Objective:
Information security policies (SecPol) set the strategic direction
for information security
emergency procedures and information security incident
management, change management, and information security
awareness and training
The SecPol is an essential part of information security documentation as it outlines the high‐level
policy objectives. The SecPol can form part of the overall agency security policy.
To provide consistency in approach and documentation, agencies should consider the following
when developing their SecPol:
policy objectives
how the policy objectives will be achieved
the guidelines and legal framework under which the policy will operate
stakeholders
education and training
what resourcing will be available to support the implementation of the policy
what performance measures will be established to ensure that the policy is being
implemented effectively
a review cycle
Agencies should also avoid outlining controls for systems within their SecPol. The controls for a
system will be determined by this manual and based on the scope of the system, along with any
additional controls as determined by the SRMP, and documented within the SecPlan.
8.3.
Security Risk Management Plans (SRMP)
Objective:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Recommended Control 4:
Security Risk Management Plans (SRMP) identify security risks
and appropriate treatment measures for systems
Agencies should determine agency and system specific security
risks that could warrant additional controls to those specified in
this manual
The Security Risk Management Plan should contain a security risk
assessment and a corresponding treatment strategy
Agencies should incorporate their SRMP into their wider agency
risk management plan
Agencies should develop their SRMP in accordance with
international standards for risk management
30