Computer Security: Audited for the better

The Computer Security team’s public account of the 2023 external cybersecurity audit.

What it anchors

  • Summer 2023, external firm, against the CIS v8 standard, within the five-yearly internal audit plan.
  • 82 recommendations, 73 accepted by the Director-General: 15 major, 34 medium, 24 minor, none catastrophic.
  • The measures: SAST/DAST for GitLab repositories, SBOM and digital asset inventories, WAF tightening (ModSecurity, Falco) planned for 2026, SOC ingestion of Google Workspace / Azure / network logs, network segregation review, endpoint protection, antispoofing (SPF/DMARC/DKIM), a Data Governance Officer, and 2FA for all accounts.