Audit of Departmental Security – Security RACI Chart
Long text description
Activities
Develop and maintain Government of Canada security policies and standards
- DMC: Informed. Person that needs to know of the decision or action.
- IMC: Informed. Person that needs to know of the decision or action.
- Deputy Minister: Informed. Person that needs to know of the decision or action.
- ADM Corporate Services: Consulted. Person that needs to feedback and contribute to the activity.
- Chief Information Officer: Informed. Person that needs to know of the decision or action.
- Departmental Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Security: Informed. Person that needs to know of the decision or action.
- IT Security Officer: Informed. Person that needs to know of the decision or action.
- Manager Information Management: Informed. Person that needs to know of the decision or action.
- Manager Network Services: Informed. Person that needs to know of the decision or action.
- Director Application Services: Informed. Person that needs to know of the decision or action.
- Business Process Owner: Informed. Person that needs to know of the decision or action.
- TBS - CIOB: Accountable. Person who is accountable and has Yes/No/Veto. / Responsible. Person who performs an activity or does the work.
- Shared Services Canada: N/A
Develop and maintain Infrastructure Canada security policies and standards
- DMC: Informed. Person that needs to know of the decision or action.
- IMC: Informed. Person that needs to know of the decision or action.
- Deputy Minister: Informed. Person that needs to know of the decision or action.
- ADM Corporate Services: Informed. Person that needs to know of the decision or action.
- Chief Information Officer: Informed. Person that needs to know of the decision or action.
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.
- IT Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Information Management: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Network Services: Consulted. Person that needs to feedback and contribute to the activity.
- Director Application Services: Consulted. Person that needs to feedback and contribute to the activity.
- Business Process Owner: Informed. Person that needs to know of the decision or action.
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Create and maintain the Departmental Security Plan
- DMC: Informed. Person that needs to know of the decision or action.
- IMC: Informed. Person that needs to know of the decision or action.
- Deputy Minister: Accountable. Person who is accountable and has Yes/No/Veto.
- ADM Corporate Services: Informed. Person that needs to know of the decision or action.
- Chief Information Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Departmental Security Officer: Responsible. Person who performs an activity or does the work.
- Manager Security: Consulted. Person that needs to feedback and contribute to the activity.
- IT Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Information Management: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Network Services: Informed. Person that needs to know of the decision or action.
- Director Application Services: Informed. Person that needs to know of the decision or action.
- Business Process Owner: Informed. Person that needs to know of the decision or action.
- TBS - CIOB: Informed. Person that needs to know of the decision or action.
- Shared Services Canada: N/A
Maintain and monitor a security risk register
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: Informed. Person that needs to know of the decision or action.
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work. (For Corporate Security)
- IT Security Officer: Responsible. Person who performs an activity or does the work. (For IT Security)
- Manager Information Management: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Network Services: Consulted. Person that needs to feedback and contribute to the activity.
- Director Application Services: Consulted. Person that needs to feedback and contribute to the activity.
- Business Process Owner: N/A
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Establish, maintain and monitor a security data classification scheme
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: Informed. Person that needs to know of the decision or action.
- Chief Information Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Departmental Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Security: Consulted. Person that needs to feedback and contribute to the activity.
- IT Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Information Management:
- Manager Network Services: Responsible. Person who performs an activity or does the work.
- Director Application Services: N/A
- Business Process Owner: N/A
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Establish, maintain and monitor a security data classification scheme
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: N/A
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.
- IT Security Officer: N/A
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: N/A
- Business Process Owner: N/A
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Manage inventory information assets
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Departmental Security Officer: N/A
- Manager Security: N/A
- IT Security Officer: N/A
- Manager Information Management: Responsible. Person who performs an activity or does the work.
- Manager Network Services: N/A
- Director Application Services: N/A
- Business Process Owner: N/A
- TBS - CIOB: A / Responsible. Person who performs an activity or does the work.
