UNCLASSIFIED 4.3.2 Responsibilities of Information Risk Owner The security organisation shall appoint a Board-level official to the role of Information Risk Owner (IRO) with responsibilities including: 4.3.2.1  Ownership of a plan to foster a culture of information security;  Accountability for the organisational risk management policy;  Alignment of the risk management programme with business processes;  Advising on information risk sections of the Statement on Internal Control;  Ensuring that all assets have skilled and empowered owners; and  The production of quarterly and annual information risk assessments. Choice of Information Risk Owner It is important to stress that the IRO is a role not necessarily a job title. As such, organisations could appoint anyone with adequate standing and expertise to this role. However, guided by the Presidential Directive to create a programme to professionalise information security, the Chief Information Security Officer (CISO) or a similar title must be the first choice for the Board-level IRO role. Choosing a CISO for the IRO role would help ensure that the Board receives timely and effective advice about the impacts of their strategic and operational decisions on information security. Organisations may appoint an interim IRO during the hiring and/or training of a CISO or similar title to take over the role. 4.3.3 Responsibilities of Information Asset Owners Information asset owners must be heads of division or department and perform the following functions: 4.3.4  Understand and support the organisation’s security culture;  Know what information the assets under their responsibility hold;  Know who accesses the assets under their responsibility and why;  Identify and mitigate risks to the assets under their responsibility;  Ensure that assets under their responsibility are available for business use;  Provide the Board-level Information Risk Owner reasonable assurance that the assets under their responsibility are secure at least annually. Responsibilities of Security Coordination Group Led by Board-level Information Risk Owner, the information security coordinators must perform the following functions:  Ensure that effective information risk management processes are in place; 15

Select target paragraph3