Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
pub:company:accountability_chart:start [21.07.2026 13:29] – Update Accountability Chart with ISO 20000-1 and ISO 27001 role assignments Predrag Tasevskipub:company:accountability_chart:start [21.07.2026 13:53] (current) – [How These Roles Support Commitments] Predrag Tasevski
Line 11: Line 11:
 ===== SMS & ISMS Role Assignments (October 2026) ===== ===== SMS & ISMS Role Assignments (October 2026) =====
  
-As Unicis pursues **ISO 20000-1:2018** (Service Management System) and **ISO 27001:2022** (Information Security Management System) certification, the following role assignments are effective:+As Unicis pursues **[[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]]** (Service Management System) and **[[pub:trust_center:iso_27001_overview|ISO 27001:2022]]** (Information Security Management System) certification, the following role assignments are effective:
  
 ^ Seat ^ SMS Role (ISO 20000-1) ^ ISMS Role (ISO 27001) ^ Responsibility ^ ^ Seat ^ SMS Role (ISO 20000-1) ^ ISMS Role (ISO 27001) ^ Responsibility ^
-| **CEO (Predrag)** | SMS Sponsor / Service Strategy Owner | ISMS Sponsor / Information Security Policy Approval | Oversees both systems; approves policies and budgets; reviews metrics quarterly | +| **CEO (Predrag)** | **SMS Sponsor / Service Strategy Owner** **ISMS Sponsor / Information Security Policy Approval** | Oversees both systems; approves policies and budgets; reviews metrics quarterly | 
-| **CTO (Peter)** | Service Delivery Owner, Incident Response Owner | Information Security Implementation, Incident Response Lead | Technical lead for service reliability and security; manages incidents, vulnerabilities, deployments | +| **CTO (Peter)** | **Service Delivery Owner, Incident Response Lead** **Information Security Implementation, Technical Controls Lead** | Technical lead for service reliability and security; manages incidents, vulnerabilities, deployments | 
-| **Operations (Alexander)** | Support Manager, Change Management | Access Control Manager, Incident Escalation | Operational responsibilities for service delivery; manages user provisioning and support escalation | +| **Operations (Alexander)** | **Support Manager, Change Management Owner** **Access Control Manager, Incident Escalation Lead** | Operational responsibilities for service delivery; manages user provisioning and support escalation | 
-| **Marketing (Ksenija)** | Communications & Stakeholder Updates | Security Awareness & Training Lead | Supports communications around service updates and security awareness training |+| **Marketing (Ksenija)** | **Communications & Stakeholder Updates Lead** **Security Awareness & Training Lead** | Supports communications around service updates and security awareness training |
  
 ---- ----
Line 25: Line 25:
 === SMS (Service Management System) Roles === === SMS (Service Management System) Roles ===
  
-  * **SMS Sponsor** (Predrag) — Owns the SMS as a whole; ensures it delivers value +Per **[[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]]**, the SMS requires: 
-  * **Service Delivery Owner** (Peter) — Accountable for incident response, problem management, capacity planning + 
-  * **Support Manager** (Alexander) — Owns customer support interactions; escalates critical issues+  * **SMS Sponsor** (Predrag) — Owns the SMS as a whole; ensures it delivers value and gets resources 
 +  * **Service Delivery Owner** (Peter) — Accountable for incident response, problem management, capacity planning, deployment success 
 +  * **Support Manager** (Alexander) — Owns customer support interactions; escalates critical issues; manages response SLAs
   * **Communications** (Ksenija) — Communicates service updates and SLA performance to stakeholders   * **Communications** (Ksenija) — Communicates service updates and SLA performance to stakeholders
 +
 +**Related Metrics:** [[pub:company:scorecard|Scorecard #6, #11, #12, #14]] (uptime, incident response, patches, deployments)
  
 === ISMS (Information Security Management System) Roles === === ISMS (Information Security Management System) Roles ===
  
