UNCLASSIFIED
compliance checks must identify and report insecure configurations;
unauthorised installations; changes to system and application configuration;
Have in place a comprehensive audit regime that includes penetration testing
or ethical hacking and system security audits to identify and report potential
gaps in the security of operational systems;
Have in place a process for communicating additional security requirements
to the Board and Accounting Officer in an event of newly identified security
threats and vulnerabilities; and
Have in place an effective process for showing the compliance of security
activities with all statutory, regulatory, and contractual requirements.
20