The SRMP is considered to be a best practice approach to identifying and reducing potential security risks. Depending on the documentation framework chosen, multiple systems can refer to, or build upon, a single SRMP. SRMPs may be developed on a functional basis, systems basis or project basis. For example, where physical elements will apply to all systems in use within that agency, a single SRMP covering all physical elements is acceptable. Generally each system will require a separate SRMP. Information on the development of SRMP can be found: ISO 27005:2011, Information Security Risk Management ISO 22301:2012, Business Continuity Risks within an agency can be managed if they are not known, and if they are known, failing to treat or accept them is also a failure of risk management. For this reason SRMPs consist of two components, a security risk assessment and a corresponding treatment strategy. If an agency fails to incorporate SRMPs for systems into their wider agency risk management plan, then the agency will be unable to manage risks in a coordinated and consistent manner across the agency. The International Organization for Standardization has developed an international risk management standard, including principles and guidelines on implementation, outlined in ISO 31000:2009, Risk Management – Principles and Guidance. The terms and definitions for this standard can be found in ISO/IEC Guide 73, Risk Management – Vocabulary – Guidelines. The ISO/IEC 270xx series of standards also provides guidance. 8.4. System Security Plans (SecPlan) Objective: Mandatory Control 1: Recommended Control 1: System Security Plans (SecPlan) specify the information security measures for systems Agencies mustTselect controls from this manual to be included in the SecPlan based on the scope of the system with additional system specific controls being included as a result of the associated SRMP Agencies should include a Key Management Plan in the SecPlan The SecPlan describes the implementation and operation of controls within the system derived from the GOBISM and the SRMP. Depending on the documentation framework chosen, some details common to multiple systems can be consolidated in a higher level SecPlan. 31

Select target paragraph3