Corporate Audit of Security
Final Summary Report
5.1 MANAGEMENT RESPONSE
AND ACTION PLAN (1 of 3)
| Recommendations | Response | Action Plan and Tasks | Responsibility | Target Dates |
|---|---|---|---|---|
| Audit Recommendation 1
1. Senior management should review the organizational
context for security and ensure that all elements of security have
a sufficiently high profile by: |
Several steps have already been taken to address this recommendation. In the last year, CIC raised the profile and awareness of security issues at all levels of the organization. The profile of the DSO has been elevated and given greater access to senior management. A review of the security organization will be completed and benchmarked with the cooperation of several partner agencies. New resources have been allocated to augment IT and Corporate Security capability. CIC will also explore the degree to which a security component should be incorporated into managers’ contracts. | 1.1 Assessing the appropriateness of the organizational
level to which the security function reports
a) Greater visibility and executive access for the DSO The profile of the DSO has been elevated and the DSO has been given greater access to senior management:
|
|
|
| b) Review of the security organization and structures
A security organizational review has been undertaken
to assess the effectiveness of the current CIC security organization,
benchmark it against other departments and make recommendations. |
|
|
||
| c) Enhancement of the IT Security and Corporate
Security organizations
A revised organizational structure that includes changes and enhancements to the IT Security organization staff levels, roles and responsibilities was completed on June 28, 2002. Staffing actions have begun to augment the capability of both the Corporate and IT Security Unit, supported by ongoing funding. |
|
|
||
| 1.2 Ensuring better integration of the elements
between NHQ and the regions
a) Operational Committees |
|
|
||
| 1.3 Building management team support by incorporating
security requirements in the management contracts developed with senior
managers across the Department
a) Security contracts with managers 1.4 Periodically assessing the security function
at the regional and local levels against the management contract |
|
|
||
| 1.5 Revising budgets to help security staff at all
levels provide leadership, then evaluating that leadership as part
of the security management contract a) Major ongoing investment in personnel for IT and Corporate Security incorporated into base budget and infrastructure. |
|
|
||
| 1.6 Improving communications by providing resources
for interdepartmental information sharing of “best” security
practices
a) Management forums and conferences A CIC Annual Security Conference has been established
in association with the current Annual Administration Conference |
|
|
||
| 1.7 Benchmarking the investment in security made
by other government departments and applying “lessons learned”
to the Department
a) Demographic Analysis and Survey of the Security
Community |
|
|
- Date Modified:
