7.2. Conducting Certifications Objective: Mandatory Control 1: Mandatory Control 2: Recommended Control 1: The security posture of the organization has been incorporated into its system security design, controls are correctly implemented, are performing as intended and that changes and modifications are reviewed for any security impact or implications All systems must undergo an audit as part of the certification process The certification authority must accept that the controls are appropriate, effective and comply with the relevant GOBISM components, in order to award certification Following the audit, the certification authority should produce an assessment for the Accreditation Authority outlining the residual security risks relating to the operation of the system and a recommendation on whether to award accreditation or not The purpose of a Certification Audit is to assess the actual implementation and effectiveness of controls for a system against the agency’s risk profile, security posture, design specifications, agency policies and compliance with the GOBISM components. To award certification for a system the certification authority will need to be satisfied that the selected controls are appropriate and consistent with the relevant GOBISM components, have been properly implemented and are operating effectively. However, certification acknowledges only that controls were appropriate, properly implemented and are operating effectively. Certification does not imply that the residual security risk is acceptable or an approval to operate has been granted. The purpose of the residual security risk assessment is to assess the risks, controls and residual security risk relating to the operation of a system. In situations where the system is non‐ conformant, the system owner may have to take corrective actions. The residual risk may not be great enough to preclude a certification authority recommending to the Accreditation Authority that accreditation be awarded but the risk must be acknowledged and appropriate caveats documented. 7.3. Objective: Conducting Audits The effectiveness of information security measures for systems is periodically reviewed and validated 23

Select target paragraph3