B. SECURITY GOVERNANCE & SECURITY PROCESSES This section provides controls on how Security Governance should be established in an Agency. It also highlights some of the key activities that need to be established to ensure security is maintained to this baseline standard. The activities covered are Risk Management, Third Party Security Management, Data Labelling, Change Management, Personnel Security, Security Awareness, Incident Management, Business Continuity Management, Logging, Auditing & Security Monitoring, Data Retention & Archival, Documentation, and finally Certification. 1. Governance Structure [IG] 1.1. Policy Objective The objective of this policy is to define an Information Security Governance structure for Agencies. 1.2. Policy & Baseline Controls In order to comply with this policy, Agencies SHALL: IG 1. *Appoint a person to own and manage the Information Security programme. This person will be referred to as the ‘Security Manager’ within this NIA Manual. IG 2. *Allocate appropriate budget to staff and operate the Information Security Programme. IG 3. *Ensure the Security Manager has a reporting line to the Agency’s risk or internal audit function. IG 4. *Ensure that the Agency head provides documented and continuous support for the development, implementation and ongoing maintenance of ICT security processes and infrastructure within their Agency. IG 5. Where the Agency head delegates their authority to approve variations from requirements in this manual the delegate must have higher authority than the Security Manager. IG 6. Define information security responsibilities for the Security Manager, management, employees and/or outsourced/3rd party vendors, suppliers or contractors of the Agency. IG 7. *Ensure the Security Manager has: a. ready access to, and full support from, executive management b. familiarity with information security and/or ICT security c. a general knowledge of, and experience in, or necessary resources in systems used by the Agency, especially operating systems, access & authorisation control systems/facilities and auditing facilities. d. a reasonable capacity and competence to support the Security Manager role. IG 8. Include the following responsibilities within the Security Manager’s role: a. identifying and recommending ICT security improvements to all business systems and business processes. b. ensuring ICT security aspects are considered as part of the change management process. c. ensuring the coordinating of development, maintenance and implementation of all ICT security documentation, in conjunction with the business managers. d. ensuring timely reporting and adequate participation in investigation for ICT security incidents, with Q-CERT. IG 9. Ensure the Security Manager is responsible for: NATIONAL INFORMATION ASSURANCE MANUAL 18

Select target paragraph3