10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.2 Security Plan<br />

The State <strong>of</strong> Kansas requires the development and implementation <strong>of</strong> a security plan<br />

that includes provisions for each information systems. This plan will indicate the<br />

current security stance <strong>of</strong> each information system, the intended security stance <strong>of</strong><br />

each information system, and the steps that need to be taken to achieve this intent.<br />

Security plans allow organizations to establish their intent regarding the on-going<br />

maintenance and/or improvement <strong>of</strong> security controls to ensure that security is<br />

always given appropriate credence in overall planning exercises. Without security<br />

plans the potential exists that security controls are not kept current with the<br />

protection requirements <strong>of</strong> the organization.<br />

Security plans shall address the modification/update to the controls that are already in<br />

place as well the implementation <strong>of</strong> additional controls that are to be put in place.<br />

Further it shall identify the planning process to be used, the individuals charged with<br />

the responsibility <strong>of</strong> the planning process (including contact information) and the<br />

rationale for the planned security controls. Security plans shall be reviewed and,<br />

where required, updated on at least an annual basis.<br />

As an addendum, where security vulnerability analyses (see section 6.1) determine<br />

that deficiencies or other flaws exist in the security configuration <strong>of</strong> any information<br />

system, the security plan shall be updated immediately to include provisions for<br />

correcting these flaws and the plan shall be reviewed and, where required, updated<br />

on at least a quarterly basis until remediated or resolved.<br />

8

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!