Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To make a yearly plan:
The CISO should make his own plan, implement it in the company,  check internal (f.i. business) external (f.i. law) changes, check compliancy and make a plan for the next year to implement findings out of the evaluation.  Part of the yearly plan will be quarterly or monthly plansactivities.

1.1 Security Improvement Activities

...

DepartmentAreaRecurrenceNext Date

Status*

AccountingLogical Accessquarterly11 November 2017Planned
HR systemLogical Accessquarterly

DatacenterPhysical Access2/year

Quality ManagementRisk registerquarterly

Quality managamentRisk acceptance (system owner/senior management)2/year

Quality managementASecurity Security management systemannual

1.3 Awareness and Security training

Department/roleTraining/AwarenessDate

Status

AllHow to detect phishing4 October 2017Completed
AllNewsletter/blog on actual eventsMonthly
All or targeted groupsPhishing testbi-monthly
New employeesInitial security training/onboardingmonthly

1.4 Internal Audit

DepartmentType of AuditDue date

Status

H.R.Questionaire18 april 2018Planned




...