1. ISMS Governance & Leadership
- Establish, implement, maintain, and continually improve the ISMS
- Define information security policies and standards
- Ensure integration of ISMS into organisational processes
2. Risk Management
- Identify, assess, and manage information security risks
- Define risk appetite in consultation with senior management
- Maintain the risk register and ensure timely risk treatment
- Update the information security risk posture to the Information Security Committee
3. Compliance & Regulatory Oversight
- Ensure compliance with applicable laws, regulations, and standards
- Drive compliance certification and surveillance audits
- Coordinate internal and external audits
- Conduct vulnerability assessment and penetration testing, and ensure remediation of identified vulnerabilities.
- Ensure third-party/vendor security compliance
4. Security Architecture & Controls
- Define and enforce security architecture across IT and business systems
- Ensure implementation of appropriate information security controls
5. Incident Management
- Establish and maintain an incident response framework
- Lead response to major security incidents and breaches
- Ensure root cause analysis and corrective actions
- Report significant incidents to leadership and the Information Security Committee
6. Security Operations
- Oversight Security Operations Center(SOC) operations
- Monitor threats, vulnerabilities, and security events
- Ensure timely detection and response to threats
7. Business Continuity & Resilience
- Align with Business Continuity Management (BCM) and Disaster Recovery (DR) standards and build cybersecurity resilience into the Business Continuity Management System (BCMS) process
- Participate in crisis management
8. Security Awareness & Training
- Develop organisation-wide security awareness programs
- Ensure employees understand security policies and responsibilities
- Promote security culture
9. Third-Party & Supply Chain Security
- Assess and manage vendor/security risks
- Ensure contractual security requirements are defined and enforced
- Conduct vendor audits and reviews
10. Reporting & committees Engagement
- Provide regular updates to committees on:
- Information Security posture
- Information security Risk exposure
- Security Incident Trends
- Information security Compliance status
- Alignment of security risks with business operations
11. Budget & Resource Management
- Develop and manage a cybersecurity budget
- Optimise investments in security tools and resources
- Ensure cost-effective risk mitigation