Agencies should reaccredit their systems at least every two years. Accreditations should be commenced at least six months before due date to allow sufficient time for the certification and accreditations processes to be completed. Once three years has elapsed between accreditations, the authority to operate the system (the accreditation) will lapse and the agency will need to either reaccredit the system or request a dispensation to operate without accreditation. It should be noted that operating a system without accreditation is considered extremely risky. 7.5. Conducting Accreditations Objective: Mandatory Control 1: Mandatory Control 2: As a governance good practice, systems are accredited before they are used operationally All systems must be certified as part of the accreditation process The Accreditation Authority must accept the residual security risk relating to the operation of a system in order to award accreditation The aim of accreditation is to give formal recognition and acceptance of the residual security risk to a system and information it processes, stores or communicates as part of the agency’s governance arrangements. The outcome of accreditation is an approval to operate issued by the Accreditation Authority to the system owner. For agencies the Accreditation Authority is the agency head or their delegate. Depending on the circumstances and practices of an agency, the agency head could choose to delegate their authority to multiple senior executives who have the authority to accept security risks for the specific business functions within the agency, for example, the CISO and the system owner. More information on the delegation of the agency head’s authority can be found in Section 6.1 ‐ The Agency Head. Accreditation is awarded when the systems comply with the GOBISM, the Accreditation Authority understands and accepts the residual security risk relating to the operation of the system and the Accreditation Authority gives formal approval for the system to operate. In some cases the Accreditation Authority may not accept the residual security risk relating to the operation of the system. This outcome is predominately caused by security risks being insufficiently considered and documented within the SRMP resulting in an inaccurate scoping of security 26

Select target paragraph3