UNCLASSIFIED However, this is only with respect to the ways in which they connect to or access information assets and the activities they perform with the assets. 5.1.3 Information Security and Security Governance The themes contained in “Part 1 – Security Governance” apply to the information security functional area in the same way as personnel and physical security. For example, the information security area must have effective leadership; adopt a credible risk management approach; conduct effective security awareness, education and training; handle security incidents and institute assurance and compliance reporting mechanisms. Moreover, the information security functional area adopts the PDCA continuous improvement model to all processes. The mandatory minimum information security requirements are as follows: 5.2 Information Security Policy An information security policy helps improve security if published, enforced, audited and updated to reflect organisational requirements. A security policy aims to achieve the following mandated minimum-security requirements: IS1 – Management must draft, obtain Board-approval and publish an information security policy that addresses the NISF mandatory minimum requirements in terms of the organisation’s business requirements, threat environment and risk appetite. As a minimum requirement, the policy must: (a) explain how the organisation and supply chain protect information and physical assets; (b) apply to all the activities linked to protect computers; (c) define acceptance and compliance arrangements by its staff and the supply chain; (d) undergo regular review to ensure its continuing relevance. To achieve the security outcomes mandated above, the policy must:  Define the purpose, scope and approach to managing information security within the organisation;  Identify and assign suitable security roles and responsibilities depending on the size, structure, business needs and threats to the organisation;  Require the creation of a manual guiding the implementation of an ISMS in compliance with US ISO/IEC 27001;  Contain or refer to a manual detailing how to apply information, personnel and physical security measures consistently across the organisation;  Contain or reference a guide that explains the secure working practices that all users must adopt to comply with security policies and related documents;  Require the generation of evidence showing that the organisation uses the security accreditation process to identify and manage risks to ICT systems;  Outline the required business continuity roles, processes and procedures; 23

Select target paragraph3