Security Officer
Frequently Asked Questions
Direct answers to the most frequent questions.
Questions
Frequently asked questions
Is appointing a Security Officer mandatory in Portugal?
There is generally no rule requiring it. What is mandatory is the outcome: security measures appropriate to the risk and the ability to demonstrate them. In entities covered by the Portuguese Cybersecurity Act there is a regulated role, covered at cybersecurityofficer.pt.
What is the difference between the Security Officer and the data protection officer?
The data protection officer deals with the processing of personal data, advising on and monitoring GDPR compliance. The Security Officer deals with the security of all information, including information that is not personal. The roles work together but do not replace one another.
Can the same person hold both roles?
In small organisations this is common and acceptable, provided there is no conflict of interests and the person has the time and competences for both. A conflict arises, for example, when whoever decides on the systems is also the person meant to monitor those decisions.
Is ISO/IEC 27001 certification worth it?
It depends on the market. When clients or tenders require it, certification stops being optional and becomes a condition of access. Otherwise, the value lies in the management system, which can be implemented without certification.
Where to start, with a limited budget?
With the maturity assessment and the risk assessment. They are the only way of ensuring the available budget goes where it reduces most risk, and they produce the argument the board needs in order to decide.
Why is the website also in English?
Because many Portuguese organisations answer security questionnaires and audits from international clients, and the discussion about resources and priorities often takes place in English.
Security that is not measured is not managed
Start with a maturity assessment or ask for a proposal to structure the role.