6. Information Security Governance – Roles and Responsibilities 6.1. The Agency Head Objective: Mandatory Control 1: Mandatory Control 2: Recommended Control 1: Recommended Control 2: The Agency Head endorses and is accountable for information security within their agencies Where the agency head devolves their authority, the delegate must be at least a member of the Senior Executive Team or an equivalent management position The agency head must provide support for the development, implementation and ongoing maintenance of information security processes within their agency When the agency head devolves their authority the delegate should be the CISO Where the head of a smaller agencies is not be able to satisfy all segregation of duty requirements because of scalability and small personnel numbers, all potential conflicts of interest should be clearly identified, declared and actively managed. The Agency Head is an Accreditation Authority for that agency – see also 7.4Accreditation Framework. When an agency head chooses to delegate their authority as the Agency’s Accreditation Authority they should do so with careful consideration of all the associate risks, as they remain responsible for the decisions made by their delegate. The CISO is the most appropriate choice for delegated authority as they should be a senior executive and hold specialized knowledge in information security and security risk management. Without the full support of the agency head, IT and security personnel are less likely to have access to sufficient resources and authority to successfully implement information security within their agency. If an incident, breach or disclosure of information occurs in preventable circumstances, the relevant agency head will ultimately be held accountable. 6.2. Objective: The Chief Information Security Officer The Chief Information Security Officer (CISO) sets the strategic direction for information security within their agency 12

Select target paragraph3