Maintain and manage compliance to control requirements for previously identified and remedied Technology initiatives.
Continuous maintenance of initiatives that reach certain maturity levels after having gone through Remediation, Sustainability and BAU phase from any of the Tech Factories (e.g. Audit, Risk, Cloud, Currency etc.)
Maintain the process documents outlining how to test, who to engage, and what evidence to collect for in-scope control requirements (e.g., data encryption).
Leverages existing SOPs and documentation to perform assessments in the following scenarios:
New applications moving from Dev to production
Existing Applications whose parameters (e.g., data classification) change, identified via regular reports
Proactive Assessment - Perform assessments at regular intervals to determine if there are any vulnerabilities proactively