7. System Certification and Accreditation
7.1.
The Certification and Accreditation Process
Objective:
Executives and Security Practitioners understand the Certification
and Accreditation (C&A) process and its role in information
security governance and assurance
Certification and Accreditation is a fundamental governance and assurance process, designed to
provide the Board, Chief Executive and senior executives confidence that information and its
associated technology are well‐managed, that risks are properly identified and mitigated and that
governance responsibilities can demonstrably be met. It is essential for credible and effective
information assurance governance.
C&A has two important stages where certification must be completed
accreditation can take
place. It is based on an assessment of risk, the application of controls described in the GOBISM and
determination of any residual risk.
Certification and Accreditation are separate and distinct elements, demonstrate segregation of
duties and assist in managing any potential conflicts of interest. These are important attributes in
good governance systems.
The acceptance of residual risk lies with the Chief Executive of each agency, or lead agency where
sector or multi‐agency systems are implemented.
The complete C&A process has several elements and stages, illustrated in the Block Diagram at the
end of this section.
There are four groups of participant in C&A process:
System Owners, responsible for the design, development, system documentation and
system maintenance, including any requests for recertification or reaccreditation
The Certification Authority, responsible for the review of information and documentation
provided by the system owner to ensure the ICT system complies with minimum standards
and the agreed design
The Assessor or Auditor, who will conduct inspections, audits and review as instructed by
the Certification Authority
The Accreditation Authority who will consider the recommendation of the Certification
Authority, determine the acceptable level of residual risk and issue the system accreditation,
the authority to operate a system.
20