UNCLASSIFIED
However, this is only with respect to the ways in which they connect to or
access information assets and the activities they perform with the assets.
5.1.3
Information Security and Security Governance
The themes contained in “Part 1 – Security Governance” apply to the information
security functional area in the same way as personnel and physical security. For
example, the information security area must have effective leadership; adopt a
credible risk management approach; conduct effective security awareness,
education and training; handle security incidents and institute assurance and
compliance reporting mechanisms. Moreover, the information security functional
area adopts the PDCA continuous improvement model to all processes. The
mandatory minimum information security requirements are as follows:
5.2
Information Security Policy
An information security policy helps improve security if published, enforced,
audited and updated to reflect organisational requirements. A security policy
aims to achieve the following mandated minimum-security requirements:
IS1 – Management must draft, obtain Board-approval and publish an
information security policy that addresses the NISF mandatory minimum
requirements in terms of the organisation’s business requirements, threat
environment and risk appetite. As a minimum requirement, the policy must: (a)
explain how the organisation and supply chain protect information and physical
assets; (b) apply to all the activities linked to protect computers; (c) define
acceptance and compliance arrangements by its staff and the supply chain; (d)
undergo regular review to ensure its continuing relevance.
To achieve the security outcomes mandated above, the policy must:
Define the purpose, scope and approach to managing information security
within the organisation;
Identify and assign suitable security roles and responsibilities depending on
the size, structure, business needs and threats to the organisation;
Require the creation of a manual guiding the implementation of an ISMS in
compliance with US ISO/IEC 27001;
Contain or refer to a manual detailing how to apply information, personnel
and physical security measures consistently across the organisation;
Contain or reference a guide that explains the secure working practices that
all users must adopt to comply with security policies and related documents;
Require the generation of evidence showing that the organisation uses the
security accreditation process to identify and manage risks to ICT systems;
Outline the required business continuity roles, processes and procedures;
23