There can be many stakeholders involved in defining a SecPlan, including representatives from the: project, who must deliver the capability (including contractors) owners of the information to be handled system users for whom the capability is being developed management audit authority CISO, ITSM and system owners system certifiers and accreditors information management planning areas infrastructure management The GOBISM provides a list of controls that are potentially applicable to a system based on its functionality and the technology it is implementing. Agencies will need to determine which controls are in scope of the system and translate those controls to the SecPlan. These controls will then be assessed on their implementation and effectiveness during an information security assessment as part of the accreditation process. 8.5. Standard Operating Procedures (SOP) Objective: Recommended Control 1: Recommended Control 2: Recommended Control 3: Standard Operating Procedures (SOPs) ensure security procedures are followed in an appropriate and repeatable manner Agencies should develop separate SOPs for ITSM, system administrator and system user The procedures that should be documented in the ITSM, system administrator and system user‘s SOP are provided in the table below ITSMs, system administrators and system users should sign a statement that they have read and agree to abide by their respective SOPs SOPs provide step‐by‐step guides to undertaking information security related tasks and processes. They provide assurance that tasks can be undertaken in a secure and repeatable manner, even by system users without strong technical knowledge of the system’s mechanics. In order to ensure that personnel undertake their duties in an appropriate manner, with a minimum of confusion, it is important that the roles of ITSMs, system administrators and system users are covered by SOPs. Furthermore, taking steps to ensure that SOPs are consistent with SecPlans will reduce the potential for confusion resulting from conflicts in policy and procedures. 32

Select target paragraph3