Objective: Information security policies (SecPol) set the strategic direction for information security emergency procedures and information security incident management, change management, and information security awareness and training The SecPol is an essential part of information security documentation as it outlines the high‐level policy objectives. The SecPol can form part of the overall agency security policy. To provide consistency in approach and documentation, agencies should consider the following when developing their SecPol: policy objectives how the policy objectives will be achieved the guidelines and legal framework under which the policy will operate stakeholders education and training what resourcing will be available to support the implementation of the policy what performance measures will be established to ensure that the policy is being implemented effectively a review cycle Agencies should also avoid outlining controls for systems within their SecPol. The controls for a system will be determined by this manual and based on the scope of the system, along with any additional controls as determined by the SRMP, and documented within the SecPlan. 8.3. Security Risk Management Plans (SRMP) Objective: Recommended Control 1: Recommended Control 2: Recommended Control 3: Recommended Control 4: Security Risk Management Plans (SRMP) identify security risks and appropriate treatment measures for systems Agencies should determine agency and system specific security risks that could warrant additional controls to those specified in this manual The Security Risk Management Plan should contain a security risk assessment and a corresponding treatment strategy Agencies should incorporate their SRMP into their wider agency risk management plan Agencies should develop their SRMP in accordance with international standards for risk management 30

Select target paragraph3