9. Information Security Monitoring
9.1.
Information Security Reviews
Objective:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Information security reviews maintain the security of systems
and detect gaps and deficiencies
Agencies should undertake and document information security
reviews of their systems at least annually
Agencies should have information security reviews conducted by
personnel independent to the target of the review or by an
independent third party
Agencies should review the components detailed below:
Information security documentation (SecPol. SRMPs,
SecPlans, SitePlan, SOPs and IRP)
Dispensations (prior to the identified expiry date)
Operating environment (when an identified threat emerges
or changes, an agency gains or loses a function or the
operation of functions are moved to a new physical
environment)
Procedures (after an information security incident or test
exercise)
System security (items that could affect security of the
system on a regular basis)
Threats (changes in a risk environment and risk profile)
GOBISM (changes to controls)
Annual reviews of an agency’s information security posture can assist with ensuring that agencies
are responding to the latest threats, environmental changes and that systems are properly
configured in accordance with any changes to information security documentation and guidance.
Incidents, significant changes or an aggregation of minor changes may require a security review to
determine and support any necessary changes and to demonstrate good systems governance. An
agency may choose to undertake an information security review:
as a result of a specific information security incident
because a change to a system or its environment that significantly impacts on the agreed
and implemented system architecture and information security policy
as part of a regular scheduled review
37