{"id":1718,"date":"2018-12-02T12:42:22","date_gmt":"2018-12-02T12:42:22","guid":{"rendered":"https:\/\/iso27001.solutions\/?p=1718"},"modified":"2019-03-11T17:59:15","modified_gmt":"2019-03-11T17:59:15","slug":"what-is-the-job-of-chief-information-security-officer-ciso","status":"publish","type":"post","link":"https:\/\/ismsalliance.com\/trends\/iso-27001-implementation\/what-is-the-job-of-chief-information-security-officer-ciso\/","title":{"rendered":"What is the job of Chief Information Security Officer (CISO)"},"content":{"rendered":"

The CISO in ISO 27001<\/h2>\n

ISO 27001<\/strong> does not require a company to nominate a Chief Information Security Officer (CISO)<\/strong>, or any other person who would coordinate information security (e.g., Information security officer, Security manager, etc.).<\/p>\n

However, ISO 27001<\/a> is written in such a way that it is applicable to companies of any size, in any industry, so requiring small companies to have a designated CISO would be overkill.<\/p>\n<\/div>

<\/div>
<\/div>
<\/div>
<\/div><\/div><\/div><\/div><\/div>
<\/a><\/span><\/div><\/div>
<\/div><\/div><\/div><\/div><\/div>
<\/div>
<\/div>
<\/div>

What does the CISO do ?<\/h2>\n<\/div>
<\/div>
<\/div><\/div>
<\/div>

Since ISO 27001 does not require the CISO, it does not prescribe what this person should do, either \u2013 so it is up to you to decide what suits your company the best. Generally, this person should coordinate all the activities related to securing the information in a company, and here are some ideas on what this person could do (divided by ISO 27001 sections):<\/p>\n

Compliance:<\/h3>\n