6. Information Security Governance – Roles and Responsibilities
6.1.
The Agency Head
Objective:
Mandatory Control 1:
Mandatory Control 2:
Recommended Control 1:
Recommended Control 2:
The Agency Head endorses and is accountable for information
security within their agencies
Where the agency head devolves their authority, the delegate must
be at least a member of the Senior Executive Team or an equivalent
management position
The agency head must provide support for the development,
implementation and ongoing maintenance of information security
processes within their agency
When the agency head devolves their authority the delegate should
be the CISO
Where the head of a smaller agencies is not be able to satisfy all
segregation of duty requirements because of scalability and small
personnel numbers, all potential conflicts of interest should be
clearly identified, declared and actively managed.
The Agency Head is an Accreditation Authority for that agency – see also 7.4Accreditation
Framework.
When an agency head chooses to delegate their authority as the Agency’s Accreditation Authority
they should do so with careful consideration of all the associate risks, as they remain responsible
for the decisions made by their delegate.
The CISO is the most appropriate choice for delegated authority as they should be a senior
executive and hold specialized knowledge in information security and security risk management.
Without the full support of the agency head, IT and security personnel are less likely to have access
to sufficient resources and authority to successfully implement information security within their
agency. If an incident, breach or disclosure of information occurs in preventable circumstances, the
relevant agency head will ultimately be held accountable.
6.2.
Objective:
The Chief Information Security Officer
The Chief Information Security Officer (CISO) sets the strategic
direction for information security within their agency
12