7.2.
Conducting Certifications
Objective:
Mandatory Control 1:
Mandatory Control 2:
Recommended Control 1:
The security posture of the organization has been incorporated
into its system security design, controls are correctly
implemented, are performing as intended and that changes and
modifications are reviewed for any security impact or
implications
All systems must undergo an audit as part of the certification
process
The certification authority must accept that the controls are
appropriate, effective and comply with the relevant GOBISM
components, in order to award certification
Following the audit, the certification authority should produce an
assessment for the Accreditation Authority outlining the residual
security risks relating to the operation of the system and a
recommendation on whether to award accreditation or not
The purpose of a Certification Audit is to assess the actual implementation and effectiveness of
controls for a system against the agency’s risk profile, security posture, design specifications,
agency policies and compliance with the GOBISM components.
To award certification for a system the certification authority will need to be satisfied that the
selected controls are appropriate and consistent with the relevant GOBISM components, have been
properly implemented and are operating effectively. However, certification acknowledges only that
controls were appropriate, properly implemented and are operating effectively. Certification does
not imply that the residual security risk is acceptable or an approval to operate has been granted.
The purpose of the residual security risk assessment is to assess the risks, controls and residual
security risk relating to the operation of a system. In situations where the system is non‐
conformant, the system owner may have to take corrective actions. The residual risk may not be
great enough to preclude a certification authority recommending to the Accreditation Authority
that accreditation be awarded but the risk must be acknowledged and appropriate caveats
documented.
7.3.
Objective:
Conducting Audits
The effectiveness of information security measures for systems is
periodically reviewed and validated
23