This unit is responsible for the organs of State security needs analysis project (audits or survey).
- SECURITY AUDITS
The COMSEC ACT prescribes an audit to be performed every two years to establish a security posture of organs of state. The COMSEC Security Audit Regulations were published in the Government Gazette No.26914 of the 20th October 2004
The Purpose of the security audit is to
- Determine if adequate steps have been taken to document and communicate ICT security acceptable use policy guidelines to users
- Obtain detailed understanding of physical security measures taken to protect electronic communication critical or sensitive information processing facilities.
- Obtain detailed understanding of access control security measures taken to protect electronic communication systems
- Determine the deployment of existing information and communications security measures within government department
- Obtain detailed understanding of security measures taken to protect information and electronic communication assets of organ of state
- Obtain detailed understanding of security measures taken to reduce the risk of human error, theft, fraud or misuse of information processing and electronic communication facilities