adriennhem / screendesk-security-docs

0 stars 0 forks source link

Security Organization and Management Policy

Security Roles and Responsibilities

Screendesk has an organizational structure that establishes, approves, implements, and monitors adherence to an Information Security Program through clear lines of authority and responsibilities.

Risk Committee

Given Screendesk's small size (2 employees), the Risk Committee consists of both employees, with the CTO serving as the primary responsible party for security matters. The Risk Committee has oversight responsibilities related to internal security controls.

Responsibilities include:

The Risk Committee meets at least quarterly and maintains formal meeting minutes.

Personnel

The following personnel are responsible for overseeing and implementing security and data protection practices throughout Screendesk:

Every end user and vendor is responsible for identifying and mitigating risks associated with the protection of Confidential information and must comply with all the policies within this Information Security Policy.

Policy Review

The CTO is responsible for reviewing Screendesk's policies and procedures on at least an annual basis to ensure they remain accurate and up-to-date with current operations and compliance requirements.

Related Policies