{"id":4442,"date":"2014-12-01T20:21:41","date_gmt":"2014-12-01T20:21:41","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/27001academy\/blog\/014\/12\/01\/who-should-be-your-project-manager-for-iso-27001-iso-22301\/"},"modified":"2024-12-21T15:08:00","modified_gmt":"2024-12-21T15:08:00","slug":"who-should-be-your-project-manager-for-iso-27001-iso-22301","status":"publish","type":"post","link":"https:\/\/staging.advisera.com\/27001academy\/blog\/2014\/12\/01\/who-should-be-your-project-manager-for-iso-27001-iso-22301\/","title":{"rendered":"Who should be your project manager for ISO 27001\/ISO 22301?"},"content":{"rendered":"<p>If you\u2019re planning to start your ISO 27001 and\/or ISO 22301 project, you\u2019re probably wondering who could lead such a complex project \u2013 what type of person do you need, with which authorities, and should you go with someone in-house or someone from the outside?<\/p>\n<p>First of all, don\u2019t even think of starting to implement these standards without a project approach \u2013 to succeed, you need a project manager, project sponsor, clearly defined milestones and deadlines, etc. See also: <a title=\"ISO 27001 project \u2013 How to make it work\" href=\"https:\/\/staging.advisera.com\/27001academy\/knowledgebase\/iso-27001-implementation-checklist\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 27001 project \u2013 How to make it work<\/a>.<\/p>\n<h2>Profile of the project manager<\/h2>\n<p>Since <a title=\"ISO 27001\" href=\"https:\/\/staging.advisera.com\/27001academy\/what-is-iso-27001\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 27001<\/a>\u00a0and <a title=\"ISO 22301\" href=\"https:\/\/staging.advisera.com\/27001academy\/what-is-iso-22301\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 22301<\/a>\u00a0are closely related to information technology, the project manager should have at least average knowledge of IT; however, this project should not be treated as an IT project, so you should avoid having someone from your IT department lead this kind of a project. See also:\u00a0<a title=\"5 greatest myths about ISO 27001\" href=\"https:\/\/staging.advisera.com\/27001academy\/blog\/2011\/01\/24\/5-greatest-myths-about-iso-27001\/\" target=\"_blank\" rel=\"noopener noreferrer\">5 greatest myths about ISO 27001<\/a>.<\/p>\n<p>What you need is someone with a balanced knowledge of IT and of your company\u2019s business processes, because managing information security is, in most cases, related to organizational issues (developing policies and procedures, defining responsibilities and change management), not the technology.<\/p>\n<p>Since the manager of these kinds of projects will often run into opposition from some of their colleagues, such person should have enough authority either by position or by respect from his\/her peers.<\/p>\n<p>Once this project is over, this person is the most likely candidate to become your Chief Information Security Officer (CISO) or Business continuity manager. For smaller companies, you will usually have one position that covers both information security and business continuity, while in larger companies these functions will be separate \u2013 although very often in the same department. See also: <a title=\"Chief Information Security Officer (CISO) \u2013 where does he belong in an org chart?\" href=\"https:\/\/staging.advisera.com\/27001academy\/blog\/2012\/09\/11\/chief-information-security-officer-ciso-where-does-he-belong-in-an-org-chart\/\" target=\"_blank\" rel=\"noopener noreferrer\">Chief Information Security Officer (CISO) \u2013 where does he belong in an org chart?<\/a><br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><\/p>\n<h2>Needed skills &amp; availability<\/h2>\n<p>It would be perfect if your project manager had experience with ISO 27001\/ISO 22301 implementation, but you\u2019ll find these kinds of people very rarely.<\/p>\n<p>In most cases, this person will obtain these skills by attending courses \u2013 the best are Lead auditor and Lead implementer courses. Learn more here: <a title=\"Lead Auditor Course vs. Lead Implementer Course \u2013 Which one to go for?\" href=\"https:\/\/staging.advisera.com\/27001academy\/blog\/2014\/06\/16\/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for\/\" target=\"_blank\" rel=\"noopener noreferrer\">Lead Auditor Course vs. Lead Implementer Course \u2013 Which one to go for?