UNCLASSIFIED
5.3
Specify penalties for breaching the policy and related security measures;
Be publicised and made readily available to all staff; and
Specify a review cycle in order to ensure its continued applicability.
Asset Management
Organisations must achieve and maintain appropriate protection for information
assets in compliance with US ISO/IEC 27001:2005. Effective asset management
helps achieve the mandated NISF minimum security outcomes outlined below.
IS2 – All organisations must ensure that assets associated with critical
infrastructure receive the level of protection appropriate to their value,
sensitivity and criticality. As a minimum requirement, all organisations must: (a)
use approved criteria to create a definitive register of business critical facilities,
systems, sites and networks; (b) designate a suitably empowered owner for
every asset; (c) use the Government Security Classification Standard to
determine the acceptable procedures for labelling, handling, transmitting and
decommissioning assets; (d) audit the asset register regularly; and; (e) inform
the Board of the main security risks affecting vital business assets.
To achieve the security outcomes mandated above, organisations must:
Conduct an inventory of their assets drawing up and maintaining a register of
important assets as a prerequisite to risk management;
Ensure that designated divisions own and secure named information assets;
Identify, document and enforce rules of acceptable use of information assets;
Label and handle information assets throughout their lifecycle in accordance
with Security Standard No. 3 – Security Classification (SS3); and
Use the Business Impact Tables in SS1 to determine the information asset
labelling and handling levels.
24