Question: Now that you understand how standardized processes can be arrayed into a defined organizational structure using the recommendations of ISO 12207, demonstrate that you know
Now that you understand how standardized processes can be arrayed into a defined organizational structure using the recommendations of ISO 12207, demonstrate that you know how to create a process that assesses the risks of any ICT acquisition. This process will be generic; in other words, it will be applicable in all situ- ations for all ICT items. You can customize the process for any situation based on a process you must recommend. Provide a plan that specifies the following details: o Who will execute the plan? Use generic titles, such as manager of ICT security. o When will the plan be executed? In other words, what is the schedule in terms of milestones? o Where will the plan be executed within the organizations structure? o What specific actions will you recommend to establish a correct customer/ supplier agreement process for ICT? o This plan must be oriented within the lifecycle processes. It must detail the purpose and impact of these actions in laymans terms.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
