• Regularly scheduled maintenance
• Changes that are not likely to cause a service outage
c. Emergency and Unplanned Outage Changes. Examples of this type of change are:
• A severe degradation of service needing immediate action
• A system/application/component failure causing a negative impact on business operations
• A response to a natural disaster
• A response to an emergency business need
• A change requested by emergency responder personnel
CM 2.
Establish a cross functional Change Management Committee which must include representation
from security and risk divisions
CM 3.
Document and Approve all proposed changes through the relevant Change Management Committee.
CM 4.
*Ensure that upon implementing any proposed change that may impact the security of
the ICT system assess whether the system will require re-certification. The system MUST
comply with baseline requirements at minimum even after change implementation. Risk analysis
may be required to ensure residual risk at acceptable level.
CM 5.
All associated system documentation is updated to reflect the change.
CM 6.
Emergency changes may be carried out on the basis of a verbal/informed approval from the Change
management committee Head and the Business process owner. However, post emergency, the
standard procedure for documenting and risk analysis is to be applied.
6. Personnel Security [PS]
6.1. Policy Objective
The objective of this policy is to ensure that personnel (staff, vendors, contractors, and others) deployed with the
Agencies are aware of their security responsibilities and that suitable controls are in place to mitigate risks arising out
of human element.
6.2. Policy & Baseline Controls
To meet the requirements of this policy Agencies SHALL:
21
PS 1.
Ensure that the Human Resources (HR) processes are aligned with information security policies and
initiatives of the organization.
PS 2.
*Ensure the HR department documents security requirements and obligations and ways
of working in HR manual, which is read, understood and available to all staff to ensure
they are aware and comply with their obligations to information security.
PS 3.
*Obtain, manage and retain information related to personnel with due care and due
diligence, in line with the requirements for handling Personal Information as specified in
the proposed information Privacy and Protection Law.
PS 4.
Ensure information security responsibilities are included as part of the employees’ job
responsibilities and job descriptions and are applied throughout an individual’s employment within
the organization.
PS 5.
*Conduct adequate screening to ascertain the integrity of prospective candidates for
employment and contractors (including sub-contracted workers). The Agency may further
extend this exercise to existing employees as deemed necessary to satisfy conditions arising out
of factors such as but not limited to “Change of employee responsibilities” or “Suspicion raised on
the conduct of an employee”.
PS 6.
*Ensure that staff sign an agreement, on joining the Agency or when there is a change
in job profile or duties, which outlines their security obligations and responsibilities. This
SHALL include:
NATIONAL INFORMATION ASSURANCE MANUAL