3. What is an information security manual and what does it define?
The Government of Bangladesh Information Security Manual (GOBISM) details processes and
controls that are important for the protection of Bangladesh Government unclassified information
and systems.
This manual is intended for use by Bangladesh Government departments, agencies and
organizations. Private sector organizations are also encouraged to use this manual.
This GOBISM governs information security principles and controls applicable to unclassified
information. Classified government information shall have an additional set of principles and
controls developed and approved at appropriate level.
The controls presented in GOBISM shall be applicable to all government unclassified systems and
information.
The controls presented in GOBISM are divided into two categories:
Mandatory controls: the use, or‐non‐use thereof is essential in order to effectively manage
identified risk, unless the control is demonstrably not relevant to the respective system. The
rational for non‐use of mandatory controls must be clearly demonstrated to the
Accreditation Authority as part of the certification process, before approval for exception is
granted.
Recommended controls: the use, or non‐use thereof is considered good and recommended
practice, but valid reasons for not implementing a control could exist. The residual risk of
non‐using recommended controls needs to be agreed and acknowledged by the
Accreditation authority with formal auditable record of this consideration and decision.
System owners seeking a dispensation for non‐compliance with any mandatory controls in this
manual must be granted a dispensation by their Accreditation Authority.
System owners seeking a dispensation for non‐compliance with mandatory controls must complete
an agency risk assessment which documents:
the reason(s) for not being able to comply with this manual
the alternative mitigation measure(s) to be implemented
the strength and applicability of the alternative mitigations
an assessment of the residual security risk(s)
a date by which to review the decision.
Agencies should review decisions to be non‐compliant with any controls at least annually.
Agencies must retain a copy and maintain a record of the supporting risk assessment and decisions
to be non‐compliant with any mandatory controls from this manual. Where recommended controls
7