a. ensuring the development, maintenance, updating and implementation of security risk management plans, system security plans and any security procedures used. b. providing technical security advice involved with system development, acquisition, implementation, modification, operation, support, and architecture c. assisting the system manager to develop system security standards/policies d. the certification of systems, when applicable e. ensuring the agency has an appropriate ICT security awareness and training program. f. the regular review of system security, system audit trails and logs and the integrity of system configurations. IG 10. Ensure the Security Manager is familiar with all security operating procedures relating to systems, including to the roles of system managers, system administrators and system users. 2. Risk Management [RM] 2.1. Policy Objective This policy defines the requirement to conduct risk assessment to devise a suitable risk treatment plan for information assets, which have been classified as having an aggregate security level of Medium or High [IAP-NAT-DCLS] and keep the residual risk to an acceptable level depending on the Agency’s risk appetite. 2.2. Policy & Baseline Controls To meet the requirements of this policy Agencies MUST: RM 1. *Define a risk assessment process to identify threats and vulnerabilities to critical information assets (identified with an aggregate security level of Medium or High). RM 2. *Based on the assessment, define a risk treatment plan to address threats and vulnerabilities. RM 3. Ensure that the risk treatment plan and residual risk selected for information assets, with an aggregate security level of High, are vetted by senior management in the Agency. RM 4. Ensure that the controls chosen in RM2 & RM3 are monitored for effectiveness on a periodic basis. RM 5. Risk assessments should be integrated within the business process and revised whenever there is a change. Changes in the business or legal/regulatory environment may also warrant the need to do risk assessment. 3. Third Party Security Management [TM] 3.1. Policy Objective The purpose of this policy is to ensure that the baseline policy and controls specified in this NIA Manual are maintained in service(s) that have been outsourced to a third party. 3.2. Policy & Baseline Controls To meet the requirements of this policy Agencies MUST ensure: 19 TM1. *The areas or services being outsourced remain the governance, compliance and risk management accountability of the Agency. TM2. *They understand and acknowledge the risks associated with the outsourcing of their services. TM3. That the security controls and baseline policy specified in this NIA Manual are included in the third party service delivery agreement or contract. This SHALL also apply to sub-contractors used by the third party. TM4. The third party SHALL be contractually required to regularly report on the outsourced service’(s) NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3