Objective:
Mandatory Control 1:
Mandatory Control 2:
The effectiveness of information security measures for systems is
periodically reviewed and validated
Prior to undertaking the audit the system owner must approve the
system architecture and associated information security
documentation
The SecPol, SRMP, SecPlan, SOPs and IRP documentation must be
reviewed by the auditor to ensure that it is comprehensive and
appropriate for the environment the system is to operate within
Mandatory Control 3:
The Information Security Policy (SecPol) must be reviewed by the
auditor to ensure that all relevant controls specified in this manual
are addressed
Mandatory Control 4:
Prior to undertaking any system testing in support of the
certification process, the system owner must implement the
controls for the system
Mandatory Control 5:
The implementation of controls must be assessed to determine
whether they have been implemented correctly and are operating
effectively
Mandatory Control 6:
The auditor must produce a report of compliance for the
certification authority outlining areas of non‐compliance for a
system and any suggested remediation actions
Recommended Control 1:
Agencies should ensure that auditors conducting audits are able to
demonstrate independence and are not also the system owner or
certification authority
The system and security architectures should be reviewed by the
auditor to ensure that it is based on sound information security
principles and meets information security requirements, including
the GOBISM
Recommended Control 2:
The aim of an audit is to review and assess:
the risk identification
design (including the system and security architectures)
controls selection
actual implementation and effectiveness of controls for a system
supporting information security documentation
The outcome of an audit is a report of compliance and control effectiveness for the certification
authority outlining areas of non‐compliance for a system and any suggested remediation actions.
24