CRISC Certified in Risk and Information Systems Control All-in-One Exam Guide, Second Edition, 2nd Edition by Peter H. Gregory & Bobby E. Rogers & Dawn Dunkerley

CRISC Certified in Risk and Information Systems Control All-in-One Exam Guide, Second Edition, 2nd Edition by Peter H. Gregory & Bobby E. Rogers & Dawn Dunkerley

Author:Peter H. Gregory & Bobby E. Rogers & Dawn Dunkerley [Peter H. Gregory]
Language: eng
Format: epub
Publisher: McGraw-Hill
Published: 2022-05-06T00:00:00+00:00


Other Implementation Considerations

It goes without saying that implementation of a complex control has many more aspects to it than are discussed here. Some of these are resource considerations, such as having enough money in the budget, having enough qualified people to install, manage, and monitor the control, not to mention political considerations within the organization. Consider the implementation of a relatively “easy” control, such as revoking administrative rights on user workstations. Not only will users typically revolt, but managers who are used to having administrative rights over their own workstations will complain and likely go to upper management, who may cave in to those complaints, effectively rendering the control useless. Users also typically balk at having their systems offline for any amount of time since it may interrupt their work. All these issues should all be carefully considered and decided upon by management, or at the very least kept in mind by the risk practitioner.

Another aspect of control implementation is documentation. All steps of the implementation should be thoroughly documented, as well as any exception items, such as configuration or interoperability issues that may need to be addressed later. Documentation also includes policies and procedures to support the control, change management records, implementation test results, operator training materials, schedules for maintenance, and any other information relevant to the control.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.