UNCLASSIFIED 4.3  Require that all project proposals and plans to demonstrate consistency with the Board articulated information Risk Appetite;  Be read and understood in conjunction with the risk management strategy;  Assign monitoring responsibility usually to the Audit Committee; and  Be reviewed, debated and agreed at least annually. Information Security Organisation Organisations must have an effective organisation to manage its information security activities. The Accounting Officer must establish such an organisation with a view of achieving the mandatory minimum-security outcomes below. GV2 – All organisations with critical infrastructure must establish suitable information security management arrangements with clearly defined accountability at all levels. As a minimum requirement: (a) The Accounting Officer must accept personal accountability for embedding information risk management into the Internal Control system; (b) a senior executive must assume overall responsibility for information risk management at Board level; (c) organisation must establish a senior management committee to coordinate information risk management; (d) heads of business divisions must assume responsibility for named information assets; (e) every system must have a single responsible officer; and, (f) organisations must appoint trained staff to security roles. To achieve the security outcomes mandated above, organisations must:  Set up an Information Security Management System (ISMS) in accordance with US ISO/IEC 27001:2005. The organisation shall also adopt the "PlanDo-Check-Act" (PDCA) model to structure all ISMS processes; and  Create an information security organisation that is fully compliant with the requirements of US ISO/IEC 27001:2005. As a minimum requirement, organisations should distribute roles as follows: 4.3.1 Responsibilities of Boards & Accounting Officers The information security organisation must perform the roles below at Boardlevel:  Treat information risk as a corporate-level risk;  Review the information risk position at least quarterly; and  Explicitly address information risk management in Annual Reports. 14

Select target paragraph3