11.07.2015 Views

Information Management Strategy.pdf - Lincolnshire Police

Information Management Strategy.pdf - Lincolnshire Police

Information Management Strategy.pdf - Lincolnshire Police

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NOT PROTECTIVELY MARKEDi) Developing, implementing and maintaining IT security policy and procedures inaccordance with HMG policy and standard;ii) Developing and promulgating IT security awareness within the organisation;iii) Representing IT security on internal and interdepartmental security committees;iv) Providing advice and information on IT security matters to the ISO and SIRO and otherstakeholders;v)Supporting and advising on the accreditation process;vi) In conjunction with our strategic partner (G4S) ensure that suitable IT securityobligations and onward management is reflected in IT service contracts;vii) Providing a central point of contact on all IT security related issues, both internally andintra-departmentally;viii) Managing IT security investigations and reporting of IT security incidents toGovCERTUK, Cabinet Office and/or <strong>Information</strong> Commissioner;ix)Advising Accreditors, our strategic partner (G4S) and other appropriate stakeholders onany perceived changes in threat, security loopholes, infringements and vulnerabilities thatmay come to light;x) Preparing security reports and conducting security surveys required by the Accreditor orSIRO;xi) Approving any third party connections.6.9 Communications Security Officer (ComSO)a) If a Department handles cryptographic material, it must have a designatedCommunications Security Officer (ComSO). The ComSO is responsible for:i)Ensuring the Department‟s compliance with HMG minimum Comsec and Cryptographyrequirements (including this Standard), including ensuring the Department‟s compliance isaudited annually to support the production of the annual report to the Head ofDepartment/<strong>Management</strong> board on compliance with security policy;ii)Developing, implementing and maintaining organisational communications andcryptographic security policy and procedures in accordance with HMG policy andstandards;NOT PROTECTIVELY MARKED 41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!