Task Tracker #179
Updated by Liberty Mutabvuri 14 days ago
# Consolidated Control Gap This is the **main OMS ticket** for IT and information-security risk governance, the controlled risk register/risk log, periodic risk reviews, risk treatment and MANCO reporting. The following gaps are consolidated here: - [#179](https://redmine.cvevolve.com/issues/179) records that OMS 15.OMS has not defined or applied a formal information-security risk-treatment process. - [#186](https://redmine.cvevolve.com/issues/186) records that periodic information-security risk assessments are not performed. - [#438](https://redmine.cvevolve.com/issues/438), the OMS IT and Security Asset Register, remains New and is a required input for complete risk identification. - No completed monthly IT/security risk log or MANCO risk-review evidence was found. The original #179 finding remains valid: OMS does not yet have a consistently applied process to identify, assess, treat, monitor, review and report information-security risks. # Objective Define, approve and operate an OMS-wide IT and information-security risk-management process that: - Identifies risks across OMS assets, products, services, suppliers, people, data and infrastructure. - Maintains one controlled and current master information security risk register/risk log. - Applies consistent likelihood, impact, inherent-risk and residual-risk criteria. - Assigns accountable risk owners and treatment actions. - Performs planned and event-driven risk assessments. - Reviews the risk register monthly. - Reports material risks, overdue actions, trends and decisions to MANCO. - Retains auditable evidence of assessment, treatment, acceptance, review and closure. # Governance and Ownership Document and approve: - Executive risk owner, process owner and policy approver. - Operational information-security risk coordinator. - Risk owners accountable for individual business and technology risks. - Treatment-action owners and due dates. - MANCO review and escalation responsibilities. - Authorised levels for residual-risk acceptance. - Risk appetite, tolerance and escalation thresholds. - Monthly and event-driven review calendar. - Controlled SharePoint location, access permissions, version history and retention. - Annual review and reapproval cycle for the process. Assignment of this ticket OMS does not constitute acceptance of every risk. Each risk must have a named accountable owner and an authorised treatment or acceptance decision. # Risk Assessment and Treatment Method Create and approve a method that: 1. Establishes the organisational, technical, legal, contractual and client context. 2. Identifies in-scope processes, assets, data, services, suppliers and dependencies. 3. Identifies threats, vulnerabilities, failure scenarios and business consequences. 4. Assesses likelihood and impact using approved criteria. 5. Records inherent formal risk before considering controls. 6. Identifies existing controls, control owners, evidence and operating effectiveness. 7. Calculates and records residual risk. 8. Compares residual risk with approved appetite and acceptance criteria. 9. Selects a treatment: avoid, mitigate, transfer/share, or accept. 10. Defines actions, owners, target dates, resources, evidence and expected residual risk. 11. Obtains authorised approval for treatment plans and risk acceptance. 12. Monitors, reviews, reports, reassesses and closes risks using retained evidence. The method must align with applicable ISO 27001 information-security risk-assessment and treatment requirements and OMS’s POPIA, legal, contractual and client obligations. # Master Risk Register Requirements Every risk record must contain at least: - Unique risk ID and date identified - Risk source, category, project, process, system, asset or supplier - Risk statement in cause–event–impact form - Threat, vulnerability or control weakness - Confidentiality, integrity and availability impact - Legal, privacy, client, financial, operational and reputational impact where relevant - Likelihood and impact scores - Inherent-risk rating - Existing controls, control owner and evidence link - Control-effectiveness assessment - Residual-risk rating - Appetite/tolerance result - Approved treatment option - Risk owner and treatment-action owners - Target and review dates - Status, dependencies and related Redmine tickets - Treatment and closure evidence links - Acceptance approver, rationale and expiry/review date - Last review, next review and change history - Closure rationale and approval Sensitive evidence must be stored in the appropriate restricted SharePoint library. Redmine must not contain credentials, personal information, exploit details or unnecessary confidential client data. # Initial Baseline Scope The first assessment must include: - Asset and ownership gaps from [#438](https://redmine.cvevolve.com/issues/438) - Penetration-test findings and remediation status - Internet-facing infrastructure and network exposure - Identity, access, MFA, privileged and service accounts - Source code, CI/CD, deployment and software-supply-chain controls - Development, test, demo and production environment