Objective: Recommended Control 7: Recommended Control 8: Information security documentation is produced for systems, to support and demonstrate good governance Agencies should develop a regular schedule for reviewing all information security documentation Agencies should ensure that information security documentation is reviewed at least annually with the date of the most recent review being recorded on each document Information Security Documentation requirements are summarized in the table below. Title Information Security Policy Security Risk Management Plan System Security Plan Site Security Plan Standard Operating Procedures Incident Response Plan Abbreviation SecPol SRMP SecPlan SitePlan SOPs IRP Reference 8.2 8.3 8.4 11.2 8.5 8.6 The implementation of an overarching information security document framework ensures that all documentation is accounted for, complete and maintained appropriately. Furthermore, it can be used to describe linkages between documents, especially when higher level documents are used to avoid repetition of information in lower level documents. Without appropriate sign‐off of information security documentation within an agency, the security personnel will have a reduced ability to ensure appropriate security procedures are selected and implemented. Having sign‐off at an appropriate level assists in reducing this security risk as well as ensuring that senior management is aware of information security issues and security risks to the agency’s business. 8.2. Information Security Policies (SecPol) Objective: Recommended Control 1: Recommended Control 2: Information security policies (SecPol) set the strategic direction for information security The Information Security Policy (SecPol) should document the information security, guidelines, standards and responsibilities of an agency The Information Security Policy (SecPol) should include topics such as accreditation processes, personnel responsibilities, configuration control, access control, networking and connections with other systems, physical security and media control, 29

Select target paragraph3