Presentation given by Georgia at the Service Design and Delivery in a Digital Age - Academies for EaP countries organised by the SIGMA Programme and the GiZ Eastern Partnership Regional Fund. Topic 3: Quality management systems and quality culture.
2. Information Security in Georgia
Digital Governance Agency
Anna Metreveli
Certified Lead Implementer | Auditor of ISMS
Consultant of ISO 27001 | ISO 22301 | ISO 20000-1 | ISO 9001 |
NIST | Risk Management | ITIL
LEPL Digital Governance Agency
Ministry of Justice of Georgia
Tbilisi, Georgia, 2023
3. ISACA CISM
ISACA CISA
ISO 27001 Lead Auditor/Lead Implementer
ISO 22301 Lead Auditor/Lead Implementer
ISO 9001 Lead Auditor/Lead Implementer
ISO 20000-1 Lead Implementer
ISO 31000
SANS GIAC - Global Information Security Fundamentals (GISF)
ITIL Foundation for IT Service Management
Solid experience in the ICT & IS fields
Proficiency of IS Team
4. There are three categories of subjects of critical information system (109 Organizations)
71 - Government organizations
8 - Subjects of the
telecommunication field
30 - Private sector
The new amendment made in 2022 of the law is based on international standards and experience
Methodology of identifying critical information system subjects
Law of Georgia on Information Security
6. ISO 27001 By BSI/TÜV/PECB
CISA/CISM By ISACA
SANS By GIAC (Global Information Assurance Certification)
CISSP By (ISC)²
Certified Information Security Manager By DGA
IS Manager Requirements
7. Authorization of
ISMS auditors
Certification for IS
Managers
ISMS
Monitoring/Audit
Outsourcing of
ISMS Audit
ISMS
Implementation
Outsourcing
Outsourcing IS
Manager
ISMS Compliance
Preparation of
ISMS
Documentation
ISMS Trainings
IS Department Duties
8. • Ministry of Justice of Georgia
• National Archives of Georgia
• Legislative Herald of Georgia
• National Bureau of Enforcement
4 ongoing projects with
the first category
critical information
system subjects
Ongoing Projects of ISMS Implementation
9. Trainings for subjects of
critical information
system
Trainings for any
interested parties
Activities to raise
awareness on IS in
different state and
public organizations
Trainings and awareness raising activities
10. To provide more up-to-date international trainings
for our team members.
To implement new version of the standard ISO
27001 in the law of Georgia on Information
Security.
To establish ISMS certification centre in
accordance with international standards.
Our Objectives