UNCLASSIFIED 4.2 Policy Statement on Information Security Boards are supreme governing bodies that provide GoU and private sector organisations guidance on overall policy direction and strategies. Boards also facilitate, supervise and support management in the implementation of their mandate and strategies. Given that Boards must consider all the major risks affecting their organisations, it is crucial that they issue a policy statement on information security. The purpose of the Board statement is to underline the importance of information risk management to effective and secure operations. GV1 – All Boards of organisations with critical infrastructure must issue a Policy Statement on Information Security. As a minimum requirement, the Statement must: (a) recognise information as a vital business asset; (b) acknowledge information risk management as a business enabler and an integral part of good corporate governance; (c) contain the Board’s acceptance of ultimate accountability for information risk management; (d) set clear direction on information risk management by determining Risk Appetite; and, (e) assign management and employees security responsibilities.. To achieve the security outcomes mandated above, organisations must: 4.2.1 Issue Policy Statement on Information Security The policy statement on information security: 4.2.2  Recognises information – in all its forms – as a crucial business asset;  Explains why information security matters and outline policy objectives;  Is a Board commitment to protect organisational information from all threats – internal or external, deliberate or accidental;  Assigns Accounting Officer accountability for information security; and  Requires all employees (including contractors) to comply with the Statement. Articulate Information Risk Appetite Boards must articulate organisational information Risk Appetite. A statement of information Risk Appetite states the level and type of information risks that a given organisation is willing to accept, tolerate or survive in the pursuit of its strategic goals. The statement must:  Explicitly note the Board’s Risk Appetite in relation to information risk;  Map the Risk Appetite on a spectrum e.g. low to very high; averse to hungry;  Address information risk’s relationship with corporate goals in the same way as other risks e.g. legal, financial, operational, compliance and reputational; 13

Select target paragraph3