<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Patrick+Smiley</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Patrick+Smiley"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Patrick_Smiley"/>
		<updated>2026-06-03T01:59:31Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_D&amp;diff=75304</id>
		<title>Talk:Industry:Project Review/NIST SP 800-37r1 FPD Appendix D</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_D&amp;diff=75304"/>
				<updated>2009-12-20T12:02:03Z</updated>
		
		<summary type="html">&lt;p&gt;Patrick Smiley: /* D.11  INFORMATION SECURITY ARCHITECT */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| align=&amp;quot;right&amp;quot;&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;APPENDIX D&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''ROLES AND RESPONSIBILITIES'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
KEY PARTICIPANTS IN THE RISK MANAGEMENT PROCESS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.1  HEAD OF AGENCY (CHIEF EXECUTIVE OFFICER) ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.2  RISK EXECUTIVE (FUNCTION) ==&lt;br /&gt;
It seems that so far, no one role is specifically required or has the objective to define one or more organizational methods for risk calculation.  From personal experience, it is too easy to ignore one risk set in deference for another because of professional unfamiliarity with the first.  An objective risk calculation toolset defined by organizational management provides a framework for first identifying risk, then prioritizing the addressing of risks.&lt;br /&gt;
&lt;br /&gt;
== D.3  CHIEF INFORMATION OFFICER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.4  INFORMATION OWNER/STEWARD ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.5  SENIOR INFORMATION SECURITY OFFICER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.6  AUTHORIZING OFFICIAL ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.7  AUTHORIZING OFFICIAL DESIGNATED REPRESENTATIVE ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.8  COMMON CONTROL PROVIDER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.9  INFORMATION SYSTEM OWNER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.10  INFORMATION SYSTEM SECURITY MANAGER/OFFICER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.11  INFORMATION SECURITY ARCHITECT ==&lt;br /&gt;
Placing the Information Security Architect at the level of system-specific personnel, but ascribing to the position &amp;quot;requirements to protect the organization's core mission and business processes&amp;quot; is a grave mistake.  This is confusing in that the System Owner and ISSO duties are specific to the level of the system with an eye toward the overall organization/agency/nation.  This description needs to be re-addressed to better discuss the role at the system level.&lt;br /&gt;
&lt;br /&gt;
== D.12  INFORMATION SYSTEM SECURITY ENGINEER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.13  SECURITY CONTROL ASSESSOR ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Footnotes==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:GIC-NISTSP80037r1FPD]]&lt;/div&gt;</summary>
		<author><name>Patrick Smiley</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_D&amp;diff=75303</id>
		<title>Talk:Industry:Project Review/NIST SP 800-37r1 FPD Appendix D</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_D&amp;diff=75303"/>
				<updated>2009-12-20T11:42:42Z</updated>
		
		<summary type="html">&lt;p&gt;Patrick Smiley: /* D.2  RISK EXECUTIVE (FUNCTION) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| align=&amp;quot;right&amp;quot;&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;APPENDIX D&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''ROLES AND RESPONSIBILITIES'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
KEY PARTICIPANTS IN THE RISK MANAGEMENT PROCESS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.1  HEAD OF AGENCY (CHIEF EXECUTIVE OFFICER) ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.2  RISK EXECUTIVE (FUNCTION) ==&lt;br /&gt;
It seems that so far, no one role is specifically required or has the objective to define one or more organizational methods for risk calculation.  From personal experience, it is too easy to ignore one risk set in deference for another because of professional unfamiliarity with the first.  An objective risk calculation toolset defined by organizational management provides a framework for first identifying risk, then prioritizing the addressing of risks.&lt;br /&gt;
&lt;br /&gt;
== D.3  CHIEF INFORMATION OFFICER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.4  INFORMATION OWNER/STEWARD ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.5  SENIOR INFORMATION SECURITY OFFICER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.6  AUTHORIZING OFFICIAL ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.7  AUTHORIZING OFFICIAL DESIGNATED REPRESENTATIVE ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.8  COMMON CONTROL PROVIDER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.9  INFORMATION SYSTEM OWNER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.10  INFORMATION SYSTEM SECURITY MANAGER/OFFICER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.11  INFORMATION SECURITY ARCHITECT ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.12  INFORMATION SYSTEM SECURITY ENGINEER ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== D.13  SECURITY CONTROL ASSESSOR ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Footnotes==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:GIC-NISTSP80037r1FPD]]&lt;/div&gt;</summary>
		<author><name>Patrick Smiley</name></author>	</entry>

	</feed>