Policies and Standards Manager

advertisement
Manchester City Council
Role Profile
Policies, Standards & Governance Manager, Grade 10
ICT Service, Chief Executives Directorate
Reports to: Strategy, Governance and Compliance Manager
Key Role Descriptors:
The roleholder will plan and deliver policies and standards and provide
guidance on governance, processes, procedures, tools and techniques to the
business and service based ICT teams.
The roleholder will develop and manage evaluation plans, including scheduled
internal and external audits, penetration testing, self assessment, evaluation
following incidents and reporting.
Key Role Accountabilities:
Ensure appropriate and effective governance and compliance is consistently
applied.
Be the owner of all governance processes within the service, ensuring these
are continually reviewed, updated and communicated to the appropriate
audiences throughout the Council.
Conduct governance and compliance self-assessments for the ICT Service,
reporting on governance and compliance breaches and monitor, facilitate,
and in appropriate circumstances partake in, remedial actions to help
eliminate or mitigate governance and compliance risks and non compliance
with legislation and regulation including independent audit findings.
Analyse the impact of applicable legislation and regulation to existing
operating processes, policies, procedures and standards and make
recommendations for amendments as appropriate.
Undertake risk assessments and make recommendations for action, ensuring
that the Service Areas Business Continuity Plan and Disaster Recovery Plan
are considered.
Ensure the dissemination of procedures, standards and related materials.
Ensure that all ICT policies, standards and processes meet legal and service
requirements and are in accordance with best practice, working in conjunction
with relevant managers in services to ensure effective implementation. The
roleholder will be accountable for all aspects of the Information Security
Management Framework.
People. Pride. Place.
Ensure that effective security levels are maintained and monitored,
evaluating. The roleholder will ensure that relevant sections of the service
level agreement (SLA) are fit for purpose, working to agree any underpinning
contracts with suppliers.
Act as centre of security expertise for the organisation.
Ensure that a performance management culture is prevalent throughout the
ICT service, and that comprehensive statistics around service provision are
maintained and reported upon.
Develop and maintain installation, fault diagnosis, investigative analysis and
rectification standards for the organisation, ensuring they are in accordance
with professional and international standards of security.
Accountable for service continuity management plans and processes for the
ICT Service. The roleholder will conduct regular analysis of business impact
to determine priority recoveries in the event of a major incident and will own
the availability plan for the information and network security, monitoring actual
availability against the plan and agreed service levels.
Develop effective processes to measure and monitor security and system
reliability and maintainability.
Work collaboratively across directorates and partners in order to achieve
quality partnerships with internal and external customers, service managers
and external agencies and organisations to achieve the objectives of the ICT
Service. The roleholder will work with services to identify ICT security assets,
threats, vulnerabilities and countermeasures.
Personal commitment to continuous self development and service
improvement.
Through personal example, open commitment and clear action, ensure
diversity is positively valued, resulting in equal access and treatment in
employment, service delivery and communications.
Where the roleholder is disabled every effort will be made to supply all
necessary aids, adaptations or equipment to allow them to carry out all
the duties of the role. If, however, a certain task proves to be
unachievable, job redesign will be given full consideration.
People. Pride. Place.
Policies, Standards & Governance Manager– Key Competencies and
Technical Requirements
Behavioural Competencies





Leadership & Management: The behaviours and actions of our
managers define how we work and what we achieve.
Change: Improving services and making the most of resources.
Delivery: Delivery of high quality services is an essential part of what
we do.
Pride in Manchester: Demonstrating pride in our city.
Influence: Effective relationships give the best results.
Generic Skills
Communication Skills - Ability to build and maintain strong networks of
support both internally and externally and to forge effective partnerships with
external agencies, voluntary and statutory, and key stakeholders for the
continuous improvement of services. Ability to harness the full commitment
and responsibility of key stakeholders in delivering the vision for excellence
for the city.
Analytical Skills - Skills to analyse a wide range of data and other sources of
information to break them down into component parts, patterns and
relationships; probes for further understanding of problems and makes
rational judgements from the available information and analysis demonstrating
and understanding of how one issue or risk may be part of a much larger
system/issue.
Planning and Organising - Sets clearly defined objectives, plans activities
and projects well in advance and takes account of risks and changing
circumstances; identifies and organises resources and manages time
effectively monitoring performance against milestones and deadlines.
Project Management & Change Management - Proven ability in developing
complex project schedules that clearly defines the timeline required to achieve
the required outcomes, with expertise in identifying and monitoring
complicated interdependencies, identifying and managing the critical path and
utilising the schedule in budget forecasting and planning future resource
requirements.
Problem Solving and Decision Making - Uses creative ability to find
solutions and whilst considering policy and procedure is also confident in
adopting (and justifying) novel or non standard approaches.
ICT Skills - Skills to perform risk assessment, business impact analysis and
accreditation for major information systems within the organisation; provide
authoritative advice and guidance on security strategies to manage the
identified risk.
Research & Intelligence - Demonstrate the ability to analyse, organise and
present research material in an appropriate format.
Strategic Thinking - Contributes to the development, implementation and
evaluation of strategy to shape future plans
People. Pride. Place.
Technical requirements (Role Specific)



Qualified to ITIL v3 Foundation, or willing to work towards.
Significant knowledge of the relevant legislative framework and
professional standards both within the ICT industry and in particular to
a Local Authority.
Significant understanding of the ISO27000-series
People. Pride. Place.
Download