8. Information Security Documentation 8.1. Documentation Fundamentals Objective: Mandatory Control 1: Mandatory Control 2: Mandatory Control 3: Mandatory Control 4: Mandatory Control 5: Mandatory Control 6: Mandatory Control 7: Recommended Control 1: Recommended Control 2: Recommended Control 3: Recommended Control 4: Recommended Control 5: Recommended Control 6: Information security documentation is produced for systems, to support and demonstrate good governance Agencies must have a Security Policy (SecPol) for their agency. The SecPol is usually sponsored by the Chief Executive and managed by the CISO or Chief Information Officer (CIO). The ITSM should be the custodian of the SecPol Agencies must ensure that every system is covered by a Security Risk Management Plan (SRMP) Agencies mustensure that every system is covered by a Security Plan (SecPlan) Agencies mustensure that Standard Operating Procedures (SOPs) are developed for systems Agencies mustdevelop an Incident Response Plan and supporting procedures Agency personnel must be trained in, and exercise the Incident Response Plan Agencies must ensure that their SecPol, SRMP, SecPlan, SOPs and IRP are appropriately classified Agencies shouldcreate and maintain an overarching document describing the agency’s documentation framework, including a complete listing of all information security documentation that shows a document hierarchy and defines how each document is related to the other Agencies should ensure that their SRMP, SecPlan, SOPs and IRP are logically connected and consistent for each system, other agency systems and with the agency’s SecPol The SecPol should include an acceptable use policy for any agency technology equipment, systems, resources and data All information security documentation should be formally approved and signed off by a person with an appropriate level of seniority and authority Agencies should ensure that all high‐level information security documentation is approved by the CISO and the agency head or their delegate Agencies should ensure that all system‐specific documents are reviewed by the ITSM and approved by the system owner 28

Select target paragraph3