UNCLASSIFIED 4.8  Obtain Board endorsement for incident management processes as part of the holistic business continuity management strategy approval;  Have in place channels for reporting security events to management;  Require all staff, including contractors, to record and report observed or suspected security weaknesses in systems or services;  Have in place effective and orderly processes for responding to incidents;  Put in place effective mechanisms for quantifying and monitoring the types, volumes and costs of information security incidents;  Adopt procedures for reporting security incidents to GoU agencies such as the national Computer Emergency Response Team (CERT); and  Ensure that the collection, retention and presentation of data about security incidents comply with relevant rules of evidence to enable follow-up action. Assurance & Compliance Assurance and compliance reporting aims to demonstrate that the organisation is achieving the mandatory minimum-security outcomes outlined below. GV7 – Organisations must provide reasonable assurance that their security arrangements mitigate risks to critical infrastructure adequately. Using a range of compliance mechanisms, organisations must, as a minimum requirement: (a) provide the Board an assessment of the information risk position, including that of the supply chain, at least quarterly; (b) undertake an annual security assessment against the NISF and approved security policies declaring compliance status; (c) disclose areas of non-compliance with the NISF to their line Minister, Auditor General’s Office, security organisations and President in a classified annual report; (d) address information risk within Statements on Internal Control; and, (e) cover information risk management issues including risks, actions and incidents in the Annual Report. To achieve the security outcomes mandated above, organisations must:  Provide evidence as to how their security operations comply with US ISO/IEC 27001:2005. In particular, organisations must produce a Statement of Applicability showing the controls implemented;  Make information risk management a regular item on the Board’s agenda;  Disclose to the Board the main security risks affecting vital business assets in quarterly and annual assessments;  Add the role of ensuring compliance with security policies and standards, in one’s area of responsibility, to a manager’s performance evaluation criteria;  Establish a programme to check regularly that information systems comply with technical security implementation standards. In particular, the technical 19

Select target paragraph3