The system should at all times remain in the control of its managers.
This means that the management will observe the operation and behaviour of the system, will make decisions about how to control it based on these observations, and will implement actions to exert that control.
|
|
| namespace | SABSA |
| stereotype | ManagementAttribute |
| softMetric | Independent audit and review against Security Architecture Capability Maturity Model. |