Who uses it
It suits any organisation that works online, above all banks and mobile money providers.
How it is applied
- Current defences are assessed against the guidance and known threats.
- Roles, policies and incident response are agreed.
- Technical controls such as access control and monitoring are put in place.
- Staff are trained and response plans are tested.
Cost drivers
The number of systems, users and online services drives the cost. Monitoring tools and outside testing add to it.
Timeline
A first programme usually runs over several months. The work then continues as systems and threats change.
Certification
No certificate is issued for this area alone. Organisations usually seek ISO/IEC 27001 certification to show that security is managed.


