Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


A guide on how to establish and implement an ISMS and the run of your ISMS. Planning consists of annual activities and of monthly or quarterly activities. (the CISO's planning for the year/quarter/month)

To make a yearly plan:
The CISO should make his own plan, implement it in the company,  check internal (f.i. business) external (f.i. law) changes, check compliancy and make a plan for the next year to implement findings out of the evaluation.  Part of the yearly plan will be quarterly or monthly plans.

1.1 Security Improvement Activities

ActivityReasonResultDateReference to Security goals in the ISMS

Status*

Implement IDSsee an increase of attacksEarly warning of an attack2 august 2018Goal nr. 2 to detect and react and mitigate security attacksIn progress






...

1.2 Plan for Risk assessment

DepartmentAreaRecurrenceNext Date

Status*

AccountingLogical AccesAccessquarterly11 November 2017Planned
HR systemLogical Accessquarterly

DatacenterPhysical Access2/year

Quality ManagementRisk registerquarterly

Quality managamentRisk acceptance (system owner/senior management)2/year

Quality managementASecurity management systemannual

1.3 Awareness and Security training

...

To put in: Security by Design - What to look at when you have a new product or service run.


Legend
Status
Planned
In progress
Completed
Cancelled