PM-9 Risk Management Strategy
Description
The university develops a risk management strategy to secure university operations and assets.
Applicability
- The university’s Chief Information Security Officer (CISO) has the primary responsibility for the implementation of this Control.
Implementation
-
1The Chief Information Security Officer (CISO) shall develop a comprehensive strategy to:
- 1.1Manage security risks to university operations and assets, individuals, and other organizations related to the operation and use of information resources.
- 1.2Manage privacy risks to individuals resulting from the authorized processing of personally identifiable information.
-
2Implement a risk management strategy consistently across the university.
-
3Review and update a risk management strategy annually or as required to address organizational changes.