Information Security
Skill packages tagged with “Information Security”
ISMS Internal Audit Report (Clause 9.2)
Plan and execute ISO 27001 internal audits: create audit plans with sampling strategies, draft structured audit reports with findings mapped to clauses, validate finding completeness (severity, evidence, clause, CAPA), classify finding severity, and verify auditor impartiality.
ISO 20000 Information Security Management
Establish information security management for the SMS per ISO/IEC 20000-1:2011 Clause 6.6. Defines the information security policy, identifies security controls mapped to services, establishes security incident management, and documents ISO 27001 alignment. Validates the security controls register for domain coverage and service mapping.
ISO 27001 Risk Assessment
Complete ISO 27001:2022 risk assessment workflow covering methodology definition, risk identification using a 12-category threat taxonomy, risk analysis with 5×5 matrix scoring, treatment planning with Annex A control mapping, and residual risk validation. Produces auditor-ready risk methodology, risk register, treatment plan, and acceptance forms per Clause 6.1.2 and 6.1.3.