Security Roles and Responsibilities Flashcards
Roles and Responsibilities
- Ownership of assets
- Access to assets
- Use of assets
- Managers
Ownership of assets
Individual assets and groups of assets need to have designated owners who are responsible for their operation and protection.
Access to assets
The owners of assets should be designated as the persons who decide who may access or use those assets.
Use of assets
All employees should be explicitly designated as responsible for their individual use of assets.
Managers
Managers should be designated as being responsible for the behaviour of employees under their control.
SLA
Service Level Agreement is a formally defined level of service provided by an organisation.
They can be defined for many activities:
- Security incident response
- Security alert delivery
- Security investigation
- Policy and procedure review
Risks associated with outsourcing
- Control of confidential information
- Loss of control
- Accountability