Table of Contents
1.
Document information ................................................................................................................... 1
2.
Executive summary......................................................................................................................... 6
3.
What is an information security manual and what does it define? ............................................... 7
4.
Applicability, Authority and Compliance ........................................................................................ 9
5.
Information Security within Government .................................................................................... 10
6.
7.
8.
9.
5.1.
Government Engagement ..................................................................................................... 10
5.2.
Industry Engagement and Outsourcing ................................................................................ 10
Information Security Governance – Roles and Responsibilities................................................... 12
6.1.
The Agency Head ................................................................................................................... 12
6.2.
The Chief Information Security Officer ................................................................................. 12
6.3.
Information Technology Security Managers ......................................................................... 15
6.4.
System Owners ...................................................................................................................... 17
6.5.
System Users ......................................................................................................................... 18
System Certification and Accreditation ........................................................................................ 20
7.1.
The Certification and Accreditation Process ......................................................................... 20
7.2.
Conducting Certifications ...................................................................................................... 23
7.3.
Conducting Audits ................................................................................................................. 23
7.4.
Accreditation Framework...................................................................................................... 25
7.5.
Conducting Accreditations .................................................................................................... 26
Information Security Documentation .......................................................................................... 28
8.1.
Documentation Fundamentals.............................................................................................. 28
8.2.
Information Security Policies (SecPol) .................................................................................. 29
8.3.
Security Risk Management Plans (SRMP) ............................................................................. 30
8.4.
System Security Plans (SecPlan) ............................................................................................ 31
8.5.
Standard Operating Procedures (SOP) .................................................................................. 32
8.6.
Incident Response Plans (IRP) ............................................................................................... 35
Information Security Monitoring.................................................................................................. 37
9.1.
Information Security Reviews ............................................................................................... 37
2