Objective: Recommended Control 11: Recommended Control 12: Recommended Control 13: Recommended Control 14: Recommended Control 15: Recommended Control 16: Recommended Control 17: Recommended Control 18: Recommended Control 19: Recommended Control 20: Recommended Control 21: Recommended Control 22: Information Technology Security Managers (ITSM) provide information security leadership and management within their agency to support and enforce information security policies ITSMs should provide leadership and direction for the integration of information security strategies and architecture with agency business and ICT strategies and architecture ITSMs should provide technical and managerial expertise for the administration of information security management tools ITSMs should work with the CISO to develop information security budget projections and resource allocations based on short‐term and long‐term goals and objectives ITSMs should coordinate, measure and report on technical aspects of information security management to CISO ITSMs should monitor and report to CISO on compliance with information security policies, as well as the enforcement of information security policies within the agency ITSMs should provide regular reports on information security incidents and other areas of particular concern to the CISO ITSMs should assess and report to CISO on threats, vulnerabilities, and residual security risks and recommend remedial actions ITSMs should assist system owners and security personnel in understanding and responding to audit failures reported by auditors ITSMs should assist and guide the disaster recovery planning team in the selection of recovery strategies and the development, testing and maintenance of disaster recovery plans ITSMs should provide or arrange for the provision of information security awareness and training for all agency personnel ITSMs should provide expert guidance on security matters for ICT projects ITSM should keep the CISO and system owners informed with up‐ to‐date information on current threats ITSMs are executives within an agency that act as a conduit between the strategic directions provided by the CISO and the technical efforts of systems administrators. The main area of responsibility of an ITSM is that of the administrative and process controls relating to information security within the agency. When agencies outsource their ICT services, ITSMs should be independent of any company providing ICT services. This will prevent any conflict of interest for an ITSM in conducting their duties. 16

Select target paragraph3