The Information Security And Compliance stream is responsible to establish the security and
compliance framework in the engagement in line with the Group security requirements and contractual obligations. In
order to implement this framework , few activities need to executed by other streams.
For example:
-
The security requirements in the on-boarding and off-boarding process may be addressed through
the Service Engagement Staff stream
-
Implementing firewalls or security patches or establishing an isolated network , though a
requirement of the Information Security And Compliance stream, will be addressed by the Technology And
Infrastructure stream.
For this, therefore, the Information Security And Compliance Lead should provide inputs to relevant
Stream Leads to implement the framework.
Once the information for security requirements is communicated to the other streams, these streams need to incorporate
the information and changes into their respective plans and implement them. The streams should connect back with the
Information Security And Compliance stream to provide feedback and highlight risks and issues if any.
It is the responsibility of the Information Security And Compliance Lead to gather feedback on the actions taken by
other streams and inputs if any based on information provided.
|