|
|
Defining Roles and Responsibilities
The establishment of clear roles and responsibilities is a critical success
factor for any risk management program due to the requirement for cross-group
interaction and segregated responsibilities. The following table describes the
primary roles and responsibilities used throughout the Microsoft security risk
management process.
Table 3.3 Primary Roles and Responsibilities in the
Microsoft Security Risk Management Process
Title |
Primary Responsibility |
Executive Sponsor |
Sponsors all activities associated with managing risk to
the business, for example, development, funding, authority, and support
for the Security Risk Management Team. This role is usually filled by an
executive such as the chief security officer or chief information
officer. This role also serves as the last escalation point to define
acceptable risk to the business. |
Business Owner |
Is responsible for tangible and intangible assets to the
business. Business owners are also accountable for prioritizing business
assets and defining levels of impact to assets. Business owners are
usually accountable for defining acceptable risk levels; however, the
Executive Sponsor owns the final decision incorporating feedback from
the Information Security Group. |
Information Security Group |
Owns the larger risk management process, including the
Assessing Risk and Measuring Program Effectiveness phases. Also defines
functional security requirements and measures IT controls and the
overall effectiveness of the security risk management program. |
Information Technology Group |
Includes IT architecture, engineering, and operations. |
Security Risk Management Team |
Responsible for driving the overall risk management
program. Also responsible for the Assessing Risk phase and prioritizing
risks to the business. At a minimum, the team is comprised of a
facilitator and note taker. |
Risk Assessment Facilitator |
As lead role on the Security Risk Management Team,
conducts the data gathering discussions. This role may also lead the
entire risk management process. |
Risk Assessment Note Taker |
Records detailed risk information during the data
gathering discussions. |
Mitigation Owners |
Responsible for implementing and sustaining control
solutions to manage risk to an acceptable level. Includes the IT Group
and, in some cases, Business Owners. |
Security Steering Committee |
Comprised of the Security Risk Management Team,
representatives from the IT Group, and specific Business Owners. The
Executive Sponsor usually chairs this committee. Responsible for
selecting mitigation strategies and defining acceptable risk for the
business. |
Stakeholder |
General term referring to direct and indirect
participants in a given process or program; used throughout the
Microsoft security risk management process. Stakeholders may also
include groups outside IT, for example, finance, public relations, and
human resources. |
The Security Risk Management Team will encounter first-time participants in
the risk management process who may not fully understand their roles. Always
take the opportunity to provide an overview of the process and its participants.
The objective is to build consensus and highlight the fact that every
participant has ownership in managing risk. The following diagram, which
summarizes key participants and shows their high-level relationships, can be
helpful in communicating the previously-defined roles and responsibilities and
should provide an overview of the risk management program.
To summarize, the Executive Sponsor is ultimately accountable for defining
acceptable risk and provides guidance to the Security Risk Management Team in
terms of ranking risks to the business. The Security Risk Management Team is
responsible for assessing risk and defining functional requirements to mitigate
risk to an acceptable level. The Security Risk Management Team then collaborates
with the IT groups who own mitigation selection, implementation, and operations.
The final relationship defined below is the Security Risk Management Team's
oversight of measuring control effectiveness. This usually occurs in the form of
audit reports, which are also communicated to the Executive Sponsor.
|
Call Now : 800-519-
2267
Testimonials
|
If you're serious about getting certified,
this is the place to go. Definitely worth
their competitive price. Excellent
instructors, making it possible for anyone
to learn no matter what your level of
experience or knowledge.
Michael Doty
|
|
|
|
|
|
MCITP Boot Camp
,
MCSE Boot camp,
CCNA Boot Camp,
Upgrade to MCITP Boot
camp,
MCITP Enterprise admin
Certification
Boot camp Training.
All
rights reserved. ©1998 - 2015, Vibrant Worldwide Inc.
