Security project health report (SPHR)
Security Health Parameters are the critical Project level
security parameters like Risk Assessment, Data Privacy and
Business Continuity mandatory requirements definitions and
docuemntation completions. These are assessed by project managers
at Project level and updated using the SPHR tool kit.
Security Engineering is discipline of building dependable and
resilient systems by implementing Security across System
Development Life Cycle - from its inception until it retires. This
includes the 6 attributes below.
- Awareness and knowledge of Secure SDLC (System Development
Life Cycle)
- Incorporating Data protection requirements
- Applying Privacy principles by design
- Identifying Risks and implementing their treatment plan
- Security Assessments and compliances
- Ensuring Availability of Systems and Services
SPHR is a toolkit which enables monitoring through security
compliance parameters meeting the secure engineering objectives.
The SPHR platform is supported by the CIO application support team.
The roles associated with the Security Project Health report
(SPHR) across ISG unit is provided below in the Activity RACI
chart.
# |
Activity |
Responsible |
Accountable |
Consult |
Inform |
1 |
Analysis of Risks in Projects with reference to SPHR data |
ISG Compliance Lead / Team |
ISG Compliance Head |
Project Manager |
ISG Risk Management |
2 |
Checking SPHR baseline entry compliance and validation of
all evidences aligned to SPHR questions |
ISG Assurance Lead / Team |
ISG Assurance Head |
Project Manager |
ISG Risk Management |
3 |
Request for re-visit and update of SPHR record aligned to
Risk exposures |
ISG Compliance Lead / Team |
ISG Compliance Head |
Project Manager |
ISG Risk Management |
4 |
Validation of SPHR status change prior to NC Closure for
identified gaps in evidences aligned to SPHR questions |
ISG Assurance Lead / Team |
ISG Assurance Head |
Project Manager |
ISG Risk Management |
5 |
Tracking completion of SPHR baseline in Clusters |
ISG Compliance Lead / Team |
Cluster Head |
Project Manager |
ISG Compliance Lead / Team |