Work Stream 3: Information Technology and Systems Audits
Status Awarded
Contract number 3000614989
Solicitation number 5000022607
Publication date
Contract award date
Contract value
Status Awarded
Contract number 3000614989
Solicitation number 5000022607
Publication date
Contract award date
Contract value
The objective of the audit is to assess whether NRCan has an effective Management Control Framework in place to mitigate risks in the event of a cyber security incident.
The scope of the engagement will include an assessment of the controls in place to support the Department to identify, prevent and recover from a cyber security attack including: the policy framework; management and business procedures dealing with risk and vulnerability management; processes for handling incidents, business continuity, security assessments, operational controls over network access and protection; and overall staff awareness. The scope will not include an evaluation of IT Governance or Physical Security, but will consider the results of recent audits completed in these areas
Refer to the description above for full details.