MCITP Boot camp
UK
MCITP Camp
Thailand
MCITP
RHCE Boot Camp India
MCSE Boot Camp - Proven Boot camp for MCSE at Baltimore, Maryland
MCITP, MCSE, CCNA, Certification n training guide, how mcse mcitp
ccna boot camp works
MCSE Boot Camp Proven MCSE Boot camp Training for MCSE
Certification Fast
MCSE Boot Camp Card Payment by Paypal
CCNA 801 Boot Camp by Vibrant boot camps, join MCSE camps
CCNA Boot Camp by Vibrant boot camps, join MCSE camps
CCNP Boot Camp by Vibrant boot camps, join CCNP camps
MCSE MCITP CCNA Boot Camp Card Payment by Paypal
MCSE MCITP Boot Camp location
comaprision between USA, UK, India and Thailand
MCSE Boot Camp compare Vibrant boot camps with other boot camp
provider
Comptia Security+ Boot Camp by Vibrant boot camps, join MCSE
camps
MCSE Boot Camp contact Vibrant boot camps
MCSE Boot Camp course fees Vibrant boot camps, join MCSE camps
MCSE Boot Camp FAQ by Vibrant boot camps, join MCSE camps
MCSE Boot Camp provide your Feedback here
MCSE CCNA CCNP Boot Camp inquire we call back
MCSE Boot Camp location San Francisco and Baltimore
MCITP Boot Camp MCITP 14days
all_incl MCITP Certifiation boot camp
MCITP Boot Camp MCITP Benefits
MCITP Certifiation boot camp
MCITP Boot Camp MCITP curriculum
MCITP Certifiation boot camp
MCITP Boot Camp MCITP bootcamp
details MCITP Certifiation camp
MCITP Boot Camp MCITP exam detail
MCITP Certifiation boot camp
MCSE Boot Camp MCSE Certification Camp also MCSE Training Boot
Camp
MCSE Benefits join MCSE Boot Camp by Vibrant boot camps
MCSE Curriculum join MCSE Boot Camp
MCSE Exam Detials join MCSE Boot Camp
MCSE boot camp details, join MCSE camps
MCSE MCITP Boot Camp MCSE MCITP 18days 8 Certifiation boot camp
MCSE MCITP combo Boot Camp MCITP
MCSE Benefits MCITP Certifiation boot camp
MCITP MCSE Boot Camp MCITP
curriculum MCITP Certifiation boot camp
MCSE MCITP Boot Camp MCITP MCSE
bootcamp details MCITP Certifiation camp
MCSE MCITP Boot Camp MCITP MCSE
exam detail MCITP Certifiation boot camp
MCSE MCITP CCNA Boot Camp MCSE
MCITP CCNA 23days 9 Certifiation boot camp
MCSE Security Boot Camp MCSE
14days all_incl MCSE Certifiation boot camp
MCSE Security certification benefits join boot camp now
MCSE Security Boot Camp Curriculum join MCSE camps
MCSE Security Exam Detail join MCSE boot camps
MCSE Security Boot Camp Details for MCSE Certification
MCSE Boot Camp Payment Gateway to get MCSE Certification Fast!
MCITP Boot Camp, CCNA Boot Camp
reason to join Vibrant boot camp
MCSE Boot Camp Refunds
MCSE CCNA CCNP Boot Camp Register. Join MCSE CCNA Boot Camp today
MCSE CCNA CCNP thailand bangkok Boot Camp Register. Join Thailand
MCSE CCNA Boot Camp today
MCSE Schedule CCNA Scedule CCNP Boot Camp Schedule
MCITP Boot Camp, MCSE Boot camp, CCNA Boot Camp, Special offer
Vibrant boot camp
MCSE Boot Camp Testimonials by Vibrant boot camps
MCSE Boot Camp location San Francisco and Baltimore
Virbant Boot Camp thank You Trasaction successfull
MCSE Boot Camp upgrade win2008 mcse camps
Microsoft Vista Certification Boot
Camp for Vista training boot camps
MCSE Boot Camp location San Francisco and Baltimore
bootcamp_schedule.php
cardpay.php
CCNA-boot-camp.php
certification-courses.php
certified-ethical-hacker-ceh-certified-EC-council.php
cisco-certification-courses.php
comptia_a+_bootcamp_course.php
comptia_a+_network+_boot_camp.php
comptia-certification-courses.php
compTia-network+.php
compTia-security+.php
contact_us.php
course_fees.php
course_template.php
faq_camp.php
guarantee.php
how-boot-camp-works.php
index.php
join-vibrant-as-trainer.php
locations.php
mcsa_server_2012_r2_boot_camp.php
mcsa-windows-server-2016-training-certification-boot-camp.php
mcse-cloud-platform-infrastructure-azure-track.php
mcse-cloud-platform-infrastructure-security-with-mcsa-windows-server-2016-training-certification-boot-camp.php
mcse-cloud-platform-infrastructure-with-mcsa-windows-server-2012-R2-training-certification-boot-camp.php
mcse-productivity-exchange-server-2016.php
microsoft-certification-courses.php
microsoft-mcse-messaging-certification-training-course.php
msca-windows-2016-upgrade.php
msce-windows-2008-to-2016-upgrade.php
msce-windows-2016-upgrade.php
mta-it-infrastructure-windows-server-training-certification.php
onsite-training.php
our-clients.php
photogallery.php
reason_to_join_vibrant_boot_camp.php
recaptchalib.php
refund.php
register.php