- Shared Services Canada: N/A
Manage inventory IT assets
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Departmental Security Officer: N/A
- Manager Security: N/A
- IT Security Officer: N/A
- Manager Information Management: N/A
- Manager Network Services: Responsible. Person who performs an activity or does the work.
- Director Application Services: N/A
- Business Process Owner: N/A
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Assure adequate security controls are included in project development.
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work. (For Corporate Security)
- IT Security Officer: Responsible. Person who performs an activity or does the work. (For IT Security)
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: Consulted. Person that needs to feedback and contribute to the activity / Responsible. Person who performs an activity or does the work.
- Business Process Owner: Consulted. Person that needs to feedback and contribute to the activity.
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Track and manage applications security requirements (SA&A Process)
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: N/A
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Consulted. Person that needs to feedback and contribute to the activity.
- IT Security Officer: Responsible. Person who performs an activity or does the work.
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: Consulted. Person that needs to feedback and contribute to the activity. / Responsible. Person who performs an activity or does the work.
- Business Process Owner: Consulted. Person that needs to feedback and contribute to the activity.
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Develop, deliver, monitor security awareness activities
- DMC: Informed. Person that needs to know of the decision or action.
- IMC: Informed. Person that needs to know of the decision or action.
- Deputy Minister: Informed. Person that needs to know of the decision or action.
- ADM Corporate Services: Informed. Person that needs to know of the decision or action.
- Chief Information Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.
- IT Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Information Management: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Network Services: Consulted. Person that needs to feedback and contribute to the activity.
- Director Application Services: Consulted. Person that needs to feedback and contribute to the activity.
- Business Process Owner: Informed. Person that needs to know of the decision or action.
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Establish and periodically review access rights and privileges (Physical)
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: N/A
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.
- IT Security Officer: N/A
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: N/A
- Business Process Owner: N/A
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Establish and periodically review access rights and privileges (IT)
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Departmental Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Security: N/A
- IT Security Officer: Consulted. Person that needs to feedback and contribute to the activity.
- Manager Information Management: N/A
- Manager Network Services: Responsible. Person who performs an activity or does the work.
- Director Application Services: Accountable. Person who is accountable and has Yes/No/Veto.
- Business Process Owner: Consulted. Person that needs to feedback and contribute to the activity.
- TBS - CIOB: N/A
- Shared Services Canada: Responsible. Person who performs an activity or does the work.(For IT infrastructure)
Define and monitor security incidents
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: N/A
- Chief Information Officer: N/A
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.(For Corporate Security)
- IT Security Officer: Responsible. Person who performs an activity or does the work.(For IT Security)
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: N/A
- Business Process Owner: N/A
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Conduct regular vulnerability assessment
- DMC: N/A
- IMC: N/A
- Deputy Minister: N/A
- ADM Corporate Services: Informed. Person that needs to know of the decision or action.
- Chief Information Officer: Informed. Person that needs to know of the decision or action.
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.(For Corporate Security)
- IT Security Officer: Responsible. Person who performs an activity or does the work.(For IT Security)
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: N/A
- Business Process Owner: Informed. Person that needs to know of the decision or action.
- TBS - CIOB: N/A
- Shared Services Canada: N/A
Develop, maintain and test Business Continuity Plan (BCP)
- DMC: N/A
- IMC: Informed. Person that needs to know of the decision or action.
- Deputy Minister: N/A
- ADM Corporate Services: Informed. Person that needs to know of the decision or action.
- Chief Information Officer: N/A
- Departmental Security Officer: Accountable. Person who is accountable and has Yes/No/Veto.
- Manager Security: Responsible. Person who performs an activity or does the work.
- IT Security Officer: N/A
- Manager Information Management: N/A
- Manager Network Services: N/A
- Director Application Services: N/A
- Business Process Owner: Consulted. Person that needs to feedback and contribute to the activity.
- TBS - CIOB: Informed. Person that needs to know of the decision or action.
- Shared Services Canada: Consulted. Person that needs to feedback and contribute to the activity.
- Date modified: