7. System Certification and Accreditation 7.1. The Certification and Accreditation Process Objective: Executives and Security Practitioners understand the Certification and Accreditation (C&A) process and its role in information security governance and assurance Certification and Accreditation is a fundamental governance and assurance process, designed to provide the Board, Chief Executive and senior executives confidence that information and its associated technology are well‐managed, that risks are properly identified and mitigated and that governance responsibilities can demonstrably be met. It is essential for credible and effective information assurance governance. C&A has two important stages where certification must be completed accreditation can take place. It is based on an assessment of risk, the application of controls described in the GOBISM and determination of any residual risk. Certification and Accreditation are separate and distinct elements, demonstrate segregation of duties and assist in managing any potential conflicts of interest. These are important attributes in good governance systems. The acceptance of residual risk lies with the Chief Executive of each agency, or lead agency where sector or multi‐agency systems are implemented. The complete C&A process has several elements and stages, illustrated in the Block Diagram at the end of this section. There are four groups of participant in C&A process: System Owners, responsible for the design, development, system documentation and system maintenance, including any requests for recertification or reaccreditation The Certification Authority, responsible for the review of information and documentation provided by the system owner to ensure the ICT system complies with minimum standards and the agreed design The Assessor or Auditor, who will conduct inspections, audits and review as instructed by the Certification Authority The Accreditation Authority who will consider the recommendation of the Certification Authority, determine the acceptable level of residual risk and issue the system accreditation, the authority to operate a system. 20

Select target paragraph3