Week One:
Team review of existing process and documentation, and future state agreement.
- Create Custom online training slides.
- Identify risk team and kick off process.
- Distribute Risk Criteria Matrix to key stakeholders
Week Two:
- Present training: Assist managers to document risks as aligned to position and department responsibilities.
- Input High Profile Job Descriptions; Organization Titles and map to aligned to ISO/IEC 27001, CSF, CCM v4, NIST RMF 800-37 controls, with an emphasis towards segregated duties as recommended by Information Systems and Audit Control Association
- Generate by consensus with all IT Directors first Agenda
- Conduct first Meeting
- Post Minutes and establish Portal for RiskWatch meetings, agenda, archives
- Collect Risk Criteria first response summary
Week Three:
- Assist managers to document risks
- Generate Agenda and Post Minutes
- Establish method for remote attendees and be on site to Conduct Second Meeting
- Present initial job descriptions for affirmation, review standard associated duties and alignment to "CobiT/ISO" controls
- Deliver Visio with job profiles (DSN) (see image)
- Risk Criteria Matrix Second Run validation
- Based on interview with managers, document job-related control anomalies; suggest changes in job definitions as might be indicated by organization chart
- Kick off - Fragile Artifacts, Technology Resource Risk
- Collect Application Names; System Names; Factors for review of system-based Risk
- Determine minimum monitoring profile and automated source data

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics