M. A. Ghafoor
Senior GRC Consultant/Lead Auditor
Overview
Confidently able to handle implementation, Compliance, and Governance /Internal
Audits, Certification Audits, and training of ISMS (ISO 27001), (Local CS
Frameworks, SAMA CSF, NCA CS controls) and other international standards like
PCI-DSS, NIST, COBIT, GDPR, and other standards.
I have more than 20 years in Telecom, operations, and project management.I have
served strategically in the leading Pakistan telecom industry players, including
multinational organizations.
Relevant Experience
-
-
-
- Led the independent I.T. controls and security assessments to provide maturity and benchmarking against international standards.
- Implemented ISO 27001 in various organizations within KSA.
- Implemented Regulatory Frameworks (NCA, SAMA & and NDMO) for various organizations.
- Performed Compliance assessments against the Regulatory Requirements (SAMA CSF & NCA)
- Managed NCA AND SAMA CSF and implementation projects for many organizations, including but not limited to NIC, SAR, IPA, NEOM, Amlak Intl, etc.
-
-
Certifications
-
-
-
-
- ISO 27001: Senior Lead Implementer
- ISO 27001: Lead Auditor
- CISM: Certified Information Security Manager
- CISA: Certified Information Systems Auditor.
- ITIL: ITIL 4 Foundation
-
-
-