Tuesday, November 18, 2014

Chapter 11: Security Operations - Security Operations and Administrative Management

A core principle when it comes to administrative management is the concept of separation of duties. This term means that roles are specified to only do one distinct thing. This idea ensures that one person alone could not compromise the whole company by either making a mistake or with intentions of causing harm. Common roles with their descriptions are listed below:

Control Group - Gets the information from different groups or people and passes the information along to the groups or people that need the information to do their jobs.

Systems Analyst - Designs how data will be used in a system or how the data will be transferred from system to system based upon requirements provided by the user as long as those requirements are within the scope of operation.

Application Programmer - Develop software and maintains software.

Help Desk/Support - Responsible for fixing technical issues within the organization and provides guidance to clients and employees for using systems.

IT Engineer - Responsible for doing routine operations on systems on a daily basis to keep them up and running. 

Database Administrator - Develops new data models for database implementations and maintain the databases in an organization.

Network Administrator - Installs Local Area Networks and/or Wide Area Networks for use within the company. Also responsible for maintaining these networks.

Security Administrator - Responsible for the security framework. They develop the security controls, implement them, and insure that these controls are in use effectively.

Tape Librarian - Responsible for backing up and keeping record of all important data.

Quality Assurance - Ensures that activities meet the standards of requirements. Responsible for testing the activities to find issues and pass the issues back to the appropriate group so that the problem/issue can be resolved. 

No comments:

Post a Comment