Objective: Mandatory Control 4: Recommended Control 1: System owners obtain and maintain accreditation of their systems SecPlans and SOPs for systems under their ownership. Such actions must be documented. See Section 19.5‐ Event Logging and Auditing System Owners involve the ITSM in the redevelopment and updates of the SRMPs, SecPlans, and SOPs System owners should be a member of the Senior Executive Team or an equivalent management position, for large or critical agency systems It is the responsibility of the management (or system owner) to prepare and validate assertions4 relating to the governance, assurance and security of information systems, in accordance with national policy and related standards. The system owner is responsible for the overall operation of the system and they may delegate the day‐to‐day management and operation of the system to a system manager or managers. System owners need to ensure that systems are accredited to meet the agency’s operational requirements. If modifications are undertaken to a system the system owner will need to ensure that the changes are undertaken in an appropriate manner, documented adequately and that any necessary reaccreditation activities are completed. All systems should have a system owner in order to ensure IT governance processes are followed and that business requirements are met. It is strongly recommended that a system owner be a member of the Senior Executive Team or in an equivalent management position, however, this does not imply that the system manager(s) should also be at such a level. 6.5. System Users Objective: Mandatory Control 1: Mandatory Control 2: System users comply with information security policies and procedures within their agency All system users must comply with the relevant security policies and procedures for the systems they use All system users must protect account authenticators, must not share authenticators for accounts without approval and be 4 Assertions are formal statements by management or system owners, which claim the completeness, accuracy and validity of evenets, presentations, disclosure, transactions and related assurance, risk and governance aspects of certification and accreditation. 18

Select target paragraph3