UNCLASSIFIED
4.8
Obtain Board endorsement for incident management processes as part of
the holistic business continuity management strategy approval;
Have in place channels for reporting security events to management;
Require all staff, including contractors, to record and report observed or
suspected security weaknesses in systems or services;
Have in place effective and orderly processes for responding to incidents;
Put in place effective mechanisms for quantifying and monitoring the types,
volumes and costs of information security incidents;
Adopt procedures for reporting security incidents to GoU agencies such as
the national Computer Emergency Response Team (CERT); and
Ensure that the collection, retention and presentation of data about security
incidents comply with relevant rules of evidence to enable follow-up action.
Assurance & Compliance
Assurance and compliance reporting aims to demonstrate that the organisation
is achieving the mandatory minimum-security outcomes outlined below.
GV7 – Organisations must provide reasonable assurance that their security
arrangements mitigate risks to critical infrastructure adequately. Using a
range of compliance mechanisms, organisations must, as a minimum
requirement: (a) provide the Board an assessment of the information risk
position, including that of the supply chain, at least quarterly; (b) undertake an
annual security assessment against the NISF and approved security policies
declaring compliance status; (c) disclose areas of non-compliance with the
NISF to their line Minister, Auditor General’s Office, security organisations
and President in a classified annual report; (d) address information risk within
Statements on Internal Control; and, (e) cover information risk management
issues including risks, actions and incidents in the Annual Report.
To achieve the security outcomes mandated above, organisations must:
Provide evidence as to how their security operations comply with US
ISO/IEC 27001:2005. In particular, organisations must produce a Statement
of Applicability showing the controls implemented;
Make information risk management a regular item on the Board’s agenda;
Disclose to the Board the main security risks affecting vital business assets
in quarterly and annual assessments;
Add the role of ensuring compliance with security policies and standards, in
one’s area of responsibility, to a manager’s performance evaluation criteria;
Establish a programme to check regularly that information systems comply
with technical security implementation standards. In particular, the technical
19