Policy |
June 2019–current
CurrentMandated
Identifying and managing risks to information, applications and technologies, through their lifecycle, using Information Security Management Systems.
Requirements
- Departments must implement an ISMS based on ISO 27001.
- Departments must apply a systematic and repeatable approach to risk management.
- Departments must meet minimum security requirements.
- Departments accountable officers must obtain security assurance for systems.
- Accountable officers must attest to the appropriateness of departmental information security.