fbpx

CIMSNex User Guides

Star InactiveStar InactiveStar InactiveStar InactiveStar Inactive

ISO 18788 Clause 6.2.2 outlines the requirements for establishing, implementing, and maintaining programs to achieve security operations and risk treatment objectives within the Security Operations Management System (SOMS). Here's an explanation of the key elements of this clause:

Clause 6.2.2 - Achieving Security Operations and Risk Treatment Objectives:

  1. Establishment of Programs: The organization is required to establish, implement, and maintain programs that are designed to achieve its security operations and risk treatment objectives. These programs should be tailored to control and treat risks associated with the organization's operations, subcontractors, and supply chain.

  2. Optimization and Prioritization: The programs should be optimized and prioritized based on the identified risks. This means that the organization should focus its resources on addressing the most critical and significant risks first.

  3. Formal and Documented Risk Treatment Process: The organization must establish, implement, and maintain a formal and documented risk treatment process. This process should consider various strategies for managing risks, including:

    • a) Removing the source of risk when possible.

    • b) Reducing the likelihood of an event and its consequences.

    • c) Mitigating harmful consequences.

    • d) Sharing the risk with other parties, including through risk insurance.

    • e) Spreading the risk across assets and functions.

    • f) Accepting the risk or pursuing opportunities through informed decision-making.

    • g) Avoiding or temporarily halting activities that pose a risk.

  4. Responsibility of Top Management: Top management is responsible for key aspects of the risk treatment process, including:

    • a) Assessing the benefits and costs of different risk treatment options to determine whether risks should be removed, reduced, or retained.

    • b) Evaluating the impact of security operations programs to identify any new risks introduced.

    • c) Periodically reviewing the risk treatment process to ensure it remains effective and reflects changes in the external environment, including legal, regulatory, and other requirements, as well as changes within the organization related to policies, facilities, information management systems, activities, functions, products, services, and the supply chain.

In summary, this clause emphasizes the need for structured programs to address security operations and risk treatment objectives effectively. It also underscores the importance of a documented risk treatment process that considers various strategies for managing risks. Top management plays a crucial role in assessing options, evaluating program impacts, and ensuring that risk treatment remains aligned with changing requirements and organizational developments.

 

Star InactiveStar InactiveStar InactiveStar InactiveStar Inactive

ISO 18788 Clause 7.1.2.2 focuses on the organizational structure of the Security Operations Management System (SOMS). It outlines the requirements for defining roles, responsibilities, authorities, and accountabilities within the organization's management structure. Here's an explanation of the key elements of this clause:

Clause 7.1.2.2 - Organizational Structure:

  1. Clearly Defined Management Structure: The organization is required to have a clearly defined management structure. This structure should identify roles, responsibilities, authorities, and accountabilities for both its operations and services related to security operations.

  2. Documentation of Organizational Structure: The organization must document its organizational structure, which includes details such as the duties, responsibilities, and authorities of management personnel. This documentation provides clarity and transparency within the organization.

  3. Legal Entity Definition: If the organization is a defined part of a legal entity (e.g., a subsidiary or division of a larger corporation), it should define and document this relationship. This includes clarifying how the organization fits into the legal entity's overall structure and governance.

  4. Joint Ventures and Partnering Arrangements: If there are any joint venture or partnering arrangements within the scope of the SOMS, these should be defined and documented. This ensures that the organization has a clear understanding of how such arrangements relate to its security operations.

In summary, this clause emphasizes the importance of having a well-defined organizational structure within the SOMS. By documenting roles, responsibilities, authorities, and accountabilities, the organization ensures that everyone understands their respective roles in security operations. Additionally, if the organization is part of a larger legal entity or has joint venture/partnering arrangements, these relationships should be clearly defined and documented to maintain transparency and governance.

 

Image
SIMPLIFYING IMPLEMENTATION OF ISO STANDARDS, providing specialized guidance through reliable Expert Knowledge and Software to help you obtain and maintain your ISO certification.
ISO Compliance Software
Integrate . Mantain . Comply

Search