The Caisse de Compensation, a Moroccan organization, has taken steps to strengthen its cybersecurity by launching a tender for a comprehensive audit of its information system. This move aims to evaluate the overall security, identify technical and organizational vulnerabilities, and verify compliance with regulatory requirements. The audit will cover the organization's entire information system, including infrastructure, applications, and data.
The decision to conduct this audit comes in response to the increasing number of cyber threats and vulnerabilities affecting information systems. The Caisse de Compensation has been engaged in a digitalization process for several years, aiming to modernize its information system and improve service quality. The organization recognizes the need for continuous reinforcement of its information system's security level to mitigate potential risks.
The audit will be conducted in four phases over a period of 150 days. The first phase, lasting 20 days, will focus on defining the mission's scope, including the project management plan, preliminary planning, and workload plan. The second phase, lasting 70 days, will involve a technical audit, including an assessment of the system's architecture, configuration, and code source.
The technical audit will evaluate the robustness, relevance, and security of the system's design and implementation. It will identify structural weaknesses and provide concrete recommendations for improvement. The audit will also verify the system's compliance with Moroccan cybersecurity regulations, including Law No. 05-20 on cybersecurity and the National Directive on Information System Security.
The third phase, lasting 60 days, will focus on an organizational audit, assessing the governance, organization, and compliance of the information system's security. This phase will evaluate the maturity of organizational and procedural devices, identify gaps and associated risks, and provide recommendations for strengthening governance and resilience.
The final phase will involve the development of action plans, including corrective, preventive, and compensatory measures tailored to identified risks. The selected service provider will prioritize actions based on their criticality, impact, feasibility, and available resources, and provide a roadmap for improving the information system's security and compliance.
The Caisse de Compensation's efforts to enhance its cybersecurity demonstrate its commitment to protecting its information system and ensuring the confidentiality, integrity, and availability of its data. The organization invites bids from qualified service providers, with the tender opening scheduled for October 29.
Key points
- The Caisse de Compensation has launched a tender for a comprehensive audit of its information system to identify vulnerabilities and enhance cybersecurity.
- The audit will be conducted in four phases over 150 days, covering technical, organizational, and compliance aspects.
- The selected service provider will provide recommendations for improving the information system's security and compliance with Moroccan regulations.