- Code of Conduct & Workforce Accountability Cycle — HR; with Compliance & Legal · 6 steps
Adopt the code of conduct and its performance, incentive and disciplinary expectations; communicate it, gate access on acknowledgments, assess violations and verify timely disciplinary and remediation outcomes.
- Control Responsibility Communications & Ethics Hotline — Compliance & Legal; with HR · 6 steps
Approve tailored control-responsibility communications, assess acknowledgment coverage and verify concern-raising channels; test anonymous intake routing, review real matters and retain quarterly evidence with owned exceptions.
- Employee Offboarding — HR; with IT · 4 steps
HR authorizes the departure and effective time, IT evidences removal, the manager transfers work and assets, and HR decides closure with residual obligations visible.
- Employee Onboarding — HR; with IT · 3 steps
HR and the manager approve joiner facts and entitlements, IT evidences access grants, and HR resolves readiness conditions before recording an active engagement.
- Joiner-Mover-Leaver Access Lifecycle — IT; with HR · 6 steps
Handle joiner, mover, and leaver events end-to-end: provision role-based access, adjust with SoD checks on transfer, and evidence timely removal on exit.
- Personnel Screening, Agreements & Sanctions Administration — HR · 8 steps
Apply proportional personnel screening, adjudicate adverse findings and obtain required signed security agreements before access; determine consistent sanctions on substantiated violations and retain the access/notification evidence and rescreen record.
- Recruiting and Hiring Decision — HR · 4 steps
Approve a requisition, review candidates against job criteria, assess interview evidence and authorize an offer handoff.
- Security Awareness Training Campaign — IT; with HR · 4 steps
Run a security awareness campaign end-to-end: curriculum, launch, completion tracking, phishing simulation, escalation, and effectiveness reporting.
- Subservice Organization & Third-Party Personnel Oversight — Procurement; with HR · 7 steps
On the annual per-vendor cycle with quarterly issue follow-up, the vendor risk manager enriches each subservice organization's Vendor register entry, verifies its contracts and assurance reports bind it to the security, data-processing, and third-party personnel-security commitments matching its mapped control objectives, and maps the assurance report's complementary user-entity controls (CUECs) to the organization's internal Controls. Every identified gap becomes a tracked Issue followed to closure, and the cycle closes into an archived, auditor-ready vendor file.
- User Activity & External Exposure Monitoring — IT; with HR · 7 steps
Operate the monthly cycle of the standing user-activity and external-exposure monitoring control: review captured privileged and remote session activity and personnel technology usage against acceptable-use expectations, restricting access to authorized reviewers and routing findings to HR and legal counsel per the disclosed monitoring terms. In the same cycle, sweep external open-source and dark-web channels for improperly disclosed organizational information, alerting designated personnel and initiating takedown on discovery, with every confirmed finding from both halves recorded as an Issue linked to the control and consolidated into one restricted case log feeding security-event evaluation.
- Workplace & Remote Work Security Cycle — IT; with HR, Facilities · 6 steps
Operate the quarterly workplace and remote-work security cycle: walk offices for clear-desk, clear-screen, and output-device compliance, and verify and enforce remote-working device, privacy, environment, and connectivity attestations before granting access. Review the approved alternate-work-site list, assess control effectiveness, and confirm workers there have a functioning incident-reporting channel.