Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Services›External CISO
Services

External CISO

Measure 1 of Annex II requires a named responsible person who sets direction, reports to the board and secures resources. For most organisations a permanent hire at that level is not justified, and the obligation remains.

Leadership and oversight of the security programme

How we work

01Strategy and policy
Setting direction, drafting the cyber security policy and having it adopted by the board.
02Risk management
Maintaining the risk register, defining risk appetite and investment priorities.
03Reporting to the board
Regular status, trend and open issues, in language the board understands.
04Running the compliance programme
Tracking deadlines, owners and evidence for each measure, through to verification.
05Incident response
Leadership during an incident and the decision on significance and notification to the competent CSIRT.

What you get

Named responsible person
Policy and strategy
Risk register
Board reporting
Compliance roadmap

Measures of Annex II this service covers

01 Commitment and accountability of those responsible for implementing cyber risk management measures 03 Risk management 11 Incident handling

Sectors where it is most in demand

Check for yourself before we talk

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.