The Profile menu, located under the Dashboard menu, provides access to the organizational context of your company within CSFaaS.

This module is designed to meet the requirements of ISO 27001 Annex A 4.1 and A 4.2, by defining the organization’s identity, interested parties, and compliance environment. It centralizes the essential elements that describe who your organization is, how it operates, and under which legal, regulatory, and governance frameworks it functions.


Module Description: Organizational Context

The Profile module captures structured and traceable information about your organization. It ensures that all contextual data relevant to your Information Security Management System (ISMS) is documented, consistent, and continuously updated.

Each section within this module is fully customizable, allowing you to adapt the structure and fields to your organization’s specific requirements or compliance scope.

  1. General Company Information

    This section consolidates the organization’s core administrative and legal details, including:

    • Legal Name and Trade Name
    • Head Office Address and Jurisdiction Country
    • Legal Entity Type, Registration Number, and Date of Incorporation

    These fields ensure traceability and compliance with legal identification requirements.

  2. This subsection allows defining one or more authorized legal representatives with clearly specified attributes:

    • Full Name, Title/Role, and Scope of Authority
    • Contact Email (optional)
    • Signature Rights (Sole, Joint, or Per Category)
    • Start and End Dates of authority validity
    • Evidence Links to official documents (e.g., company statutes or appointment letter)

    This structure ensures that corporate authority and responsibilities are properly documented and verifiable.

  3. Contact Points

    Centralizes the main points of contact within the organization. Predefined roles include:

    • Security Officer (CISO)
    • Compliance Officer
    • Data Protection Officer (DPO)
    • Primary Operational Contact

    Each contact includes a name and email address, ensuring quick and transparent communication channels.

  4. Company Background & Mission

    Captures the business and strategic identity of the organization:

    • Business Description — summary of activities, products, and services
    • Target Markets / Customers — identification of key sectors (B2B, B2C, etc.)
    • Company Size and Estimated Revenue Range
    • Applicable Regulations — main laws and standards affecting the organization

    This section helps contextualize the organization’s risk environment and operational scope.

  5. Organizational & IT Structure

    Describes how the organization and its IT systems are structured:

    • Organization Chart — optional upload or link for visual clarity
    • Hosting Model — Cloud, On-Premises, or Hybrid
    • Primary IT Providers — imported from the Third-Party module
    • Data Locations — countries or regions where data is stored or processed

    These details support compliance with data protection and sovereignty regulations.

  6. Security & Compliance

    Documents the organization’s adherence to recognized standards and practices:

    • Obtained Certifications — e.g., ISO 27001, SOC 2
    • Followed Standards — ISO, NIST, CIS, etc.
    • Information Security Policy (ISP) — available document or link
    • Date of Last Security Audit — to track review cadence

    This section supports evidence-based security governance.

  7. Acts as a centralized evidence repository for official company records:

    • Registration certificates
    • Legal or contractual documentation
    • Compliance and insurance attestations
    • Other supporting evidence

    Each file can be linked directly to relevant controls or framework requirements.

Purpose

The Profile Menu ensures that your organization’s contextual information is:

  • Structured and complete for compliance and audits
  • Linked to your ISMS and security framework mapping
  • Easily updatable for ongoing governance activities

It forms the foundation upon which all risk, control, and policy management modules in CSFaaS are contextualized.