Objective:
Mandatory Control 4:
Recommended Control 1:
System owners obtain and maintain accreditation of their
systems
SecPlans and SOPs for systems under their ownership. Such actions
must be documented. See Section 19.5‐ Event Logging and
Auditing
System Owners involve the ITSM in the redevelopment and
updates of the SRMPs, SecPlans, and SOPs
System owners should be a member of the Senior Executive Team
or an equivalent management position, for large or critical agency
systems
It is the responsibility of the management (or system owner) to prepare and validate assertions4
relating to the governance, assurance and security of information systems, in accordance with
national policy and related standards.
The system owner is responsible for the overall operation of the system and they may delegate the
day‐to‐day management and operation of the system to a system manager or managers. System
owners need to ensure that systems are accredited to meet the agency’s operational requirements.
If modifications are undertaken to a system the system owner will need to ensure that the changes
are undertaken in an appropriate manner, documented adequately and that any necessary
reaccreditation activities are completed.
All systems should have a system owner in order to ensure IT governance processes are followed
and that business requirements are met.
It is strongly recommended that a system owner be a member of the Senior Executive Team or in
an equivalent management position, however, this does not imply that the system manager(s)
should also be at such a level.
6.5.
System Users
Objective:
Mandatory Control 1:
Mandatory Control 2:
System users comply with information security policies and
procedures within their agency
All system users must comply with the relevant security policies
and procedures for the systems they use
All system users must protect account authenticators, must not
share authenticators for accounts without approval and be
4
Assertions are formal statements by management or system owners, which claim the completeness, accuracy and
validity of evenets, presentations, disclosure, transactions and related assurance, risk and governance aspects of
certification and accreditation.
18