04. Organisational Structure, Roles, Responsibilities Flashcards
Organisational Structure, Roles, Responsibilities
The way the organisation is structured will help drive how it deals with what - this being due to departments and other hierarchial structures being established to take care of specific functions that contribute towards business goals and objectives
Cybersecurity
41
Organisational Structure, Roles, Responsibilities
Each unit at each level of the business hierarchy should be aware of and what for its impact on information protection and cybersecurity
Responsible
42
Organisational Structure, Roles, Responsibilities
What does a ROLE describe of an employee
Expected activities obligated to perform as part of their employment
42
Organisational Structure, Roles, Responsibilities
A job title or position title are typically associated with what
Role
42
Organisational Structure, Roles, Responsibilities
A RESPONSIBILITY is a statement of what
Activities that a person is expected to perform
43
Organisational Structure, Roles, Responsibilities
An organisation assigns roles and responsibilities to individuals and groups to meet the organisations what 2 things in relation to security
Strategy and Objectives
43
Organisational Structure, Roles, Responsibilities
What is the purpose of the development of a RACI
Help personnel determine roles for various business activities
43
Organisational Structure, Roles, Responsibilities
What 3 things specifically should be considered when assigning roles to individuals and groups in a RACI chart
- Skills
- Segregation of duties
- Conflict of interest
45
Organisational Structure, Roles, Responsibilities
Activities performed by the baord of directors, as well as directors authority are usually defined by what 3 things
- Constitution
- Bylaws
- External Regulation
45
Organisational Structure, Roles, Responsibilities
Board members have fiduciary duty, which means what
A fiduciary is a person who holds a legal or ethical relationship of trust with one or more other parties
45
Organisational Structure, Roles, Responsibilities
In the U.S., public companies are required to form an audit committee based on what act
Sar-Banes-Oxley Act
45
Organisational Structure, Roles, Responsibilities
The Board of Directors expect the CEO and other executives to implement a corporate governance function to ensure who has an appropriate level of visibility and control over the organisations operations
Executive Management
46
Organisational Structure, Roles, Responsibilities
Who is accountable to the board of directors to demonstrate that they have effectively carried out the boards strategies
Executives
46
Organisational Structure, Roles, Responsibilities
Information security management includes ensuring that sufficient organisational resources are devoted to implementing a security program and devloping and maintaining security controls to protect critical assets. Who is responsible for this
Executive Management
CIO - Chief Information Officer
CTO - Chief Technical Officer
CISO - Cheif Information Security Officer
47
Organisational Structure, Roles, Responsibilities
To ensure the success of the organisations information security program, executive management should be involved in which 3 key areas
- Ratify corporate security policy
- Leadship by example
- Assume Ultimate Responsibility
47
Organisational Structure, Roles, Responsibilities
A security steering committee should consist of, if possible, stakeholders from which 4 things
- Business units
- Departments
- Functions
- Principle Locations
47
Organisational Structure, Roles, Responsibilities
Risk treatment deliberations and recommendations are typically the responsibility of who
Steering Committee
47
Organisational Structure, Roles, Responsibilities
Discussion and coordination of IT and security projects is typically the responsibility of who
Steering Committee
47
Organisational Structure, Roles, Responsibilities
Reviewing of recent risk assessments is typically the responsibility of who
Steering Committee