Virtual CISO
Information security direction
For anyone who already has, or is about to have, a security management system and needs someone to steer it.
- Steers the risk treatment plan and decides what is accepted, mitigated or transferred
- Chairs the security committee and leaves minutes with agreements and owners
- Reports to top management or to the board in business language, not technical
- Keeps the Statement of Applicability, the policies and the indicators alive
- Assesses the security of critical suppliers before signing and during the relationship
- Directs the response when there is an incident and puts the evidence in order afterwards
- Prepares and supports the internal and certification audits