Policy |
February 2025–current
CurrentMandated
Identifying and managing risks to information, applications and technologies, through their lifecycle, using Information Security Management Systems.
Requirements
- Agencies must implement an ISMS based on ISO 27001.
- Agencies must apply a systematic and repeatable approach to security risk management.
- Agencies must meet minimum information security requirements .
- Accountable officers must obtain security assurance for systems.
- Accountable officers must attest to the appropriateness of agency information security.