02-17-2022, 04:26 PM
Can anyone help me better understand the expectation of 3.2.7 Accountability under the Business Domain - Charter? The remarks state "Accountability for the SOC for actions taken". What would you expect a Charter to include regarding "Accountability"? A simple statement on who is ultimately accountable for the SOC (e.g. CISO)? A RACI matrix that defines responsibility and accountability for the various services provided by the SOC?
Thanks in advance. First time working through the SOC-CMM and just looking for input from others.
Thanks in advance. First time working through the SOC-CMM and just looking for input from others.