In: Computer Science
Discuss the role of people within a company's computer-security plan.
Hi,
Please find the answer below:
-----------------------------------------------------------------
Security is defined as the state of being secure whether its physical assets like computers, network devices, or data or information like customer documents, files etc.
Security planning and security plan is a document that outlines the organizations security goals, objectives, establishing trust boundaries, defensive strategies and plans to protect the devices and data of the organization. The plan also outlines security risk mitigations and recovery plan when a security threat becomes a reality aka security incidents.
People are the most critical in the computer security planning. Almost everyone is responsible for the security in the organization.
There are many roles that people can play for successful execution of the security plan in the organization. The security team vastly depends on the organization size and mode of operation etc.
CIO- Chief Information officer
CIO is the person responsible for security in the organization.
Security Manager
This role is mostly responsible for managing security resources within the organization, hiring new security team members etc.
Security Architect
Architect is responsible for implementing security controls in the company, involves in security best practices. Conduct security training new security engineers, employees and analysts. Perform Security Audits
Security Engineers
Engineers are responsible for building security systems in the organization. Engineers closely work with other team members like developers, testers etc in the company. Perform Security Audits
Security Analysts and Testers
Analysts are responsible to investigate security holes or defects, and respond to incidents. Testers log security defects and incidents in the reporting tool. Help and coordinate with other members during security incidents.
CEO
CEO is responsible to announce any security incidents (if any) to customers and to the outside world. Announcement, emails about the incident and outlines the corrective actions etc
Staff and Employees
To follow security policies and privacy standards, participate in security trainings.
---------------
Hope this helps.