First thing I spotted:
3 years is a long time to renew C&A's. A typical IT system would be 2 years. A sensitive system like this should be done annually (i.e once a year).Initially, and every three years, the system’s design, implementation and service management complete the Police Certification and Accreditation process, which is directed from Government through the NZ Information Security Manual and the Protective Security Requirements. Accreditation – or formal approval to operate – is provided by the Police Director of Assurance on successfully passing the certification process.
Bookmarks