• Regularly scheduled maintenance • Changes that are not likely to cause a service outage c. Emergency and Unplanned Outage Changes. Examples of this type of change are: •  A severe degradation of service needing immediate action •  A system/application/component failure causing a negative impact on business operations •  A response to a natural disaster •  A response to an emergency business need •  A change requested by emergency responder personnel CM 2. Establish a cross functional Change Management Committee which must include representation from security and risk divisions CM 3. Document and Approve all proposed changes through the relevant Change Management Committee. CM 4. *Ensure that upon implementing any proposed change that may impact the security of the ICT system assess whether the system will require re-certification. The system MUST comply with baseline requirements at minimum even after change implementation. Risk analysis may be required to ensure residual risk at acceptable level. CM 5. All associated system documentation is updated to reflect the change. CM 6. Emergency changes may be carried out on the basis of a verbal/informed approval from the Change management committee Head and the Business process owner. However, post emergency, the standard procedure for documenting and risk analysis is to be applied. 6. Personnel Security [PS] 6.1. Policy Objective The objective of this policy is to ensure that personnel (staff, vendors, contractors, and others) deployed with the Agencies are aware of their security responsibilities and that suitable controls are in place to mitigate risks arising out of human element. 6.2. Policy & Baseline Controls To meet the requirements of this policy Agencies SHALL: 21 PS 1. Ensure that the Human Resources (HR) processes are aligned with information security policies and initiatives of the organization. PS 2. *Ensure the HR department documents security requirements and obligations and ways of working in HR manual, which is read, understood and available to all staff to ensure they are aware and comply with their obligations to information security. PS 3. *Obtain, manage and retain information related to personnel with due care and due diligence, in line with the requirements for handling Personal Information as specified in the proposed information Privacy and Protection Law. PS 4. Ensure information security responsibilities are included as part of the employees’ job responsibilities and job descriptions and are applied throughout an individual’s employment within the organization. PS 5. *Conduct adequate screening to ascertain the integrity of prospective candidates for employment and contractors (including sub-contracted workers). The Agency may further extend this exercise to existing employees as deemed necessary to satisfy conditions arising out of factors such as but not limited to “Change of employee responsibilities” or “Suspicion raised on the conduct of an employee”. PS 6. *Ensure that staff sign an agreement, on joining the Agency or when there is a change in job profile or duties, which outlines their security obligations and responsibilities. This SHALL include: NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3