Service
Security governance & compliance
Policies, committees, roles and metrics: a security governance that survives an audit.
The problem we solve
Policies often exist on paper, but nobody knows who applies them, who reviews them or how to measure their effect. When an audit or a major client request arrives, everything has to be rebuilt in a hurry.
Who it is for
- Organizations pursuing ISO/IEC 27001 certification
- Companies required to appoint a person in charge of personal information
- Boards wanting regular oversight of cyber risk
What is included
- Review and drafting of security policies
- Definition of roles and responsibilities (RACI)
- Set-up of a security committee
- Executive metrics dashboard
- Certification audit readiness
Our approach
We start from what exists and make it workable: short policies, tied to named owners, with metrics that can actually be measured. Governance has to hold once we are gone.
Typical deliverables
Policy set
Drafted, approved, versioned
RACI matrix
Security and privacy roles
Dashboard
Quarterly metrics for leadership
Statement of applicability
For the ISO 27001 journey
Expected outcomes
- Clear, owned responsibilities
- An audit you prepare for instead of endure
- Leadership informed of risk, quarter after quarter