Development of an ISMS
Coordinate, create and revise the security policies and related sub- concepts based on the context of the country or country region
Implementing, coordinating, and continuously improving the local information security management system (ISMS) based on the ISMS country project plans
Implementation of measures
Planning and coordinating the implementation of information security measures in close alignment with management level and key stakeholders such as e.g., HQ- ISMT (Information Security Management Team), IT Department, central Data Protection Team, and Digitalization Partner, local Security Risk Management Officer (SRMO) and projects
Monitor the effectiveness of the information security program and make recommendations for improvements to the departments of the country office
Support and maintain incident management
Support in the implementation and coordination of security- relevant processes
Advising and reporting to management
Reporting of security risks and issues to local management and HQ/CISO
Reporting on the local information security management system (ISMS) performance to local management level and HQ/ Chief Information Security Officer (CISO)
Advising the local management and HQ/CISO how audit findings should be implemented
Internal audits and support on external audits
Prepare and support the continuous improvement through the certification and surveillance audit
Contact person for all internal and external non- conformities in audits
Develop an internal audit plan based on the audit program from HQ/ISMT
Support and conduct internal audits for the implementation of applicable security control objectives
Awareness and central contact person
Initiation and implementation of awareness- raising measures for information security in consultation with various stakeholders (such as IT professionals and local digitization partners)
Provide guidance and support to employees on information security best practices
Close interaction and communication to Headquarter ISM- Operations and relevant stakeholders