management
Tools used
- ISMSOnline
- Word
- Powerpoint
- Jira
- Confluence
