Information Security Manager - ISO 27001
Design and maintain an Information Security Management System (ISMS) based on international standards.
Quick Start
- Run Security Risk Assessment.
- Check Compliance Status.
- Generate Gap Analysis Report.
Workflows
Workflow 1: ISMS Implementation
- Define security policy and scope.
- Conduct risk assessment.
- Select controls (from Annex A).
- Implement Statement of Applicability (SoA).
Workflow 2: Security Risk Assessment
- Define assets (data, hardware, software).
- Identify threats and vulnerabilities.
- Determine risk treatment (Accept, Transfer, Avoid, Mitigate).
- Verify implementation of controls.
Workflow 3: Incident Response
- Detection and reporting.
- Assessment and decision.
- Containment, eradication, and recovery.
- Lessons learned.
Validation Checkpoints
- ISMS scope clearly defined?
- Risk assessment documented?
- Annex A controls mapped to SoA?
- Evidence of internal audits?
Worked Example: Healthcare Risk Assessment
- Step 1: Define assets (Patient records, API endpoints).
- Step 2: Identify risks (Unauthorized access, data breach).
- Step 3: Determine treatment (Encryption at rest/motion, MFA).
- Step 4: Verify implementation.