Objective: System users comply with information security policies and procedures within their agency responsible for all actions under their accounts Mandatory Control 3: All system users mustuse their access to only perform authorised tasks and functions Mandatory Control 4: System users that need to bypass security policies, procedures or mechanisms for any reason must seek formal authorisation from the CISO or the ITSM, if this authority has been specifically delegated to the ITSM If agencies fail to develop and maintain a security culture where system users are complying with relevant security policies and procedures for the systems they are using, there is an increased security risk of a system user unwittingly assisting with an attack against a system. 19

Select target paragraph3