NTTManager, Business Continuity, ISMS/Compliance/ISO 27001 and Risk Management
Jan. 2015 - Oct. 2023Massachusetts, United States● Business Continuity o Built BC program with full operational capabilities o ISO 22301 as framework for policy, program, plan, testing o Fostered ownership through business with BIA exercises, development of different team’s DR plans o Test simulation exercises, raising awareness, increasing preparedness, creating opportunities for improvement. Test Tier 1 applications plans o Roadmap for evolution of BCM program, and ever closer working with leaders o xMatters for mass communications including SMS, Email, Call invitations o Established, tested, fine-tuned call tree procedure o Developed process, criteria for initiating pre-event (severe storms, etc.) assessments ● ISMS/Compliance/ISO 27001 o Created, executed, maintained ISO 27001 certification processes and procedures. Evaluated scope periodically, wrote policy, reviewed applications, built metrics, reporting, roadmap. Prepared for and hosted audits. Responded to client information requests o Decreased time needed of resources in audits by 25%, using Excel-driven Statement of Applicability tool o Awareness training for all staff annually and new employees when onboarding o Reduced number of audit findings by 50% over 8 years o Supported Brazil region in successful certification of ISO 27001 o Worked with Chile region so they could be audited without need for self to be on-site reducing costs ● Risk Management o Risk management program based on ISO 27001; annual risk assessment, risk register, impact assessments, roadmap, project, vendor assessments o Established ownership, buy-in through steering committee and training o Worked with business leaders to identify, scope risks using Business Impact Analysis, Root Cause Identification, plans to correct the risk o Assessment and rating index (e.g. cost impact, client impact) o Metrics and reporting to show progress and proactively identified issues o Gave clients, vendors program overview, updates on risks where appropriate, responded to client requests