Objective: Mandatory Control 1: Mandatory Control 2: The effectiveness of information security measures for systems is periodically reviewed and validated Prior to undertaking the audit the system owner must approve the system architecture and associated information security documentation The SecPol, SRMP, SecPlan, SOPs and IRP documentation must be reviewed by the auditor to ensure that it is comprehensive and appropriate for the environment the system is to operate within Mandatory Control 3: The Information Security Policy (SecPol) must be reviewed by the auditor to ensure that all relevant controls specified in this manual are addressed Mandatory Control 4: Prior to undertaking any system testing in support of the certification process, the system owner must implement the controls for the system Mandatory Control 5: The implementation of controls must be assessed to determine whether they have been implemented correctly and are operating effectively Mandatory Control 6: The auditor must produce a report of compliance for the certification authority outlining areas of non‐compliance for a system and any suggested remediation actions Recommended Control 1: Agencies should ensure that auditors conducting audits are able to demonstrate independence and are not also the system owner or certification authority The system and security architectures should be reviewed by the auditor to ensure that it is based on sound information security principles and meets information security requirements, including the GOBISM Recommended Control 2: The aim of an audit is to review and assess: the risk identification design (including the system and security architectures) controls selection actual implementation and effectiveness of controls for a system supporting information security documentation The outcome of an audit is a report of compliance and control effectiveness for the certification authority outlining areas of non‐compliance for a system and any suggested remediation actions. 24

Select target paragraph3