Computer Security: Audited for the better
The Computer Security team’s public account of the 2023 external cybersecurity audit.
What it anchors
- Summer 2023, external firm, against the CIS v8 standard, within the five-yearly internal audit plan.
- 82 recommendations, 73 accepted by the Director-General: 15 major, 34 medium, 24 minor, none catastrophic.
- The measures: SAST/DAST for GitLab repositories, SBOM and digital asset inventories, WAF tightening (ModSecurity, Falco) planned for 2026, SOC ingestion of Google Workspace / Azure / network logs, network segregation review, endpoint protection, antispoofing (SPF/DMARC/DKIM), a Data Governance Officer, and 2FA for all accounts.