UNCLASSIFIED
4.2
Policy Statement on Information Security
Boards are supreme governing bodies that provide GoU and private sector
organisations guidance on overall policy direction and strategies. Boards also
facilitate, supervise and support management in the implementation of their
mandate and strategies. Given that Boards must consider all the major risks
affecting their organisations, it is crucial that they issue a policy statement on
information security. The purpose of the Board statement is to underline the
importance of information risk management to effective and secure operations.
GV1 – All Boards of organisations with critical infrastructure must issue a
Policy Statement on Information Security. As a minimum requirement, the
Statement must: (a) recognise information as a vital business asset; (b)
acknowledge information risk management as a business enabler and an
integral part of good corporate governance; (c) contain the Board’s
acceptance of ultimate accountability for information risk management; (d) set
clear direction on information risk management by determining Risk Appetite;
and, (e) assign management and employees security responsibilities..
To achieve the security outcomes mandated above, organisations must:
4.2.1
Issue Policy Statement on Information Security
The policy statement on information security:
4.2.2
Recognises information – in all its forms – as a crucial business asset;
Explains why information security matters and outline policy objectives;
Is a Board commitment to protect organisational information from all threats
– internal or external, deliberate or accidental;
Assigns Accounting Officer accountability for information security; and
Requires all employees (including contractors) to comply with the Statement.
Articulate Information Risk Appetite
Boards must articulate organisational information Risk Appetite. A statement of
information Risk Appetite states the level and type of information risks that a
given organisation is willing to accept, tolerate or survive in the pursuit of its
strategic goals. The statement must:
Explicitly note the Board’s Risk Appetite in relation to information risk;
Map the Risk Appetite on a spectrum e.g. low to very high; averse to hungry;
Address information risk’s relationship with corporate goals in the same way
as other risks e.g. legal, financial, operational, compliance and reputational;
13