6.3. Information Technology Security Managers Objective: Mandatory Control 1: Mandatory Control 2: Mandatory Control 3: Recommended Control 1: Recommended Control 2: Recommended Control 3: Recommended Control 4: Recommended Control 5: Recommended Control 6: Recommended Control 6: Recommended Control 7: Recommended Control 8: Recommended Control 9: Recommended Control 10: Information Technology Security Managers (ITSM) provide information security leadership and management within their agency Agencies must appoint at least one ITSM within their agency ITSMs must be responsible for assisting system owners to obtain and maintain the accreditation of their systems ITSMs must be responsible for ensuring the development, maintenance, updating and implementation of Security Risk Management Plans (SRMPs), Systems Security Plans (SecPlan) and any Standard Operating Procedures (SOPs) for all agency systems Where an agency is spread across a number of geographical sites, it is recommended that the agency should appoint a local ITSM at each major site ITSMs should not have additional responsibilities beyond those needed to fulfill the role as outlined within this manual ITSMs should work with the CISO to develop an information security program within the agency ITSMs should undertake and manage projects to address identified security risks ITSMs should identify systems that require security measures and assist in the selection of appropriate information security measures for such systems ITSMs should consult with ICT project personnel to ensure that information security is included in the evaluation, selection, installation, configuration and operation of IT equipment and software ITSMs should work with system owners, systems certifiers and systems accrediators to determine appropriate information security policies for their systems and ensure consistency with relevant GOBISM components ITSMs should notify the Accreditation Authority of any significant change that may affect the accreditation of that system ITSMs should liaise with vendors and agency purchasing and legal areas to establish mutually acceptable information security contracts and service‐level agreements ITSMs should conduct security risk assessments on the implementation of new or updated IT equipment or software in the existing environment and develop treatment strategies, if necessary ITSMs should select and coordinate the implementation of controls 15

Select target paragraph3