Week One:

Team review of existing process and documentation, and future state agreement.

  • Create Custom online training slides.
  • Identify risk team and kick off process.
  • Distribute Risk Criteria Matrix to key stakeholders

Week Two:

  • Present training: Assist managers to document risks as aligned to position and department responsibilities.
  • Input High Profile Job Descriptions; Organization Titles and map to aligned to ISO/IEC 27001, CSF, CCM v4, NIST RMF 800-37 controls, with an emphasis towards segregated duties as recommended by Information Systems and Audit Control Association
  • Generate by consensus with all IT Directors first Agenda
  • Conduct first Meeting
  • Post Minutes and establish Portal for RiskWatch meetings, agenda, archives
  • Collect Risk Criteria first response summary

Week Three:

  • Assist managers to document risks
  • Generate Agenda and Post Minutes
  • Establish method for remote attendees and be on site to Conduct Second Meeting
  • Present initial job descriptions for affirmation, review standard associated duties and alignment to "CobiT/ISO" controls
  • Deliver Visio with job profiles (DSN) (see image)
  • Risk Criteria Matrix Second Run validation
  • Based on interview with managers, document job-related control anomalies; suggest changes in job definitions as might be indicated by organization chart
  • Kick off - Fragile Artifacts, Technology Resource Risk
  • Collect Application Names; System Names; Factors for review of system-based Risk
  • Determine minimum monitoring profile and automated source data
Main Menu