Organisation: what you record here and why
Last checked on
The Organisation group describes the company your management system covers: what you do, what is in scope, who works for you and in which role, what you rely on, and who expects something from you.
Why this protects your organisation
Every later decision about risks and measures depends on knowing your own organisation. If nobody has written down which systems hold customer data, which supplier hosts them or who decides on access, a risk assessment turns into guesswork and an auditor has nothing to test against. This group is the foundation the rest of Trustbird builds on. In ISO 27001 it covers the context of chapter 4 and the roles of clause 5.3, together with the competence requirements of clause 7.2.
Steps
- Start with Organisation: describe what you do, where you work and what affects you.
- Set out the boundaries of your management system under Scope and establish it.
- Add the people who work for you under People, then group them in Teams and give them Roles.
- Record the competencies each role needs and check the gaps in the Competency overview.
- List the systems, devices and data you depend on under Assets, and who delivers them under Suppliers.
- Record under Interested parties who expects what from you.
- Ask the workspace owner to review the Task templates, so starters, leavers and new suppliers get the right follow-up.
The screens in this group describe your organisation in your own words. Trustbird links them to each other: people own assets and suppliers, roles carry competency requirements, and the scope you establish can be chosen when you adopt a standard.
- Organisation: what your organisation does and for whom, its locations and headcount, and the internal and external topics that affect it.
- Scope: what falls inside your management system, what falls outside it and why, and where your responsibility ends. You establish it, and changes go into a new version.
- People: everyone who works for you, with their employment type and status, their qualifications and the documents they confirmed.
- Teams: groups of people around a shared responsibility, each with an owner.
- Roles: the functions in your organisation, with their responsibilities and authorities, the people who hold them and the competencies they need.
- Competency overview: per role, who is missing a required competency or has an expired qualification.
- Assets: the devices, systems, applications, data stores and other assets you rely on, with owner and criticality.
- Suppliers: who delivers what to you, how critical they are, when you last reviewed them and the questionnaires you sent them.
- Task templates: the tasks Trustbird sets up when a colleague starts or leaves, or when you add a supplier or a system.
- Interested parties: customers, regulators and others, and what they expect from you.
If it does not work
The fields are greyed out and I cannot add anything
You are probably an advisor in this workspace. Advisors can read everything, but only edit a screen when the workspace owner has given them edit rights for its module. For most screens in this group that is Organisation, for People it is People, and for competencies and qualifications it is Improvement.
Task templates is missing from the menu
Only the owner of the workspace sees Task templates. Ask the owner to adapt the templates.
A list asks me to pick a person, but it is empty
Owners of teams, assets and suppliers, and the holders of a role, are chosen from People. Add the person there first.