Organizational structure
The success of an organization’s risk management program depends on the sponsorship and support of the senior management. Different departments may lead risk management programs and to make risk-conscious decisions, senior management needs to combine all the individual programs in an enterprise risk program, often referred to as enterprise risk management (ERM).
The IT risk manager needs to be acquainted with the ERM program and establish roles and responsibilities for all relevant stakeholders. This can often be performed by a tool called RACI.
RACI
RACI is an effective tool for determining the roles and responsibilities of a project with several stakeholders with varying priorities. There are four main roles under the RACI method:
Role |
Description |
Responsible |
The individual or team responsible for performing... |