CRA-5.2.7

Past version: Effective from 01 Jan 2020 to 31 Mar 2023
To view other versions open the versions tab on the right

Licensees must conduct test of their IT infrastructures and core systems to verify the robustness of the security control measure that is in place to prevent security breaches. These tests, among others, must include penetration testing and vulnerability assessment of the IT infrastructure. The test must be undertaken by an external independent party that have security professionals, such as ethical hackers, and not by employees of the licensee or entities associated with the licensee.

Added: January 2020