The reason for change.
Within an organisation with several operating companies, projects and cooperation partners, documents and processes were initially separate. Clients increasingly asked for demonstrable information security, while the coherence and connection to ISO 27001 were still lacking.
Software, structure and guidance.
De Compliance Afdeling started with the organization itself: objectives, working methods, client requirements and existing information. Risk analyses, policy documents and responsibilities were then set up. The Compliance Tool became the central place for policies, risk assessments, measures, tasks and evidence.
What changed in practice.
- Processes and responsibilities are structured.
- Information is less dependent on individual employees.
- Audit preparation requires less searching and gives more certainty.
- Compliance remains part of a continuous cycle.
We go into audits with much more certainty, because we know where everything is and who is responsible for it.Richard van Breugel · Coordinator ICT
