The ISSO team are responsible to the Information System Security Manager, for the following:
a) Complying with extant workplace Risk Assessments
b) Providing a comprehensive, holistic approach to continually monitoring the security posture relating to Information, Information systems and operations.
c) Produce and publish the Information Assurance (IA) Standard Operating Procedure.
d) Assist the ISSM in meeting their duties and responsibilities.
e) Conduct Continuous monitoring of information systems to ensure compliance with the security authorisation package;
f) Serve as member of the Security Working Group (SWG), if designated by the ISSM;
g) Formally notify the ISSM when changes occur that might affect system authorisation;
h) Ensure all IS security-related documentation is current and accessible to properly authorised individuals; and
i) Ensure audit records are collected, reviewed, and documented (to include any anomalies).
j) Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties;
k) Maintain required IA certifications;
l) Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change;
m) Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly;