6.3.
Information Technology Security Managers
Objective:
Mandatory Control 1:
Mandatory Control 2:
Mandatory Control 3:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Recommended Control 4:
Recommended Control 5:
Recommended Control 6:
Recommended Control 6:
Recommended Control 7:
Recommended Control 8:
Recommended Control 9:
Recommended Control 10:
Information Technology Security Managers (ITSM) provide
information security leadership and management within their
agency
Agencies must appoint at least one ITSM within their agency
ITSMs must be responsible for assisting system owners to obtain
and maintain the accreditation of their systems
ITSMs must be responsible for ensuring the development,
maintenance, updating and implementation of Security Risk
Management Plans (SRMPs), Systems Security Plans (SecPlan) and
any Standard Operating Procedures (SOPs) for all agency systems
Where an agency is spread across a number of geographical sites,
it is recommended that the agency should appoint a local ITSM at
each major site
ITSMs should not have additional responsibilities beyond those
needed to fulfill the role as outlined within this manual
ITSMs should work with the CISO to develop an information
security program within the agency
ITSMs should undertake and manage projects to address identified
security risks
ITSMs should identify systems that require security measures and
assist in the selection of appropriate information security
measures for such systems
ITSMs should consult with ICT project personnel to ensure that
information security is included in the evaluation, selection,
installation, configuration and operation of IT equipment and
software
ITSMs should work with system owners, systems certifiers and
systems accrediators to determine appropriate information
security policies for their systems and ensure consistency with
relevant GOBISM components
ITSMs should notify the Accreditation Authority of any significant
change that may affect the accreditation of that system
ITSMs should liaise with vendors and agency purchasing and legal
areas to establish mutually acceptable information security
contracts and service‐level agreements
ITSMs should conduct security risk assessments on the
implementation of new or updated IT equipment or software in
the existing environment and develop treatment strategies, if
necessary
ITSMs should select and coordinate the implementation of controls
15