| Independent Security and Internal Control Certification/Accreditation of IT Services: obtaining independent certification/accreditation of security and internal controls (including all external service providers) prior to implementing critical new information technology services and re-certification/re-accreditation of these services on a routine cycle after implementation
|
|
| Independent Effectiveness Evaluation of IT Services: obtaining independent evaluation of the effectiveness of IT services (including all external service providers) on a routine cycle
|
| Independent Assurance of Compliance with Laws and Regulatory Requirements and Contractual Commitments: obtaining independent assurance of the information service function’s compliance (including all external service providers) with legal and regulatory requirements, and contractual commitments on a routine cycle
|