From the course: Certified Information Systems Auditor (CISA) Cert Prep

Unlock this course with a free trial

Join today to access over 24,200 courses taught by industry experts.

Roles and responsibilities

Roles and responsibilities

- [Narrator] Okay, our last section talking about roles and responsibilities within the organization. Now, there is no document that says every organization must be organized exactly like this. However, there's sort of some some general guidelines that we can follow. And the most important piece is that our roles have a clear line of reporting and they're free from conflict of interest. So the board of directors, when we talk about governing entities, the board of directors obviously are in that category, right? So their job is to help determine the risk appetite and to help figure out what those goals and objectives are to satisfy the stakeholder. So ultimately, they're not going to be working hands-on detail by detail with risk, but to ensure that risk is integrated, risk management's integrated throughout, not just IT, but throughout the business. Now we also have steering committees. And your steering committees are those groups that are pulled together to kind of oversee…

Contents