Process Librarian

The Process Librarian controls the process information directory structure and makes sure the integrity of the folders is maintained. The librarian function catalogues and categorizes documentation assets and aligns documentation standards to the needs of the business and technology functions.

Where changes are required to existing process documentation, the process librarian handles the registration and posting of new procedures to the established process location.

Any new folders must be requested via email to the process librarian, currently [Name of Process Librarian], at This email address is being protected from spambots. You need JavaScript enabled to view it.. The librarian insures name and contents integrity within Facilitated Compliance Management process tracking. \\...\PAL\Facilitated Compliance Management\Facilitated Compliance Management2000FCM.mdb

People who administer access to process assets will adhere to sanctioned user access process, providing resource access to employees as determined by their role and the approval of their management. The Resource Administrator will not add or modify folders outside the boundaries defined by the Process Engineering Team. Specifically, once a business area is provided space for information assets, modification to root level file hierarchy is not permitted. This rule is established to assure inventory over information and in no way limits the productivity of any business area. Information can be created in subfolders within the designated file share. Persons with write access can create subfolders within the root of their information domain.

The Security Administrator will create file shares and folders as requested by the Process Librarian, and will allow changes within the files as determined by the business owner for the share information.

Business Unit and Department Data Owners

Data owners are accountable to the reasonable use of their designated drive space, assuring proper classification and location of their data. Business owners define users and establish access rules based on a need-to-know principal. Where a business area needs folders that extend beyond the current process architecture, the Business Unit must gain approval through process engineering and security, ensuring proper rules for classification and the avoiding of duplicate information. (See Current PAL Contents and File Location Description of Use)

Business owners are accountable for the periodic review of information on their drive. This review is to assure appropriate use of file naming conventions, the validity of the process, completed procedures, and to archive out-of-date content. Business owners are accountable to understanding their data privacy and retention requirements and communicating these requirements to their personnel.

Access Control

Access to the production library contents must be controlled in the same manner as the production environment to ensure that only authorized users can access the documents. Access controls must be established to ensure only authorized individuals can view, edit, and update documents according to appropriate roles.

Default access controls include:

  • Process Librarian has administrative privileges to the PAL and provides Security Administration with the Functional Business Owner for each directory in the PAL.
  • System Administrator has administrative privileges to the PAL and may grant user access according to Manager Approval.
  • Functional Managers, such as Support, Change Management and Process Engineering, have read/write/update/delete privileges to their file share on the PAL. Policy dictates they should not create or delete folders without notice and approval from the Process Librarian.
  • Employees (non managers) have read only privileges unless granted write privilege by the Functional Manager. Employees do not have delete privilege.

Audience and Audit Considerations

This process profile serves as a reference for COMPANY. Groups may be referenced by functional email notification names such as This email address is being protected from spambots. You need JavaScript enabled to view it.. Group functional emails are used to support communication trails and facilitate rules for review, approval, and timely business communication.

Procedures are detailed documents, generally derived from parent policy and implemented to the spirit (intent) of the policy statement. Therefore, all procedures written and implemented by COMPANY align to Security Policy, HR Policy, Program Change Policy, and specific requirements for Data Classification, Data Retention, and Data Privacy as defined by senior management.

Auditors

Main Menu