An audit may be conducted by agency auditors or an independent security organisation. 7.4. Accreditation Framework Objective: Mandatory Control 1: Mandatory Control 2: Accreditation is the formal authority for a system to operate, and an important element in fundamental information system governance. Accreditation requires risk identification and assessment, selection and implementation of baseline and other appropriate controls and the recognition and acceptance of residual risks relating to the operation of a system. Accreditation relies on the completion of system certification procedures Agencies must develop an accreditation framework for their agency Agencies must ensure that each of their systems is awarded accreditation Mandatory Control 3: Agencies must ensure that that all systems are awarded accreditation before they are used operationally Mandatory Control 4: Agencies must ensure that that all systems are awarded accreditation prior to connecting them to any other internal or external system Mandatory Control 5: Agencies must ensure that the period between accreditations of each of their systems does not exceed three years Mandatory Control 6: Agencies must not operate a system without accreditation or with a lapsed accreditation unless the accreditation authority has granted a dispensation Recommended Control 1: Agencies should ensure information security monitoring, logging and auditing is conducted on all accredited systems The development of an accreditation framework within the agency will ensure that accreditation activities are conducted in a repeatable and consistent manner across the agency and that consistency across government systems is maintained. This requirement is a fundamental part of a robust governance model and provides a sound process to demonstrate good governance of information systems. 25

Select target paragraph3