πŸ‘€ CISO

Automatically generated excerpt from nestr.io on 2026-08-28 15:55 UTC, view all live information here.

Circle (Delegator)

Role Keepers

Roland Ulrich

Purpose

VSHN operates an ISMS to ensure adherence to information security throughout the company. The CISO role holds the responsibility for managing this ISMS, aiming to integrate it seamlessly into the company’s processes rather than allowing it to remain a paper exercise.

The primary objective for VSHN is to deliver high quality services to customers. The CISO collaborates with the teams and roles to enhance the services within the scope of information security that is confidentiality, integrity, and availability (known as C-I-A triad). Additionally, the CISO ensures, in coordination with internal teams and roles that standards and policies are diligently adhered to.

Accountabilities (Key Responsibilities)

  • ISAE 3402 compliance and audit

  • Information security incident management

  • Information security awareness for VSHNeers to lower the risk of incidents

  • In practice compliance with defined ISMS policies

  • Information security risk assessment to continuously improve VSHN’s information security

  • Maintained Information Security Management System (ISMS) to remain ISO/IEC 27001 certified

Stakeholders and Key Deliverables

Customers (represented through Account Management)
  • ISO/IEC 27001 certificate they can refer to to be compliant.

  • ISAE 3402 report they can refer to to be compliant.

  • More detailed information about scope, assessed and controlled risks, etc.

  • Transparently addressed and documented incidents that affected them.

Teams, Roles and all VSHNeers
  • Point-of-contact and defined process to report information security incidents and transparently see how they are triaged and addressed.

  • Continuously train and educate VSHNeers in information security

Marketing and Sales
  • ISO/IEC 27001 certificate to show compliance

  • ISAE 3402 report to show compliance