Xcina Case Study

ISO 27001 Internal Audit and Virtual CISO

Strategic Partner Supporting Capital Markets Trader with Compliance Requirements

The Challenge

The organisation provides a digital ecosystem for managing complex documentation associated with listings and the ongoing compliance of securities in capital markets. Their technology digitises pre-trading and post-trading processes in the issuance of securities using structured content and data.

Highlights and key components of the engagement

Xcina Consulting was engaged as a strategic partner supporting the organisation’s ISO 27001 compliance requirements.  

 

Methodology and Approach

Our role was to:

  • Provide virtual CISO (vCISO) services and act as the organisation’s Information Security Officer
  • Review and update the ISO 27001 three-year Audit Programme as well as the Annual Audit Plan
  • Review and update the ISO 27001 supporting artefacts ensuring compliance with standard requirements
  • Prepare the relevant audit documentation (workpapers) in line with the Audit Manual and quality expectations
  • Conduct an annual internal audit of the ISMS in compliance with the standard requirements
  • Discuss audit findings throughout the audit to ensure no surprises in the draft audit report
  • Draft the audit report in the “house style” and discuss it with the auditees, ensuring that all feedback is considered in the final report.
  • Identify nonconformities and opportunities for improvement, and provide recommendations to address findings
  • Work with top management to prioritise remediation of identified nonconformities
  • Update the Corrective Action Plan worksheet with identified nonconformities to be remediated.

 

Results and Outcome

Over a duration of several months, Xcina consultants fulfilled the role of Chief Information Security Officer for the client. This period covered the transition of the client’s information security management system from the older (2013) version of the ISO 27001 standard to the current (2022) version. Xcina supported this transition, and the client recently successfully completed a formal transition certification audit to the new version with their external certifying body. Xcina is currently conducting an internal audit against ISO 27001:2022 for the client, ahead of next year’s external formal ISMS audit.

What This Means for You

Whether you are at an early stage of your Cyber Maturity journey or looking for continuous improvement, Xcina delivers:

  • Independent benchmarking assessments against leading cyber maturity frameworks such as NIST, CAF, ISO27001, NIS2, DORA and TSA, identifying areas for improvement
  • Expert advice on complex security, resilience and certification issues and best practices
  • Pragmatic implementation assistance to help strengthen your security and resilience posture
  • A long-term partnership and ongoing assistance throughout your journey, not just a point-in-time assessment

 

To find out more about how we can assist you, please refer to our Information Governance Consultancy Services at https://xcinaconsulting.com/services/information-governance/

 

 

 

Industry and sector:

Financial

Solutions and service area:

Xcina’s objective:

Xcina Consulting was engaged as a strategic partner to support the organisation’s ISO 270001 compliance requirements

We’d love to hear from you

We have a strong track record in providing risk advisory services with a focus on governance, regulatory compliance, conduct and culture, data protection, and third-party assurance. We help organisations successfully address governance, risk management and compliance challenges.

To discuss how the areas highlighted in this case study, or any other aspect of risk management, information governance or compliance impact your business, speak with our team, tell us what matters to you and find out how we can help you navigate complex issues to help you deliver long term value.

If you have any questions or comments, or if there’s anything you would like to see covered, please get in touch by emailing Xcina Consulting at info@xcinaconsulting.com. We’d love to hear from you.

Lindsey Domingo

Senior Director

Speak to me directly by Email, or
Telephone: +44 (0)203 745 7826

Lindsey Domingo

Subscribe to Updates

Receive regular updates from our expert consultants as they provide clarification and guidance on issues impacting your organisation.

Subscribe >>