separation - Secrets and organisational API-key ownership - Backups, recovery, disaster recovery and business continuity - Monitoring, alerting, incident management and escalation - Microsoft 365, SharePoint, email, domains and DNS - Cloud, Coolify, databases, storage and third-party platforms - OBSE, CVEvolve and other OMS-managed applications and APIs - Client and supplier dependencies - POPIA, retention and third-party processing - AI/model, dataset, prompt-injection, model-supply-chain and human-review risks - Skills, capacity, key-person and succession risks - Devices, laptops, physical security and remote access # Monthly and Event-Driven Reviews ## Monthly Review Retain evidence of a monthly review that: - Confirms new, changed, closed and overdue risks. - Reviews all high and critical risks and treatment progress. - Validates owners, target dates, evidence and residual ratings. - Escalates overdue actions and risks outside appetite. - Identifies emerging technology, supplier, legal, client and threat changes. - Records attendees, decisions, approvals and actions. - Updates the controlled master risk log and preserves version history. ## Event-Driven Assessment Reassess risks after material events, including: - Major system, architecture, supplier or infrastructure change - New product, client, integration or sensitive-data use - Security incident, material vulnerability or penetration-test finding - Significant regulatory, contractual or business change - Failed control, backup, restore, deployment or disaster-recovery test - Material change to threat exposure or service criticality # MANCO Reporting Provide a concise monthly risk dashboard or report showing: - Current high and critical risks - Movement since the previous month - New, closed, accepted and overdue risks - Top control gaps and dependencies - Treatment progress and blocked actions - Risks outside appetite - Residual risks awaiting acceptance - Material incidents, vulnerabilities, supplier risks and audit findings - Decisions, resources and approvals required from MANCO Retain the report, meeting record, decisions, approvals and action tracking in controlled SharePoint storage, and add the canonical evidence link to #179. # Relationship to Other Tickets - **#179 is the main governance and tracking ticket.** - [#186](https://redmine.cvevolve.com/issues/186) provides evidence of the periodic-assessment gap and is addressed by the approved review schedule and completed assessments. - [#438](https://redmine.cvevolve.com/issues/438) is the asset-register dependency and must feed ownership, exposure and control data into the risk register. - Technical remediation may remain in separate tickets, but each material risk must link to its treatment ticket and remain tracked centrally through #179. # Required Deliverables - Approved IT and Information Security Risk Management Policy - Approved risk-assessment and risk-treatment procedure - Likelihood, impact, risk-rating, appetite and acceptance criteria - Controlled master IT/security risk register - Initial baseline risk assessment - Risk Treatment Plan with owners and dates - Asset-register linkage process to #438 - Monthly identify and event-driven review schedule - Monthly risk-review template and completed evidence - MANCO risk dashboard/report and completed review evidence - Residual-risk acceptance workflow and approval record - Risk escalation and overdue-action procedure - Controlled SharePoint storage and canonical links - Evidence-retention requirements - Staff and risk-owner awareness/training evidence # Acceptance Criteria - #179 is clearly established and used as the main OMS risk-governance ticket. - The policy and procedure are approved, version-controlled and published in controlled SharePoint storage. - Risk appetite, likelihood, impact, inherent-risk, residual-risk and acceptance criteria are approved and consistently applied. - A controlled master risk register exists with the required fields and change history. - The baseline assessment covers all material OMS products, infrastructure, data, suppliers, legal obligations and dependencies. - Assets and ownership manage information from #438 are incorporated or linked. - Every material risk has a risk owner, treatment decision, action owner, target date and evidence requirement. - High and critical risks are escalated and cannot remain overdue without a documented management decision. - Risk acceptance records the authorised approver, rationale, compensating controls and review/expiry date. - A planned review schedule resolves the periodic-assessment gap in #186. - At least one complete monthly risk review is performed and evidenced. - At least one risk report is reviewed by MANCO, with decisions and actions retained. - The risk register, Risk Treatment Plan and related Redmine tickets reconcile. - Closed risks contain objective closure evidence and approval; completion percentage alone is insufficient. - Canonical SharePoint evidence links are added to #179 with access limited by sensitivity. - The process has an accountable owner, review cycle and recurring monitoring mechanism. security risks.