UNCLASSIFIED 5.3  Specify penalties for breaching the policy and related security measures;  Be publicised and made readily available to all staff; and  Specify a review cycle in order to ensure its continued applicability. Asset Management Organisations must achieve and maintain appropriate protection for information assets in compliance with US ISO/IEC 27001:2005. Effective asset management helps achieve the mandated NISF minimum security outcomes outlined below. IS2 – All organisations must ensure that assets associated with critical infrastructure receive the level of protection appropriate to their value, sensitivity and criticality. As a minimum requirement, all organisations must: (a) use approved criteria to create a definitive register of business critical facilities, systems, sites and networks; (b) designate a suitably empowered owner for every asset; (c) use the Government Security Classification Standard to determine the acceptable procedures for labelling, handling, transmitting and decommissioning assets; (d) audit the asset register regularly; and; (e) inform the Board of the main security risks affecting vital business assets. To achieve the security outcomes mandated above, organisations must:  Conduct an inventory of their assets drawing up and maintaining a register of important assets as a prerequisite to risk management;  Ensure that designated divisions own and secure named information assets;  Identify, document and enforce rules of acceptable use of information assets;  Label and handle information assets throughout their lifecycle in accordance with Security Standard No. 3 – Security Classification (SS3); and  Use the Business Impact Tables in SS1 to determine the information asset labelling and handling levels. 24

Select target paragraph3