The SRMP is considered to be a best practice approach to identifying and reducing potential
security risks. Depending on the documentation framework chosen, multiple systems can refer to,
or build upon, a single SRMP.
SRMPs may be developed on a functional basis, systems basis or project basis. For example, where
physical elements will apply to all systems in use within that agency, a single SRMP covering all
physical elements is acceptable. Generally each system will require a separate SRMP.
Information on the development of SRMP can be found:
ISO 27005:2011, Information Security Risk Management
ISO 22301:2012, Business Continuity
Risks within an agency can be managed if they are not known, and if they are known, failing to treat
or accept them is also a failure of risk management. For this reason SRMPs consist of two
components, a security risk assessment and a corresponding treatment strategy. If an agency fails
to incorporate SRMPs for systems into their wider agency risk management plan, then the agency
will be unable to manage risks in a coordinated and consistent manner across the agency.
The International Organization for Standardization has developed an international risk management
standard, including principles and guidelines on implementation, outlined in ISO 31000:2009, Risk
Management – Principles and Guidance. The terms and definitions for this standard can be found in
ISO/IEC Guide 73, Risk Management – Vocabulary – Guidelines. The ISO/IEC 270xx series of
standards also provides guidance.
8.4.
System Security Plans (SecPlan)
Objective:
Mandatory Control 1:
Recommended Control 1:
System Security Plans (SecPlan) specify the information security
measures for systems
Agencies mustTselect controls from this manual to be included in
the SecPlan based on the scope of the system with additional
system specific controls being included as a result of the associated
SRMP
Agencies should include a Key Management Plan in the SecPlan
The SecPlan describes the implementation and operation of controls within the system derived
from the GOBISM and the SRMP. Depending on the documentation framework chosen, some
details common to multiple systems can be consolidated in a higher level SecPlan.
31