Project Tracking |
PM to tracking project timelines. Highlight any challenges both from delivery, security and dependencies prospective. |
BCP Tracking |
Track BCP Plan and drills are as per schedules. Any challenges and gaps to be tracked and highlighted to Customer and Management |
Privacy Tracking |
PIA and ROPA as per ISG Guidelines |
Vendor Monitoring |
Tracking Vendors and highlighting the gap including closing of Third-party audits NC closure
|
Tracking external audits |
Tracking Third party audits NC closure |
Security Assessments |
Regular security assessments with the help of internal functions and highlight any gaps to respective stake holders
|
Customer updates |
Regular meeting with customer and their security team and discuss on current and improvement plans |
Quality Assurances |
Closing Quality NC |
Communication |
Communication with all the stake holders on updates including vendors and customers
|
Risk Register |
Update Risk register at regular intervals. |
Alert |
Is alert mechanism is place during downtime |
Application Security Lifecycle (ASL) |
Monitoring application security life cycle. |
Health check |
Automate health check at regular intervals |
Secure Data Lifecycle |
Monitoring of Secure data life cycle |
Additional Training |
Update associates with additional trainings specially on data security and business continuity. Connect with ISG Training division for security training, mailers and posters. |
Project Management Review |
Update Project management with current and upcoming tasks and challenges. |
Initiate change request |
Consider any project change request with customer and vendors. |
Check list review |
Review check list as per Gate 2 process |
Commitments review |
Highlight wherever commitment levels are going down with all stake holders. |
Data Classification followed? |
Are all documents labeled as per classification guidelines - "Company Confidential”, "Restricted", "Client Confidential", "PUBLIC”, or "Commercial in Confidence”?
|
Data Breach Monitoring |
Are project team members aware of the incident management training & reporting websites? |