-
4
pages
-
English
-
Documents
Description
Compliance Review of Security of Electronic Information Information is an asset that must be protected to ensure its necessary confidentiality, integrity and availability. Governments gather a large amount of information as they conduct their business. They become custodians of information that may be politically, commercially and personally sensitive. Governments therefore have a duty of care to protect the information from unauthorised or accidental modification, loss or release. Information can be printed or written, stored electronically, transmitted by post or using electronic means, shown on films or spoken in conversation. CONCLUSION Our review looked at the progress made by 23 agencies towards obtaining certification of their information systems under the national standard AS/NZS 7799. The review indicated that while about one-third of those tested had made good progress, many agencies have a lot of work to do before they will be ready to seek certification. KEY FINDINGS Agency progress towards achieving the certification deadlines set by Government has been varied. At the time of the audit, in our view seven of the agencies sampled had made little progress in undertaking the formal requirements necessary to achieve certification under the national standard. Only twelve agencies in our sample had completed a full risk assessment, which is the first requirement in the overall certification process. Agencies must have in place an extensive ...
-
Publié par
-
Langue
English