a. ensuring the development, maintenance, updating and implementation of security risk
management plans, system security plans and any security procedures used.
b. providing technical security advice involved with system development, acquisition,
implementation, modification, operation, support, and architecture
c. assisting the system manager to develop system security standards/policies
d. the certification of systems, when applicable
e. ensuring the agency has an appropriate ICT security awareness and training program.
f. the regular review of system security, system audit trails and logs and the integrity of system
configurations.
IG 10.
Ensure the Security Manager is familiar with all security operating procedures relating to systems,
including to the roles of system managers, system administrators and system users.
2. Risk Management [RM]
2.1. Policy Objective
This policy defines the requirement to conduct risk assessment to devise a suitable risk treatment plan for information
assets, which have been classified as having an aggregate security level of Medium or High [IAP-NAT-DCLS] and keep
the residual risk to an acceptable level depending on the Agency’s risk appetite.
2.2. Policy & Baseline Controls
To meet the requirements of this policy Agencies MUST:
RM 1.
*Define a risk assessment process to identify threats and vulnerabilities to critical
information assets (identified with an aggregate security level of Medium or High).
RM 2.
*Based on the assessment, define a risk treatment plan to address threats and
vulnerabilities.
RM 3.
Ensure that the risk treatment plan and residual risk selected for information assets, with an
aggregate security level of High, are vetted by senior management in the Agency.
RM 4.
Ensure that the controls chosen in RM2 & RM3 are monitored for effectiveness on a periodic basis.
RM 5.
Risk assessments should be integrated within the business process and revised whenever there is
a change. Changes in the business or legal/regulatory environment may also warrant the need to
do risk assessment.
3. Third Party Security Management [TM]
3.1. Policy Objective
The purpose of this policy is to ensure that the baseline policy and controls specified in this NIA Manual are maintained
in service(s) that have been outsourced to a third party.
3.2. Policy & Baseline Controls
To meet the requirements of this policy Agencies MUST ensure:
19
TM1.
*The areas or services being outsourced remain the governance, compliance and risk
management accountability of the Agency.
TM2.
*They understand and acknowledge the risks associated with the outsourcing of their
services.
TM3.
That the security controls and baseline policy specified in this NIA Manual are included in the third
party service delivery agreement or contract. This SHALL also apply to sub-contractors used by the
third party.
TM4.
The third party SHALL be contractually required to regularly report on the outsourced service’(s)
NATIONAL INFORMATION ASSURANCE MANUAL