(1) The ICRIR must put in place a policy document in relation to the holding and handling of information by the ICRIR.
(2) The policy document must explain the ICRIR’s policies and procedures for—
(a) securely accessing information held by others (including information which is to be transferred to the ICRIR);
(b) the secure receipt of information being transferred to the ICRIR;
(c) the secure retention of information by the ICRIR;
(d) the secure destruction or transfer of information which is to cease to be held by the ICRIR;
(e) managing and investigating any breaches of the ICRIR’s policies and procedures in relation to the holding and handling of information (which must include the reporting of all breaches to the Chief Commissioner).
(3) In meeting the obligation under paragraph (1), the ICRIR must have regard to and, insofar as possible, incorporate the requirements of the following documents published by the Cabinet Office—
(a) the document titled “Government Functional Standard GovS 007: Security – Version 2.0 13 September 2021” ;
(b) the document titled “HMG Personnel Security Controls – Version 6 2022” ;
(c) the document titled “Government Security Classifications Policy – 30 June 2023” ;
(d) the document titled “International Classified Exchanges – Version 1.5 March 2020” ;
(e) the document titled “Guidance: Protecting international RESTRICTED classified information – Version 1.3 March 2020” .
(4) The ICRIR must keep the policy document under review and update it as required.
(5) The ICRIR must—
(a) publish the policy document at the same time as it first publishes an annual report , and
(b) where it updates the policy document, publish the updated document at the same time as it next publishes an annual report.
(6) The ICRIR may make redactions to the policy document before publishing it under paragraph (5)(a) or (b).