Skip to main content

PM-9 Risk Management Strategy

Description

The university develops a risk management strategy to secure university operations and assets.

Applicability

  • The university’s Chief Information Security Officer (CISO) has the primary responsibility for the implementation of this Control.

Implementation

  • 1The Chief Information Security Officer (CISO) shall develop a comprehensive strategy to:

    • 1.1Manage security risks to university operations and assets, individuals, and other organizations related to the operation and use of information resources.
    • 1.2Manage privacy risks to individuals resulting from the authorized processing of personally identifiable information.
  • 2Implement a risk management strategy consistently across the university.

  • 3Review and update a risk management strategy annually or as required to address organizational changes.