Certification is the assertion that an ICT system complies with the minimum standards and controls
described in the GOBISM, any relevant legislation and regulation and other relevant standards. It is
based on a comprehensive evaluation or systems audit. This process is described in Section 7.2 ‐
Conducting Certifications.
Certification is evidence that due consideration has been paid to risk, security, functionality,
business requirements and is a fundamental part of information systems governance and
assurance.
The Certification Authority for all agency information systems is the CISO unless otherwise
delegated by the Agency Head.
Accreditation is the formal authority to operate a system, evidence that governance requirements
have been addressed and that the Chief Executive has fulfilled the requirement to manage risk on
behalf of the organization and stakeholders. This element of the C&A process is described in Section
7.4 ‐ Accreditation Framework.
Accreditation ensures that either sufficient security measures have been put in place to protect
information that is processed, stored or communicated by the system or that deficiencies in such
measures have been identified, assessed and acknowledged, including the acceptance of any
residual risk.
The Accreditation Authority for agencies is the agency head or their delegate (senior executive or
CISO).
Penetration tests are an effective method of identifying vulnerabilities that in a system or network
testing existing security measures and testing the implementation of controls. Penetration testing is
also very useful in validating the effectiveness of the defensive mechanisms. This testing provides
an increased level of assurance when system certification and accreditation is undertaken. It also
demonstrates prudent risk management.
A penetration test usually involves the use of intrusive methods or attacks conducted by trusted
individuals, methods similar to those used by intruders or hackers. Care must be taken not to
adversely affect normal operations while these tests are conducted.
Penetration tests can range from simple scans of IP addresses in order to identify devices or
systems offering services with known vulnerabilities, to exploiting known vulnerabilities that exist in
an unpatched operating system, applications or other software. The results of these tests or attacks
are recorded, analyzed, documented and presented to the owner of the system. Any deficiencies
should then be addressed.
21