Regulated Incident Management Ecosystem Versão portuguesa

Security Officer

Services

Eight services covering the full cycle of the role.

Service sheet

Service catalogue

Each service has its own sheet, with deliverables, method and basis.

CodeServiceTypeWho it is forFormat
SO-01External Security OfficerRecurring serviceOrganisations without an internal security leadPerforming the role, with an annual plan and reporting to the management body
SO-02Information Security Maturity AssessmentAssessmentOrganisations that do not know where they standAssessment by control domain and executive report
SO-03Management System and Certification ReadinessProjectOrganisations seeking certificationSystem implementation and audit support
SO-04Risk Assessment and ManagementProjectOrganisations deciding without a risk assessmentMethodology, asset inventory and treatment plan
SO-05Supply Chain and Procurement SecurityProjectOrganisations that depend on critical suppliersSupplier assessment and contractual clauses
SO-06Business Continuity and RecoveryProjectOrganisations with critical processesImpact analysis, plan and test exercise
SO-07Awareness and Security Culture ProgrammeRecurring serviceEvery organisation with employeesAnnual programme with campaigns, simulations and measurement
SO-08Internal Audit and Third-Party Audit ReadinessProjectOrganisations audited by clients or certification bodiesInternal audit, report and corrective plan

At a glance

SO-01

External Security Officer

External performance of the information security lead role, with a policy, an annual plan, risk assessment and periodic reporting to the management body.

Open service sheet
SO-02

Information Security Maturity Assessment

An assessment of information security maturity by control domain, with a gap map and a prioritised improvement plan.

Open service sheet
SO-03

Management System and Certification Readiness

Implementation of the information security management system and preparation for the certification audit, with documentation proportionate to the organisation.

Open service sheet
SO-04

Risk Assessment and Management

Definition of the methodology, asset inventory, risk assessment and a treatment plan approved by the management body.

Open service sheet
SO-05

Supply Chain and Procurement Security

Supplier assessment criteria, security and incident-alert clauses, and a follow-up process throughout the contract.

Open service sheet
SO-06

Business Continuity and Recovery

Business impact analysis, definition of recovery objectives, a continuity plan and an exercise that tests it.

Open service sheet
SO-07

Awareness and Security Culture Programme

An annual awareness programme, with themed campaigns, phishing simulations and measurement of results by team.

Open service sheet
SO-08

Internal Audit and Third-Party Audit Readiness

Independent internal audit of the management system and its controls, with a report, a corrective plan and preparation for external audits.

Open service sheet

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.