UNCLASSIFIED
4.3
Require that all project proposals and plans to demonstrate consistency with
the Board articulated information Risk Appetite;
Be read and understood in conjunction with the risk management strategy;
Assign monitoring responsibility usually to the Audit Committee; and
Be reviewed, debated and agreed at least annually.
Information Security Organisation
Organisations must have an effective organisation to manage its information
security activities. The Accounting Officer must establish such an organisation
with a view of achieving the mandatory minimum-security outcomes below.
GV2 – All organisations with critical infrastructure must establish suitable
information security management arrangements with clearly defined
accountability at all levels. As a minimum requirement: (a) The Accounting
Officer must accept personal accountability for embedding information risk
management into the Internal Control system; (b) a senior executive must
assume overall responsibility for information risk management at Board level;
(c) organisation must establish a senior management committee to
coordinate information risk management; (d) heads of business divisions
must assume responsibility for named information assets; (e) every system
must have a single responsible officer; and, (f) organisations must appoint
trained staff to security roles.
To achieve the security outcomes mandated above, organisations must:
Set up an Information Security Management System (ISMS) in accordance
with US ISO/IEC 27001:2005. The organisation shall also adopt the "PlanDo-Check-Act" (PDCA) model to structure all ISMS processes; and
Create an information security organisation that is fully compliant with the
requirements of US ISO/IEC 27001:2005.
As a minimum requirement, organisations should distribute roles as follows:
4.3.1
Responsibilities of Boards & Accounting Officers
The information security organisation must perform the roles below at Boardlevel:
Treat information risk as a corporate-level risk;
Review the information risk position at least quarterly; and
Explicitly address information risk management in Annual Reports.
14