-  * **ISMS Sponsor** (Predrag) — Owns information security direction; approves policies +Per **[[pub:trust_center:iso_27001_overview|ISO 27001:2022]]**, the ISMS requires: 
-  * **Information Security Implementation** (Peter) — Implements technical security controls; manages vulnerabilities + 
-  * **Access Control Manager** (Alexander) — Manages user access requests, approvals, and deprovisioning+  * **ISMS Sponsor** (Predrag) — Owns information security direction; approves policies; allocates security budget 
 +  * **Information Security Implementation** (Peter) — Implements technical security controls; manages vulnerabilities; leads incident investigation 
 +  * **Access Control Manager** (Alexander) — Manages user access requests, approvals, and deprovisioning; tracks access control compliance
   * **Security Awareness Lead** (Ksenija) — Delivers security training and awareness to team   * **Security Awareness Lead** (Ksenija) — Delivers security training and awareness to team
 +
 +**Related Metrics:** [[pub:company:scorecard|Scorecard #9, #12, #13]] (security alerts, patch deployment, access provisioning)
  
 ---- ----
  
-===== Related ======+===== How These Roles Support Commitments ===== 
 + 
 +^ Commitment ^ Owner ^ How It's Measured ^ 
 +| **99% Platform Uptime** | Peter (Service Delivery) | [[pub:company:scorecard#11|Scorecard #6]] — Real-time uptime % | 
 +| **2-hour P1 Response** | Peter + Alexander (Incident Response) | [[pub:company:scorecard#11|Scorecard #11]] — Avg response time | 
 +| **8-hour P2 Response** | Alexander (Support Manager) | [[pub:company:scorecard|Scorecard]] — Avg response time | 
 +| **7-day Patch Deployment** | Peter (Security Implementation) | [[pub:company:scorecard#12|Scorecard #12]] — Days to deploy | 
 +| **1-day Access Provisioning** | Alexander (Access Control) | [[pub:company:scorecard#13|Scorecard #13]] — Days to provision | 
 +| **99% Deployment Success** | Peter (Service Delivery) | [[pub:company:scorecard#14|Scorecard #14]] — Success % | 
 + 
 +See [[pub:company:scorecard|Service Performance Scorecard]] for real-time performance. 
 + 
 +---- 
 + 
 +===== Related Documentation ===== 
 + 
 +**Standards & Certifications:** 
 +  * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018 Overview]] — Service Management System 
 +  * [[pub:trust_center:iso_27001_overview|ISO 27001:2022 Overview]] — Information Security Management System 
 +  * [[pub:trust_center:isms_policy|Information Security Policy]] — Security commitment details 
 +  * [[pub:company:service_strategy|Service Strategy & Commitments]] — Service delivery commitments 
 + 
 +**Performance & Governance:** 
 +  * [[pub:company:scorecard|Scorecard]] — Real-time role metrics and targets 
 +  * [[pub:company:traction|Quarterly Planning & Reviews]] — How roles review performance 
 +  * [[pub:trust_center:risk_framework|Risk Assessment Framework]] — How roles manage risks 
 + 
 +**Policies & Procedures:** 
 +  * [[pub:trust_center:document_control_procedure|Document Control Procedure]] — How policies are approved and maintained 
 +  * [[pub:trust_center:policies:it_security_policy|IT Security Policy]] — Detailed security procedures 
 + 
 +---- 
 + 
 +====Quarterly Accountability Review ===== 
 + 
 +Each quarter (Q1/Q2/Q3/Q4), role owners review: 
 + 
 +  * Their assigned metrics on [[pub:company:scorecard|Scorecard]] 
 +  * Performance against [[pub:company:service_strategy|Service Strategy]] commitments 
 +  * Changes needed for [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] or [[pub:trust_center:iso_27001_overview|ISO 27001]] compliance 
 +  * Updates to the [[internal:company:accountability_chart|Full Accountability Chart]] (internal) 
 + 
 +Results are discussed in [[pub:company:traction|Quarterly Planning Sessions]]. 
 + 
 +----
  
-  * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018 — Service Management]] +[[pub:trust_center|← Trust Center]] | [[pub:company:scorecard|Scorecard ]]
-  * [[pub:trust_center:iso_27001_overview|ISO 27001:2022 — Information Security]] +
-  * [[pub:company:scorecard|Scorecard — Performance metrics by role]] +
-  * [[pub:company:traction|Traction & Quarterly Planning]]+
  
 ---- ----