Information Security Management System
A CISO's working environment: risks, policies, procedures, and management reporting. The system unifies materials and processes for managing security and supporting client security reviews.
The task
Bring information security risk management, the action plan, policies, procedures and reporting into one working environment.
Methodology and processes
The framework includes the security roadmap, regular reporting to management and documents ranging from the information security policy to the incident response procedure.
These materials and processes are connected inside a software system that supports the people accountable for security.
Audits and external requirements
A separate part covers client and investor questionnaires and preparation for transaction due diligence. For each item, the answer, compensating controls and the closure deadline are recorded.
The work combines security management tools with guidance on organizing processes and preparing the required materials.