Skjermingsverdige informasjonssystemer skal godkjennes av en godkjenningsmyndighet. Informasjonssystemer som skal behandle sikkerhetsgradert informasjon, skal godkjennes før de tas i bruk.
The organization must implement and maintain formal process to ensure that all information systems requiring protection are approved by a designated accreditation authority.
If the system will process classified information, the accreditation must be obtained before the system is put into operational use.
The organization must also establish a process for maintaining the system's accreditation if major changes are made to the system or its security posture.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.