The Information Systems Security Officers Guide: Establishing and Managing an Information Protection Program

Noncompliance inquiries (NCI) were identified as an ISSO responsibility and the process (Figures 8.9 and 8.10) developed by the InfoSec staff and coordinated with the audit and security management. The NCI process was as follows:

Figure 8.9: An overview of the NCI function.

Figure 8.10: The NCI process where revocation of user access is a major consideration.

[7]The ISSO was sensitive to privacy issues and did not want to initiate an inquiry without substantiated information since someone may have a grudge against another and use the process to harass him or her.

Категории