The Engagement Manager is responsible for assessing the status of the Security And Data Protection Controls and
Measures as defined at the beginning of the Service Engagement. Where the Engagement Manager identifies any issues in
achieving the controls and/or measures, these issues must be documented.
If issues have an unacceptable variance, appropriate actions will be developed to mitigate and/or correct them. These
variances and corresponding actions (based on risk and impact) might be discussed during the relevant meetings within
Capgemini and/or Client.
The engagement must track and manage security and data protection risks using the Risk Management procedures to ensure
actions to mitigate or contain risks are completed until the risk can be closed. Security and data protection risks
identified outside the regular security and data protection risk assessment must also be added to the Risk Log and
actively managed.
|