The specific requirements for the directive on recordkeeping are described in section 6 and are initially to ensure that the information resources of business value are properly identified, that a risk profile for those information resources is created, and that it is done with respect to taking into consideration access to information and protection of personal information, and then, that measures are taken to respond to those risks.
Then there is the responsibility to ensure that the methodologies and mechanisms and tools are put in place to support the management of those records of business value. Another recordkeeping requirement is that the practices are documented and also that good communication goes out to departmental managers and employees to ensure they understand what their responsibilities are under the act. A companion directive talks about information management responsibilities and lays out what an employee's responsibility is and what a manager's responsibilities are, ensuring this information is communicated.
Under section 6.2, the requirements are around the monitoring. Under the IM policy, the deputy head appoints this IM senior official, who is the person responsible for the implementation and monitoring of that implementation within a department.