GOV-004 Information Security Programme
Description
A formal information security programme exists with documented scope, objectives, and resource allocation. The programme covers all relevant security domains, is aligned with business risk, and is reviewed at planned intervals by management.
Rationale
An undocumented or resource-starved security programme cannot systematically implement or maintain controls across the organisation. The programme plan is the master reference for scope and coverage.
Applicability (9 profiles)
Art. 28(5) lets a financial entity contract only with providers that comply with appropriate information security standards. For services supporting a critical or important function it weighs the use of the most up-to-date and highest quality ones. The programme has to be measurable against a named external standard, not only documented. Art. 30(3)(c) adds that the security level is appropriate in line with the customer's regulatory framework, which puts the customer's supervisor in the judgement.
Framework Mappings (16)
| GRC-05 | Information Security Program | full |
| GRC-05 | Information Security Program | full |
| DORA-Art.28.5 | Information security standards of the ICT third-party service provider | partial |
| DORA-Art.30.3.c | Business contingency plans and ICT security measures | partial |
| GDPR-Art.5.1f | Integrity and Confidentiality (Security Principle) | partial |
| HIPAA-164.306.a | General Requirements | partial |
| HIPAA-164.308.a.1.i | Security Management Process | partial |
| 5.1 | Policies for information security | informative |
| NIS2-Art.20.1 | Management Body Approval and Oversight of Cybersecurity Measures | informative |
| NIS2-Art.21.1 | Appropriate and Proportionate Cybersecurity Risk-Management Measures | partial |
| PM-1 | Information Security Program Plan | full |
| PM-3 | Information Security and Privacy Resources | partial |
| SA-2 | Allocation of Resources | partial |
| CC1.3 | COSO Principle 3: Establishes Structure, Authority, and Responsibility | partial |
| CC3.1 | COSO Principle 6: Specifies Suitable Objectives | partial |
| CC5.2 | COSO Principle 11: Selects and Develops General Controls Over Technology | partial |
Evidence (2)
Formal information security programme plan documenting scope, objectives, covered domains, resource allocation, and review schedule.
Example: Information Security Programme Plan (Confluence / Google Drive), including: scope boundary, list of covered security domains (access, incident response, third-party, etc.), approved budget or headcount, and a defined annual review date.
Test: Request the information security programme plan. Verify: (1) a defined scope statement is present, (2) all security domains covered are listed, (3) resource allocation (budget or FTE) is referenced, (4) a review interval is stated and the last review date is within that interval, (5) the document carries a management approval signature or equivalent.
Security programme status report showing management review of programme health and coverage against plan.
Example: Quarterly or annual security programme status report (PDF or Confluence page) submitted to the executive sponsor, showing domain coverage, metrics, and open issues.
Test: Request the most recent security programme status report. Verify: (1) the report was produced within the defined reporting cadence, (2) it is addressed to or has been reviewed by a named executive, (3) it covers all domains listed in the programme plan, (4) open issues and remediation status are included.
Questions (3)
Does a documented information security programme plan exist?
The programme plan should be a living document approved by management, listing all security domains in scope and referencing budget or headcount allocation.
How is progress against the information security programme plan reported to management?
A documented status report (quarterly or annually) addressed to or acknowledged by a named executive is the expected evidence.
Which of the following does the information security programme plan define?
Options run from the most commonly defined to the least. Resource allocation is the limb most often absent. A plan with objectives and no resources behind them is a statement of intent.