The Profile menu, located under the Dashboard menu, provides access to the organizational context of your company within CSFaaS.
This module is designed to meet the requirements of ISO 27001 Annex A 4.1 and A 4.2, by defining the organization’s identity, interested parties, and compliance environment. It centralizes the essential elements that describe who your organization is, how it operates, and under which legal, regulatory, and governance frameworks it functions.
Module Description: Organizational Context
The Profile module captures structured and traceable information about your organization. It ensures that all contextual data relevant to your Information Security Management System (ISMS) is documented, consistent, and continuously updated.
Each section within this module is fully customizable, allowing you to adapt the structure and fields to your organization’s specific requirements or compliance scope.
-
General Company Information
This section consolidates the organization’s core administrative and legal details, including:
- Legal Name and Trade Name
- Head Office Address and Jurisdiction Country
- Legal Entity Type, Registration Number, and Date of Incorporation
These fields ensure traceability and compliance with legal identification requirements.
-
Legal Representative
This subsection allows defining one or more authorized legal representatives with clearly specified attributes:
- Full Name, Title/Role, and Scope of Authority
- Contact Email (optional)
- Signature Rights (Sole, Joint, or Per Category)
- Start and End Dates of authority validity
- Evidence Links to official documents (e.g., company statutes or appointment letter)
This structure ensures that corporate authority and responsibilities are properly documented and verifiable.
-
Contact Points
Centralizes the main points of contact within the organization. Predefined roles include:
- Security Officer (CISO)
- Compliance Officer
- Data Protection Officer (DPO)
- Primary Operational Contact
Each contact includes a name and email address, ensuring quick and transparent communication channels.
-
Company Background & Mission
Captures the business and strategic identity of the organization:
- Business Description — summary of activities, products, and services
- Target Markets / Customers — identification of key sectors (B2B, B2C, etc.)
- Company Size and Estimated Revenue Range
- Applicable Regulations — main laws and standards affecting the organization
This section helps contextualize the organization’s risk environment and operational scope.
-
Organizational & IT Structure
Describes how the organization and its IT systems are structured:
- Organization Chart — optional upload or link for visual clarity
- Hosting Model — Cloud, On-Premises, or Hybrid
- Primary IT Providers — imported from the Third-Party module
- Data Locations — countries or regions where data is stored or processed
These details support compliance with data protection and sovereignty regulations.
-
Security & Compliance
Documents the organization’s adherence to recognized standards and practices:
- Obtained Certifications — e.g., ISO 27001, SOC 2
- Followed Standards — ISO, NIST, CIS, etc.
- Information Security Policy (ISP) — available document or link
- Date of Last Security Audit — to track review cadence
This section supports evidence-based security governance.
-
Legal Documents
Acts as a centralized evidence repository for official company records:
- Registration certificates
- Legal or contractual documentation
- Compliance and insurance attestations
- Other supporting evidence
Each file can be linked directly to relevant controls or framework requirements.
Purpose
The Profile Menu ensures that your organization’s contextual information is:
- Structured and complete for compliance and audits
- Linked to your ISMS and security framework mapping
- Easily updatable for ongoing governance activities
It forms the foundation upon which all risk, control, and policy management modules in CSFaaS are contextualized.