Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

What happens if a recommendation that the team elected to accept is not implemented within the timeline stated in the Action Plan? Or if a recommendation is never implemented as planned?

0
Posted

What happens if a recommendation that the team elected to accept is not implemented within the timeline stated in the Action Plan? Or if a recommendation is never implemented as planned?

0

For most recommendations, the unit head will decide the consequences of failure to implement. Failure to implement constitutes an acceptance of the risk by the unit. For High Priority recommendations mandated by the UA security standards, possible consequences are described in Part VI (Recourse for Non-Compliance) of the Information Security Policy. According to Part II (Authority), the Chief Information Officer and the University Information Security Officer are responsible for enforcing the Policy and the supporting standards and procedures (including the Risk Assessment Standard and the Risk Assessment Procedure). Vice Presidents, Deans, Directors, Department Heads and Heads of Centers have management authority and are expected to take appropriate actions to comply with the Policy.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123