9
SABSA Implementation Generic Approach PART IV

SABSA Implementation(Part IV)_ver1-0

Embed Size (px)

Citation preview

Page 1: SABSA Implementation(Part IV)_ver1-0

SABSA Implementation

Generic Approach

PART IV

Page 2: SABSA Implementation(Part IV)_ver1-0

ROLE & RESPONSIBILITY CONCEPTS

Page 3: SABSA Implementation(Part IV)_ver1-0

Scope: Strategy & Planning Phase -People

Page 4: SABSA Implementation(Part IV)_ver1-0

SABSA Corporate Governance Model

Page 5: SABSA Implementation(Part IV)_ver1-0

SABSA Domain Model – RACI Overlay

Page 6: SABSA Implementation(Part IV)_ver1-0

Service Provider Custodian Role

Page 7: SABSA Implementation(Part IV)_ver1-0

Security Service Manager As Custodian

Page 8: SABSA Implementation(Part IV)_ver1-0

Roles & Responsibilities In Risk Aggregation

Risk appetite and policy is communicated and distributed top-down in a SABSA domain model

Risk performance and policy compliance is communicated and aggregated bottom-up in a SABSA domain model

Page 9: SABSA Implementation(Part IV)_ver1-0

END OF PART IV