An audit may be conducted by agency auditors or an independent security organisation.
7.4.
Accreditation Framework
Objective:
Mandatory Control 1:
Mandatory Control 2:
Accreditation is the formal authority for a system to operate, and
an important element in fundamental information system
governance. Accreditation requires risk identification and
assessment, selection and implementation of baseline and other
appropriate controls and the recognition and acceptance of
residual risks relating to the operation of a system. Accreditation
relies on the completion of system certification procedures
Agencies must develop an accreditation framework for their
agency
Agencies must ensure that each of their systems is awarded
accreditation
Mandatory Control 3:
Agencies must ensure that that all systems are awarded
accreditation before they are used operationally
Mandatory Control 4:
Agencies must ensure that that all systems are awarded
accreditation prior to connecting them to any other internal or
external system
Mandatory Control 5:
Agencies must ensure that the period between accreditations of
each of their systems does not exceed three years
Mandatory Control 6:
Agencies must not operate a system without accreditation or with
a lapsed accreditation unless the accreditation authority has
granted a dispensation
Recommended Control 1:
Agencies should ensure information security monitoring, logging
and auditing is conducted on all accredited systems
The development of an accreditation framework within the agency will ensure that accreditation
activities are conducted in a repeatable and consistent manner across the agency and that
consistency across government systems is maintained. This requirement is a fundamental part of a
robust governance model and provides a sound process to demonstrate good governance of
information systems.
25