<section title="3.1. The Agency Head"><subsection title="Objective"><paragraph
    title="3.1.1."


><![CDATA[<p>The agency head is accountable for information security within their agency.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="3.1.2."


><![CDATA[<p>This section covers the role of an agency head with respect to information security.</p>]]></paragraph>
</block>
<block title="Chief executive officer /or other title"><paragraph
    title="3.1.3."


><![CDATA[<p>In some agencies and bodies, the person responsible for the agency or body may also be referred to as the CEO, Director General, Director or similar title specific to that agency.  In such cases the policy for the agency head is equally applicable.</p>]]></paragraph>
</block>
<block title="Devolving authority"><paragraph
    title="3.1.4."


><![CDATA[<p>When the agency head’s authority in this area has been devolved to a board, committee or panel, the requirements of this section relate to the chair or head of that body.</p>]]></paragraph>
<paragraph
    title="3.1.5."


><![CDATA[<p>The Agency Head is also the Accreditation Authority for that agency. See&nbsp;<a title="Accreditation Framework" href="http://nzism.gcsb.govt.nz/ism-document#Section-12591">Section 4.4 – Accreditation Framework</a>.</p>]]></paragraph>
<paragraph
    title="3.1.6."


><![CDATA[<p>Smaller agencies may not be able to satisfy all segregation of duty requirements because of scalability and small personnel numbers.  In such cases, potential conflicts of interest should be clearly identified, declared and actively managed for the protection of both the individual and of the agency.</p>]]></paragraph>
<paragraph
    title="3.1.7."


><![CDATA[<p>Refer also to <a title="Compliance by smaller agencies" href="http://nzism.gcsb.govt.nz/ism-document#Block-12104"><em>Compliance By Smaller Agencies</em> in 1.2.8</a> for information on joint approaches and resource pooling.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="Delegation of authority"><paragraph
    title="3.1.8.R.01."

    tags="Governance"


><![CDATA[<p>Where an agency head chooses to delegate their authority as the Agency’s Accreditation Authority they should do so with careful consideration of all the associated risks, as they remain responsible for the decisions made by their delegate.</p>]]></paragraph>
<paragraph
    title="3.1.8.R.02."

    tags="Governance"


><![CDATA[<p>The most suitable choice for delegated authority is a senior executive who has an appropriate level of understanding of the security risks they are accepting on behalf of the agency.</p>]]></paragraph>
<paragraph
    title="3.1.8.C.01."

    tags="Governance"


    classification="All Classifications"
    compliance="Must"
    cid="282"
><![CDATA[<p>Where the agency head devolves their authority the delegate MUST be at least a member of the Senior Executive Team or an equivalent management position.</p>]]></paragraph>
<paragraph
    title="3.1.8.C.02."


    classification="All Classifications"
    compliance="Should"
    cid="283"
><![CDATA[<p class="Normal-nonumbering">When the agency head delegates their authority, the delegate SHOULD be a senior executive who understands the consequences and potential impact to the business of the acceptance of residual risk.</p>]]></paragraph>
<paragraph
    title="3.1.8.C.03."

    tags="Governance"


    classification="All Classifications"
    compliance="Should"
    cid="284"
><![CDATA[<p>Where the head of a smaller agency is not able to satisfy all segregation of duty requirements because of scalability and small personnel numbers, all potential conflicts of interest SHOULD be clearly identified, declared and actively managed.</p>]]></paragraph>
</block>
<block title="Support for information security"><paragraph
    title="3.1.9.R.01."

    tags="Governance"


><![CDATA[<p>Without the full support of the agency head, security personnel are less likely to have access to sufficient resources and authority to successfully implement information security within their agency.</p>]]></paragraph>
<paragraph
    title="3.1.9.R.02."

    tags="Governance"


><![CDATA[<p>If an incident, breach or disclosure of classified information occurs in preventable circumstances, the relevant agency head will ultimately be held accountable.</p>]]></paragraph>
<paragraph
    title="3.1.9.C.01."

    tags="Governance"


    classification="All Classifications"
    compliance="Must"
    cid="288"
><![CDATA[<p>The agency head MUST provide support for the development, implementation and ongoing maintenance of information security processes within their agency.</p>]]></paragraph>
</block>
</subsection>
</section>
