GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-004 Information Security Programme

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A formal information security programme exists with documented scope, objectives, and resource allocation. The programme covers all relevant security domains, is aligned with business risk, and is reviewed at planned intervals by management.

Rationale

An undocumented or resource-starved security programme cannot systematically implement or maintain controls across the organisation. The programme plan is the master reference for scope and coverage.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredrole duty

Art. 28(5) lets a financial entity contract only with providers that comply with appropriate information security standards. For services supporting a critical or important function it weighs the use of the most up-to-date and highest quality ones. The programme has to be measurable against a named external standard, not only documented. Art. 30(3)(c) adds that the security level is appropriate in line with the customer's regulatory framework, which puts the customer's supervisor in the judgement.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (16)

GRC-05Information Security Programfull
GRC-05Information Security Programfull
DORA-Art.28.5Information security standards of the ICT third-party service providerpartial
DORA-Art.30.3.cBusiness contingency plans and ICT security measurespartial
GDPR-Art.5.1fIntegrity and Confidentiality (Security Principle)partial
HIPAA-164.306.aGeneral Requirementspartial
HIPAA-164.308.a.1.iSecurity Management Processpartial
5.1Policies for information securityinformative
NIS2-Art.20.1Management Body Approval and Oversight of Cybersecurity Measuresinformative
NIS2-Art.21.1Appropriate and Proportionate Cybersecurity Risk-Management Measurespartial
PM-1Information Security Program Planfull
PM-3Information Security and Privacy Resourcespartial
SA-2Allocation of Resourcespartial
CC1.3COSO Principle 3: Establishes Structure, Authority, and Responsibilitypartial
CC3.1COSO Principle 6: Specifies Suitable Objectivespartial
CC5.2COSO Principle 11: Selects and Develops General Controls Over Technologypartial

Evidence (2)

policydocumentmanual

Formal information security programme plan documenting scope, objectives, covered domains, resource allocation, and review schedule.

Example: Information Security Programme Plan (Confluence / Google Drive), including: scope boundary, list of covered security domains (access, incident response, third-party, etc.), approved budget or headcount, and a defined annual review date.

Test: Request the information security programme plan. Verify: (1) a defined scope statement is present, (2) all security domains covered are listed, (3) resource allocation (budget or FTE) is referenced, (4) a review interval is stated and the last review date is within that interval, (5) the document carries a management approval signature or equivalent.

reportdocumentmanual

Security programme status report showing management review of programme health and coverage against plan.

Example: Quarterly or annual security programme status report (PDF or Confluence page) submitted to the executive sponsor, showing domain coverage, metrics, and open issues.

Test: Request the most recent security programme status report. Verify: (1) the report was produced within the defined reporting cadence, (2) it is addressed to or has been reviewed by a named executive, (3) it covers all domains listed in the programme plan, (4) open issues and remediation status are included.

Questions (3)

boolean

Does a documented information security programme plan exist?

The programme plan should be a living document approved by management, listing all security domains in scope and referencing budget or headcount allocation.

select

How is progress against the information security programme plan reported to management?

Regular written status reports reviewed by a named executiveVerbal updates at management meetings with no formal reportOnly on requestProgress is not formally reported

A documented status report (quarterly or annually) addressed to or acknowledged by a named executive is the expected evidence.

multi

Which of the following does the information security programme plan define?

Its scopeIts objectivesThe security domains it coversThe resources allocated to it, such as budget or headcountIts alignment to the assessed business riskNone of the above

Options run from the most commonly defined to the least. Resource allocation is the limb most often absent. A plan with objectives and no resources behind them is a statement of intent.