Information Security Roles Responsibilities, Procedures, and Authorities
The responsibilities of overseeing our information security processes falls directly to the owners of Vertic Pty Ltd, Jan Tenenberg, Stephen Kent, and Matt Romeo. We have broken up these responsibilities using the following high-level structures:
Jan Tenenberg (Information Security Manager) to:
Oversee the overall quality assurance processes defined within the ISO 27001 standards and guidelines
Set up the systems and processes to support the information security processes required to service Vertic’s clients
Stephen Kent (Internal Information Security Auditor) to:
Clearly define the scope of an implementation and the responsibilities of Vertic’s clients
Clearly define all relevant implementation assumptions to impact the implementation of Vertic’s services
Matt Romeo (Information Security Admin) to:
Oversee the technical outsourcing team and the required controls to ensure information is managed securely
Implement the relevant technologies to effectively communicate with our technical outsourcing team
Internal Incident Procedure
Should an internal incident occur that requires documentation and action, the following process is to be followed:
Use Vertic’s Salesforce environment to log a
Case
with the following minimum details:Case Name
Date
Impact
Priority
Urgency
Key Contact
Vertic’s Information Security Team (as detailed above) will take action as appropriate
All ongoing communications for the particular case will be managed within Salesforce and related to the case.
An example case can be seen here: .
All other relevant information is described within the ISMS-DOC-05-2 Information Security Roles Responsibilities and Authorities
document.