8. Information Security Documentation
8.1.
Documentation Fundamentals
Objective:
Mandatory Control 1:
Mandatory Control 2:
Mandatory Control 3:
Mandatory Control 4:
Mandatory Control 5:
Mandatory Control 6:
Mandatory Control 7:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Recommended Control 4:
Recommended Control 5:
Recommended Control 6:
Information security documentation is produced for systems, to
support and demonstrate good governance
Agencies must have a Security Policy (SecPol) for their agency. The
SecPol is usually sponsored by the Chief Executive and managed by
the CISO or Chief Information Officer (CIO). The ITSM should be the
custodian of the SecPol
Agencies must ensure that every system is covered by a Security
Risk Management Plan (SRMP)
Agencies mustensure that every system is covered by a Security
Plan (SecPlan)
Agencies mustensure that Standard Operating Procedures (SOPs)
are developed for systems
Agencies mustdevelop an Incident Response Plan and supporting
procedures
Agency personnel must be trained in, and exercise the Incident
Response Plan
Agencies must ensure that their SecPol, SRMP, SecPlan, SOPs and
IRP are appropriately classified
Agencies shouldcreate and maintain an overarching document
describing the agency’s documentation framework, including a
complete listing of all information security documentation that
shows a document hierarchy and defines how each document is
related to the other
Agencies should ensure that their SRMP, SecPlan, SOPs and IRP are
logically connected and consistent for each system, other agency
systems and with the agency’s SecPol
The SecPol should include an acceptable use policy for any agency
technology equipment, systems, resources and data
All information security documentation should be formally
approved and signed off by a person with an appropriate level of
seniority and authority
Agencies should ensure that all high‐level information security
documentation is approved by the CISO and the agency head or
their delegate
Agencies should ensure that all system‐specific documents are
reviewed by the ITSM and approved by the system owner
28