The ITSM SOPs are intended to cover the management and leadership of information security
functions within the agency.
The system administrator SOPs focus on the administrative activities related to system operations.
The system user SOPs focus on day to day activities that system users need to be made aware of,
and comply with, when using systems.
When SOPs are produced the intended audience should be made aware of their existence and
acknowledge that they have read, understood and agree to abide by their contents.
Topic
Access Control
Procedures to be included in the SOPs
ITSM
System administrators
System users
Authorizing access rights to
Implementing access N/A
applications and data
rights to applications
and data
Asset Musters
Audit Logs
Configuration Control
Information Security
Incidents
Data transfers
N/A
N/A
N/A
N/A
Implementing
changes to the
system software or
configurations
N/A
Detecting, reporting and
managing potential
information security incidents
Detecting, reporting
and managing
potential information
security incidents
Establishing the cause of any
information security incident,
whether accidental or
deliberate
Establishing the
cause of any
information security
incident, whether
accidental or
deliberate
What to do in the
case of a suspected
or actual
information
security incident
Actions to be taken to recover
and minimize the exposure
from an information security
incident
Actions to be taken to
recover and minimize
the exposure from an
information security
incident
Additional actions to
prevent reoccurrence
N/A
Labelling, registering and
mustering assets, including
media
Reviewing system audit trails
and manual logs, particularly
for privileged users
Approving an releasing
changes to the system
software and configurations
Additional actions to prevent
reoccurrence
Managing the review of media
N/A
33