Job Description
The duties and responsibilities of Security and Risk include but is not limited to:
1. IT Security Project Management:
- Identify, prioritize and plan key IT security projects;
- Monitor the IT security project's overall progress and outcomes.
2. Policy & Security Training Development:
- Provide guidelines and feedbacks on the policies drafted by officers;
- Measure the effectiveness of IT and Information Security training through mass surveys and selected group interviews.
3. Policy Compliance Monitoring:
- Closely monitor user activities and identify any illegal, unethical or improper conducts;
- Develop a system to properly evaluate, investigate and resolve such cases.
4. Security Operation Management:
- Monitor security of information in portable media (laptops, backups, etc.);
- Provide virus protection for applications, offer support in security matters and solve security incidents.
5. Information Security Policy Preparation & Training:
- Establish the security plan (policies and procedures) which define the appropriate procedures for security of applications, data and infrastructure;
- Develop and deliver education and training programs on information security and privacy matters for staffs and students.
6. Risk Management:
- Perform IT audit and check on IT security:
- Install risk management procedures to assure normal functionality.
7. Business Continuity & Disaster Recovery:
- Propose IT contingency and business continuity plan;
- Propose disaster recovery plan to assure continuous academic and administrative operation;
- Periodically perform IT contingency practice exercises.