Table of Contents 1. Document information ................................................................................................................... 1 2. Executive summary......................................................................................................................... 6 3. What is an information security manual and what does it define? ............................................... 7 4. Applicability, Authority and Compliance ........................................................................................ 9 5. Information Security within Government .................................................................................... 10 6. 7. 8. 9. 5.1. Government Engagement ..................................................................................................... 10 5.2. Industry Engagement and Outsourcing ................................................................................ 10 Information Security Governance – Roles and Responsibilities................................................... 12 6.1. The Agency Head ................................................................................................................... 12 6.2. The Chief Information Security Officer ................................................................................. 12 6.3. Information Technology Security Managers ......................................................................... 15 6.4. System Owners ...................................................................................................................... 17 6.5. System Users ......................................................................................................................... 18 System Certification and Accreditation ........................................................................................ 20 7.1. The Certification and Accreditation Process ......................................................................... 20 7.2. Conducting Certifications ...................................................................................................... 23 7.3. Conducting Audits ................................................................................................................. 23 7.4. Accreditation Framework...................................................................................................... 25 7.5. Conducting Accreditations .................................................................................................... 26 Information Security Documentation .......................................................................................... 28 8.1. Documentation Fundamentals.............................................................................................. 28 8.2. Information Security Policies (SecPol) .................................................................................. 29 8.3. Security Risk Management Plans (SRMP) ............................................................................. 30 8.4. System Security Plans (SecPlan) ............................................................................................ 31 8.5. Standard Operating Procedures (SOP) .................................................................................. 32 8.6. Incident Response Plans (IRP) ............................................................................................... 35 Information Security Monitoring.................................................................................................. 37 9.1. Information Security Reviews ............................................................................................... 37 2

Select target paragraph3