System owners of CIS handling EUCI
Article 9
1. The system owner shall contact the Security Accreditation Authority as early as possible in a project to implement a CIS handling EUCI in order to determine the relevant security standards and requirements, and to begin the process of security accreditation. 2. The system owner shall ensure that the security measures satisfy the requirements of the Security Accreditation Authority and that the CIS does not handle EUCI before it has been accredited. 3. The system owner shall contact the Crypto Approval Authority for approval to use any encrypting technologies. System owners shall not operate encrypting technologies in production systems without prior approval. 4. The system owner shall consult the department’s LISO for matters relating to the security of CISs. 5. The system owner shall review the security measures that are applied to a system, including its security plan, at least annually. 6. Where a security incident occurs in a CIS whereby it is indicated that the CIS can no longer adequately protect EUCI, the system owner shall inform the LSO and immediately contact the Security Accreditation Authority for advice on how to proceed. In this case, accreditation may be suspended and the system may be taken out of operation until suitable corrective action has been taken. 7. The system owner shall give the Security Accreditation Authority full support at all times in the latter’s duties relating to the accreditation of the CIS.