A Security Executive’s Bill of Rights and Responsibilities

The Security Executive has the right and responsibility:

  1. To develop security objectives, strategies and policies for the organization, for Senior Management approval or amendment.
  2. To identify security risks to the organization’s critical assets and business functions, and their potential business impacts.
  3. To identify and develop security risk mitigation options and recommendations, including their costs and business impacts, for Senior Management approval or amendment.
  4. To monitor for and identify changes to the security risk picture, and to timely act on them.
  5. To keep the Senior Management timely informed about changes to the security risk picture.
  6. To keep Senior Management timely informed about the current state and rationale of corporate asset protection and legal and regulatory compliance.
  7. To have adequate organizational resources allocated for the achievement and implementation of the security objectives, strategies and policies approved by Senior Management.
  8. To receive visible support from the Senior Executives regarding the approved security objectives, strategies and policies, and their related security initiatives.
  9. To implement corporate security as an ongoing process, by means of a security management system that incorporates continuous process improvement.
  10. To plan and execute security programs and projects to achieve the security objectives and implement the security policies set or approved by the Senior Executives.
  11. To maintain his or her continuing education in the field of enterprise security risk management.

(Note: Senior Management means the senior executives of the organization such as the Chief Executive Officer, Chief Operating Officer, Chief Financial Officer, Chief Risk Officer and anyone in charge of a principal business unit or function.)

Back to: Security Bill of Rights

Leave a Reply

Your email address will not be published. Required fields are marked *