Preparation

Step # Task Overall Responsible Personnel
Step 1 College/Division assigns D-RACs Dean/VP IT Staff
Step 2 D-RAC assigns RACs D-RAC IT Staff
Step 3 Provide the Risk Assessment Inventory list to the units IT-RMP

Phase 1: Inventory Management/Resource Identification and Grouping

Step # Task Overall Responsible Personnel
Step 1 Identify all information resources/ensure any unit level inventory list is up-to-date D-RAC RAC, IT Staff
optional Compare unit inventory list to CANOPY/FAMIS list D-RAC RAC
Step 2  Complete the Risk Assessment Inventory List. This is where the information resources managed by unit IT staff will be grouped. The roles of assessor and reviewer will also be determi D-RAC RAC, IT Staff

Phase 2: Assessment and Review

Step # Task Overall Responsible Personnel
Step 1 Complete the assessment responses.  D-RAC IT staff, assessor, reviewer
Step 2 Review the assessment which includes either approving or rejecting the assessment responses.  Reviewer D-RAC, Assessor
optional If the assessment is rejected, discuss any issue(s) about the assessment. Reviewer Assessor
Step 3 Respond to any generated findings.  Assessor IT-RMP, Reviewer
Step 4 Review the finding responses which includes either approving or rejecting them. Reviewer IT-RMP, Reviewer
Optional If a finding response is rejected, discuss with the assessor why it was rejected. Reviewer Assessor
Optional Finding responses dealing with resources (budget, personnel, equipment, etc.) could be taken to the dean/VP to ensure there will be no surprises at the end of the process.  IT-RMP Assessor, Reviewer

Phase 3: Reporting

Step # Task Overall Responsible Personnel
Step 1 Calculate scores and create reports once the college/division is completed with Phase 2. Colleges/divisions with non-IT professionals must finish the Non-IT Professional process.  IT-RMP
Step 2