UNCLASSIFIED compliance checks must identify and report insecure configurations; unauthorised installations; changes to system and application configuration;  Have in place a comprehensive audit regime that includes penetration testing or ethical hacking and system security audits to identify and report potential gaps in the security of operational systems;  Have in place a process for communicating additional security requirements to the Board and Accounting Officer in an event of newly identified security threats and vulnerabilities; and  Have in place an effective process for showing the compliance of security activities with all statutory, regulatory, and contractual requirements. 20

Select target paragraph3