UNCLASSIFIED 4.3.5  Approve organisational security policies and standards;  Monitor compliance with agreed security policies and standards; and  Encourage the professionalisation of all security areas. Responsibilities of Operational Security team Led by chief information security officer or similar role, the operational security team must perform the following functions: 4.4  Implement the organisation’s information risk policy;  Follow approved security policies and standards;  Enforce security requirements on all stakeholders including suppliers; and  Identify and report non-compliance with security policies and rules. Risk Management Risk management activities must show that the Board and Accounting Officer, acting with and through the Board-level Information Risk Owner, are complying with the mandatory minimum-security requirements below on mitigating risks to acceptable levels. GV3 – All organisations with critical infrastructure must adopt a formal, consistent and policy-guided risk management approach to help ensure the security of critical infrastructure. Drawing on the guidance within the NISF, all organisations must: (a) have a suitable information risk policy to address threat sources and actors; (b) prioritise risks; and, (c) manage information risks during the ICT system's development, acceptance, operational and decommissioning and disposal phases. To achieve the security outcomes mandated above, organisations must:  Use the Board-issued information Risk Appetite as a guide for routine risk management decisions to ensure that the organisation avoids taking either too much or too little risk in pursuit of its business goals;  Identify business critical assets and the impact of their compromise or loss;  Have in place a Risk Register to record and audit risk management decisions by identifying risk owners, residual risk and risk treatment actions; and  Comply with NISF guidance contained in the Security Standard No.1 – Technical Risk Assessment (SS1) and Security Standard No.2 – Risk Management and Accreditation (SS2). 16

Select target paragraph3