Jump to Navigation

 

3.3.2 Staff Commitment Control Objectives

As highlighted above, the role of individuals involved is also essential and that accountability must be ensured down to the employee level. Accountable organisations must provide individuals with the necessary tools and procedures to be individually accountable. These control objectives correspond to that requirement.

Identifier

Control Objective

Lifecycle Phase

1.05

Ensure a proactive attitude towards the object of accountability across the organisation. For example, if the organisation aims to be accountable for its handling of private and confidential data, the staff must be specifically trained on the topic, and commitment to protecting the privacy and confidentiality of user data must be included as an expected behaviour for all staff members.

1+2 - Governance

1.06

Drive the adoption of an accountability-driven mindset. Ensure that it is integrated with the core values of the organisation (e.g. code of conduct, ethical guidelines, list of values) and committed at the individual level (signoff). Provide appropriate tools, training, processes, and instruments to report on the state of the accountability program (including a set of metrics).

1+2 - Governance

Table 5: Staff commitment control objectives.