Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-02

Information Security Maturity Assessment

An assessment of information security maturity by control domain, with a gap map and a prioritised improvement plan.

The problem it solves

Without an initial measurement, security is discussed through impressions. Each department defends its own priority and the budget ends up where there is most insistence, not most risk.

Who it is for

  • Organisations preparing for certification;
  • Boards that need a baseline;
  • Investors and buyers in acquisitions.

Deliverables

  • Maturity report by control domain;
  • Gap map prioritised by risk;
  • Improvement plan at 90 and 180 days;
  • Presentation to the management body.

Method

  1. 01

    Collect

    Documents and interviews.

  2. 02

    Evaluate

    Controls by domain.

  3. 03

    Prioritise

    Risk and effort.

  4. 04

    Plan

    Actions and owners.

Regulatory basis

  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
  • National Cybersecurity Reference Framework of the CNCS;
  • Article 32 GDPR, on security of processing.

Expected results

  • A measured, comparable baseline;
  • Reasoned priorities;
  • Investment directed at real risk.

Ecosystem links

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.