moving on to module three
during this module will be going through close five
leadership and its commitment and its role in the ice mess
Almost nothing is large scale as an ice mess is possible without the support and commitment, as well as the financial backing off top management.
That's probably why I sold 27,001 dedicates the whole claws just to leadership.
We're now starting with Clause five
in less than 3.1 is specific to close 5.1 leadership and commitment.
So why is top management commitment important?
I'm pretty sure we all know this one.
It's a pretty standard y. Across most information security initiatives,
programs and governance are always more successful when the tone is set at the top and the culture is fed through the entire organization
a bit of a lead by example.
There are many reasons, and the most pertinent ones are highlighted in the standard itself.
Firstly, top management sets the tone of the top and is a key role player in bringing the whole organization on board.
Top management is also key to ensure that the objectives of the ice mess aligned to the overall business, strategic objectives and direction.
But what if top management doesn't see the benefit?
How does one convince them to buy into the ice mess and throw their full weight of support behind it?
While there might not be a clear cut answer to this one, there is one tool that can certainly help to show top management all the ins and outs pertaining to your eyes on this journey.
Specifically the benefits and any return on investment that will be realized.
I'm talking about a business case, and we'll get to that in the next couple of slides.
So how does top management commitment? How is it demonstrated? What sort of proof
can one have to show top management is behind your ice, Miss
I said 27,001 provides eight specific points on how top management
should be demonstrated within an organization
during sorry during your order, the orderto will most likely interview a number of top management representatives to gauge their understanding off the ice mess. It's progress of implementation within the organization,
and what the top risks are that the system is is managing.
These are only some of the questions I could ask,
and each order to would have their own way of asking questions and assessing the level of top management commitment.
Unfortunately, there are many organizations that treat activities such as implementing an icy mess or obtaining an eye. So 27,001 certification
as a check box exercise.
This approach often appears as quite see through during an audit.
The culture mindset and commitment must be visible visibly demonstrate able
even though this section is pertinent to top management, the same applies for all personnel within your organization.
Top management needs to help ensure alignment between your information security objectives
and the organization. Strategic objectives.
Top management also is key to ensuring integration of the ice messed requirements into business processes,
ensuring that the required re sources are made available. Whether this is financial technology, resource, whatever it may be,
top management is also a key role player when it comes to communicating the importance of information security
management and demonstrating conformance to the requirements of the items.
Top management plays a key role in ensuring that the intended outcomes of the ice miss are achieved.
Top management needs to provide direction and support to the team's contributing to the effectiveness of the ice. Miss
Top management is a key role player to actively promote continual improvement.
Top management also would need to provide support to other management roles to demonstrate their leadership
relevant to the ice miss in their areas.
That's quite a lot that top management is involved in.
So what documentation can one used to further prove the
involvement off top management or their commitment to the ISS? Miss,
when you go through your certification ordered, there are a couple of documents that the order to would want to view
to ensure the top management is as committed as you say they are.
Some of these documents can include budgets for ice, miss activities,
meeting minutes and attendance registers for ice melts, related discussions, workshops,
approval of various supporting documents and policies,
evidence of participation and risk management and assessment workshops,
official communication to the organization from top management pertaining to the items.
While this documentation is not specifically listed as mandatory, it is beneficial to the order process,
especially if you're in tangible evidence of top management being involved.
The mandatory information that is required
is the information security policy and the Ice Miss manual
in some cases thes air one document. But I prefer to keep these separate.
These will be covered in the following section in a bit more detail.
In those documents, there is a mandatory section pertaining to top management,
specifically their commitment
that pertains directly to a statement from top management, which formally depicts in writing
the management commitment to the achievement of the ice miss objectives
as well as to continually improve on the ice mess
in conjunction with the overall security posture of the organization.
Earlier, we mentioned a business case and how this can be beneficial to bringing top management on board with your eyes miss
and gaining their commitment.
Fantastic resource that one can use
There is also an online resource
known as the I saw 27,001 Forum,
which is dedicated dishing information Resource is relating to ISO 27,001.
They have an example of a business case template in there. I so 27,001 Talk it.
Some of the items that you can include in your business case have been included. Yeah,
make sure your business case outlines the benefits of the ice mess,
which can include information security, risk reduction,
streamlining and securing off processes to leverage cost saving,
as well as providing trust to clients and stakeholders, which increases your brand value.
I like the cost of the isthmus.
Top management will want to know all the costs involved,
whether it's costs of bringing auditors involved.
Internal costs of resource time.
Whether or not additional tools, software or re sources are required
include a section on the return on investment.
A nice um s will yield some sort of benefit to your organization.
It is an important Thio quantify and frame this out for top management, so they understand that
any costs invested into this process will have some sort of yield long term
In this video we covered white top management commitment is important for the success of the Smiths and certification.
We also looked at ways in which top management can demonstrate their commitment.
We covered the documents that are required by the standard
and that this can prove top management commitment to an auditor.
We also briefly covered how a business case can help solve your ice means to top management
and bring them on board more easily.