UNCLASSIFIED 5.13 Security Accreditation There must be a clear plan to provide stakeholders relevant information about how an organisation complies with the mandated NISF minimum security requirements. Organisations demonstrate compliance with security requirements by creating a body of evidence containing procedures, processes, instructions and plans for maintaining the security of an information system throughout its life. The mandated minimum information security outcomes below would show that the organisation has identified and addressed major risks to vital systems. IS12 – All protected Government computers must be accredited to the NISF Risk Management and Accreditation Standard. As a minimum requirement, organisations must: (a) accept and retain accountability for accreditation; (b) ensure that every IT project has a senior responsible owner; (c) define an accreditation boundary; (d) develop an accreditation roadmap; (e) create accreditation plans; (f) record all procedures, processes, instructions and plans for securing the system; (g) conduct suitable system acceptance testing notably penetration testing; and, (h) identify through-life accreditation costs. To achieve the security outcomes mandated above, organisations must:  Adopt the US ISO/IEC 27001:2005 controls set, select appropriate and applicable countermeasures to reduce risks;  Agree with the Accreditor, the approach for measuring compliance with the NISF;  Show compliance with the corporate policies and legislation applicable to the system’s security accreditation scope;  Describe how the security accreditation process met applicable business and security requirements;  Demonstrate how the risk management strategy for the system helped establish the business impact of compromising the security of key assets;  Assess threats and risks to the information system, develop a risk treatment plan and countermeasures against identified risks; and  Present a detailed plan for managing security risks to the system throughout its lifecycle until decommissioning. 36

Select target paragraph3