<\/a><\/p>\n<p>Regarding the time needed, for a smaller company the project manager will need to spend about 1 or 2 hours per day for this kind of a project; for a company with a couple of thousand employees, this kind of a project will consume this person 100% of the time throughout the project duration. See also this\u00a0<a title=\"Implementation Duration Calculator\" href=\"https:\/\/staging.advisera.com\/27001academy\/free-tools\/free-calculator-duration-of-iso-27001-iso-22301-implementation\/\" target=\"_blank\" rel=\"noopener noreferrer\">Implementation Duration Calculator<\/a>.<\/p>\n<h2>In-house or outsource?<\/h2>\n<p>There is no doubt about it \u2013 the project manager must be someone from inside your company \u2013 this is necessary because an outsider cannot know all the details and the cultural issues in your company.\u00a0 When things get tough (which they certainly will during this kind of a project), you need someone who will know who to turn to, which kind of approach to other employees will be accepted, and what to avoid.<\/p>\n<p>Don\u2019t get me wrong \u2013 you should get some external help in order to get the know-how, but a consultant cannot lead your project. See also: <a title=\"5 criteria for choosing an ISO 22301 \/ ISO 27001 consultant\" href=\"https:\/\/staging.advisera.com\/27001academy\/blog\/2013\/03\/25\/5-criteria-for-choosing-a-iso-22301-iso-27001-consultant\/\" target=\"_blank\" rel=\"noopener noreferrer\">5 criteria for choosing an ISO 22301 \/ ISO 27001 consultant<\/a>.<\/p>\n<h2>Which kind of authority?<\/h2>\n<p>This is probably the toughest question \u2013 on one hand, the project manager only has a temporary job, and on the other hand, he has to change how things are done in your company. So theoretically speaking, this person should have a formal authority to implement any change necessary as part of this project.<\/p>\n<p>But, in reality, the following two characteristics will be much more important than the formal authority:<\/p>\n<p style=\"padding-left: 10px;\">1) How well the project manager gets along with the project sponsor \u2013 because whenever the project manager hits a wall, it will be the sponsor who will provide him with a way to remove this wall.<\/p>\n<p style=\"padding-left: 10px;\">2) The level of \u201cdiplomatic\u201d skills of the project manager \u2013 since the project sponsor won\u2019t get into every detail, the project manager will need to find ways to bypass this wall.<\/p>\n<p>So, the point is \u2013 the project manager is a central figure in your implementation, and the success of your project depends much more on this person than you might think. So, to succeed, find a capable person, provide him with the required skills, and give him a good sponsor. The alternative is to have one of those never-ending projects.<\/p>\n<p><em>To implement ISO 27001 &amp; ISO 22301 easily and efficiently, use our <\/em><a href=\"https:\/\/staging.advisera.com\/27001academy\/iso-27001-22301-premium-documentation-toolkit\/\" target=\"_blank\" rel=\"noopener\">ISO 27001 &amp; ISO 22301 Premium Documentation Toolkit<\/a><em> that provides step-by-step guidance and all documents for full ISO 27001 &amp; ISO 22301 compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you\u2019re planning to start your ISO 27001 and\/or ISO 22301 project, you\u2019re probably wondering who could lead such a complex project \u2013 what type of person do you need, with which authorities, and should you go with someone in-house or someone from the outside? First of all, don\u2019t even think of starting to implement &#8230;<\/p>\n","protected":false},"author":26,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[136,380,381,500,501],"class_list":["post-4442","post","type-post","status-publish","format-standard","hentry","category-blog","tag-consulting","tag-iso-22301","tag-iso-27001","tag-ciso","tag-project-planning"],"acf":[],"_links":{"self":[{"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/4442","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/comments?post=4442"}],"version-history":[{"count":1,"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/4442\/revisions"}],"predecessor-version":[{"id":103289,"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/4442\/revisions\/103289"}],"wp:attachment":[{"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/media?parent=4442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/categories?post=4442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.advisera.com\/27001academy\/wp-json\/wp\/v2\/tags?post=4442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}