The functions and responsibilities that are structured around the security of the information They present a dichotomy that is due to their origin. Depending on whether its origin is framed in a field external to the organization, as is the case of service providers; or if it resides in it, your competencies will vary, despite sharing objective: ensure data integrity finally.

Information security outside the organization: Service providers
The responsibility of service providers, as the most common representatives of figures outside the organization who can interact with your information, creating a security violation; is summarized as a document.
The Service Level Agreements determine the objectives that should guide and that compromise these IT companies in outsourcing mode, defining your responsibility for data protection. The basic concepts that this statement of commitment should understand are:
– Technology control, and in addition to its operation.
– Making backup copies, that act as backup.
– Implementation of recovery processes, to launch if necessary.
Attention should be paid that the owners of the systems, the owners and managers of the information, are not exempt from their responsibility in matters of security of the information since other obligations will fall on them, like all those associated with data management and governance, essential to maintain data integrity in the organization within the desired standards.
Information security in an internal environment of the organization: internal IT area
Even though the IT area It is outsourced on numerous occasions, there are also companies that have their own IT department. In it would be found the figures of security boss, DBA and data architect.
The data integrity objective It is closely linked to this area but, far from belonging to it or concentrating all the responsibilities derived here, it should be extrapolated to the different affected departments. This vision is especially important when we talk about integrity flaws or human error Y, thus, it is essential that, as roles and responsibilities, each area take responsibility for its plot, its production and its scope of competence. Always having the option to come to you if a problem arises. All members of the organization are responsible for what they do, consume and produce.
Photo credits: “Business Network” by sheelamohan



