B. SECURITY GOVERNANCE
& SECURITY PROCESSES
This section provides controls on how Security Governance should be established in an Agency. It also highlights
some of the key activities that need to be established to ensure security is maintained to this baseline standard. The
activities covered are Risk Management, Third Party Security Management, Data Labelling, Change Management,
Personnel Security, Security Awareness, Incident Management, Business Continuity Management, Logging, Auditing
& Security Monitoring, Data Retention & Archival, Documentation, and finally Certification.
1. Governance Structure [IG]
1.1. Policy Objective
The objective of this policy is to define an Information Security Governance structure for Agencies.
1.2. Policy & Baseline Controls
In order to comply with this policy, Agencies SHALL:
IG 1.
*Appoint a person to own and manage the Information Security programme. This person
will be referred to as the ‘Security Manager’ within this NIA Manual.
IG 2.
*Allocate appropriate budget to staff and operate the Information Security Programme.
IG 3.
*Ensure the Security Manager has a reporting line to the Agency’s risk or internal audit
function.
IG 4.
*Ensure that the Agency head provides documented and continuous support for the
development, implementation and ongoing maintenance of ICT security processes and
infrastructure within their Agency.
IG 5.
Where the Agency head delegates their authority to approve variations from requirements in this
manual the delegate must have higher authority than the Security Manager.
IG 6.
Define information security responsibilities for the Security Manager, management, employees
and/or outsourced/3rd party vendors, suppliers or contractors of the Agency.
IG 7.
*Ensure the Security Manager has:
a. ready access to, and full support from, executive management
b. familiarity with information security and/or ICT security
c. a general knowledge of, and experience in, or necessary resources in systems used by the
Agency, especially operating systems, access & authorisation control systems/facilities and
auditing facilities.
d. a reasonable capacity and competence to support the Security Manager role.
IG 8.
Include the following responsibilities within the Security Manager’s role:
a. identifying and recommending ICT security improvements to all business systems and business
processes.
b. ensuring ICT security aspects are considered as part of the change management process.
c. ensuring the coordinating of development, maintenance and implementation of all ICT security
documentation, in conjunction with the business managers.
d. ensuring timely reporting and adequate participation in investigation for ICT security incidents,
with Q-CERT.
IG 9.
Ensure the Security Manager is responsible for:
NATIONAL INFORMATION ASSURANCE MANUAL
18