- VCC's Cyber Security Governance Framework (the Framework) consists of the following:
- Oversight Responsibilities
- Cyber Security Risk Management Program (the Program)
- Cyber Security Risk Exception Process
- Cyber Security Risk Register
A. Oversight Responsibilities
- The VCC Board of Governors (the Board) is responsible for:
- Full oversight of the Framework, and delegates this authority to the Finance and Audit Committee.
- Reviewing the Framework on an annual basis.
- Adopting an orientation program for new board members that outlines the Board's responsibilities of oversight of the Framework and Program.
- Adopting an annual development program for all board members that includes training and updates on cyber security risk management.
- The President is responsible for:
- Ongoing oversight of the Framework and Program.
- The Chief Information Officer (the CIO) is responsible for:
- Establishing and managing the Cyber Security Standards and the Cyber Security Risk Exception process, and ensuring they are consistent with this Policy.
- Establishing and managing the VCC Cyber Security Risk Register, which contains all identified cyber security risks as well as the related mitigation strategies and plans.
- Managing the Framework and Program through delegates.
- Appointing members to the Cyber Security Governance Working Group (CyberGWG).
- Providing an annual oversight report of the Framework and Program to the Board and President.
B. Cyber Security Risk Management Program
The Program consists of:
- VCC Cyber Security Standards (the Standards)
- The Standards cover all technical aspects of the cyber security risk management and establish mandatory baselines and controls for all VCC users, digital information, processes, and systems. The main goal of these baselines and controls is to protect confidentiality, integrity, privacy, and availability of all VCC cyber resources and assets.
- The Standards are defined, reviewed, and approved by the Cyber Security Governance Working Group (CyberGWG).
- Cyber Security Governance Working Group (CyberGWG)
- The CyberGWG is a high-level technical group delegated by the CIO to review and approve VCC's Cyber Security Standards (the Standards).
- Using an industry standard cyber security framework, the CyberGWG will assess on an annual basis the maturity of the Framework, Program and Standards. This assessment will be included in the oversight report provided by the CIO to the Board and President.
- Awareness and Training
- Training and awareness are part of the overall VCC onboarding process.
- Annual renewal of cyber security training is required by all employees.
- Additional training may be required when new cyber security technology or processes are implemented.
C. Cyber Security Risk Exception Process
- Depending on the use case, if a mandatory baseline cannot be met due to specific business and/or technical reasons, a Risk Exception request can be initiated for review and approval by the CIO or appointed delegates.
- The CIO or appointed delegates review, assess and approve Risk Exception requests based on business justified violations of the Standards, through a dedicated process within the IT department.
- Risk Exception requests must have a remediation plan and a defined timeline for aligning the corresponding cyber resources/assets/processes with the requirements of the violated Standards.
- When approving a specific Risk Exception request, the CIO or delegates can sometimes require a list of compensating controls to be applied during the Risk Exception timeline to manage the inherent risk. These compensating controls are mandatory for the team requesting the Exception.
D. Cyber Security Risk Register
- The CIO, or delegates, manage VCC Cyber Security Risk Register by performing various assessment processes to identify significant cyber security risks for the College. These can be, but not limited to, technical vulnerabilities (both hardware and software), process weaknesses, deficiencies in user behaviour, awareness etc.
- The Cyber Security Risk Register also contains the approved Risk Exception requests during their lifecycle, i.e. until they are remediated and closed.
- The Cyber Security Risk Register is the authoritative source of information representing the current cyber security risks for the College.
- Items in the Cyber Security Risk Register must be prioritized by the CIO or appointed delegates, based on the assessed risk of each item.
- The high-priority items of the Cyber Security Risk Register representing the most significant cyber security risks for the College are escalated to the institutional risk register as managed by the Department of Safety, Security, Risk and Privacy and are presented by the CIO in the oversight reports to the President and the Board of Governors.