Objective:
Recommended Control 7:
Recommended Control 8:
Information security documentation is produced for systems, to
support and demonstrate good governance
Agencies should develop a regular schedule for reviewing all
information security documentation
Agencies should ensure that information security documentation is
reviewed at least annually with the date of the most recent review
being recorded on each document
Information Security Documentation requirements are summarized in the table below.
Title
Information Security Policy
Security Risk Management Plan
System Security Plan
Site Security Plan
Standard Operating Procedures
Incident Response Plan
Abbreviation
SecPol
SRMP
SecPlan
SitePlan
SOPs
IRP
Reference
8.2
8.3
8.4
11.2
8.5
8.6
The implementation of an overarching information security document framework ensures that all
documentation is accounted for, complete and maintained appropriately. Furthermore, it can be
used to describe linkages between documents, especially when higher level documents are used to
avoid repetition of information in lower level documents.
Without appropriate sign‐off of information security documentation within an agency, the security
personnel will have a reduced ability to ensure appropriate security procedures are selected and
implemented. Having sign‐off at an appropriate level assists in reducing this security risk as well as
ensuring that senior management is aware of information security issues and security risks to the
agency’s business.
8.2.
Information Security Policies (SecPol)
Objective:
Recommended Control 1:
Recommended Control 2:
Information security policies (SecPol) set the strategic direction
for information security
The Information Security Policy (SecPol) should document the
information security, guidelines, standards and responsibilities of
an agency
The Information Security Policy (SecPol) should include topics such
as
accreditation
processes,
personnel
responsibilities,
configuration control, access control, networking and connections
with other systems, physical security and media control,
29