As ITSMs have knowledge of all aspects of information security they are best placed to work with ICT projects within the agency to identify and incorporate appropriate information security measures. As ITSMs are responsible for the operational management of information security projects and functions within their agency, they will be aware of their funding requirements and can assist the CISO to develop information security budget projections and resource allocations. The CISO will coordinate the use of external information security resources to the agency, whilst ITSMs will be responsible for establishing contracts and service‐level agreements on behalf of the CISO. The CISO will set the strategic direction for information security within the agency, whereas ITSMs are responsible for managing the implementation of information security measures within the agency. The CISO will oversee the development and operation of information security awareness and training programs within the agency. ITSMs will arrange delivery of that training to personnel within the agency. To ensure the CISO remains aware of all information security issues within their agency and can brief their agency head when necessary, ITSMs will need to provide regular reports on policy developments, proposed system changes and enhancements, information security incidents and other areas of particular concern to the CISO. Whilst the CISO will coordinate the development of disaster recovery policies and standards within the agency, ITSMs will need to guide the selection of appropriate strategies to achieve the direction set by the CISO. 6.4. System Owners Objective: Mandatory Control 1: Mandatory Control 2: Mandatory Control 3: System owners obtain and maintain accreditation of their systems Each system must have a system owner who is responsible for the operation and maintenance of the system System owners must obtain and maintain accreditation of their system(s) System owners must ensure the development, maintenance and implementation of complete, accurate and up to date SRMPs, 17

Select target paragraph3