Task Tracker #186
openSystem Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.
30%
Description
- OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.
OMS does not perform regular information security risk assessments or apply risk treatment plans.
Files
RA Updated by Redmine Admin 5 months ago
- Subject changed from System Gap to System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.
LM Updated by Liberty Mutabvuri 13 days ago
- Related to Task Tracker #179: 31. Establish OMS IT Risk Reviews, Risk Register and Information Security Risk Treatment Process added
LM Updated by Liberty Mutabvuri 13 days ago
- Assignee set to Ntokozo Khanyile
Assigned to Ntokozo Khanyile. Periodic risk assessments are governed and tracked through main risk ticket #179.
NK Updated by Ntokozo Khanyile 4 days ago
- File OMS_Risk_Review_Reporting_Workflow_Templates.docx OMS_Risk_Review_Reporting_Workflow_Templates.docx added
- Status changed from New to In Progress
- % Done changed from 0 to 30
A monthly review schedule and template have now been drafted as part of the broader #179 risk-governance work (see attached OMS_Risk_Review_Reporting_Workflow_Templates.docx, Section 1 – Monthly Risk Review Template).
This template defines the review cadence, the fields to be completed each month (register movement, High/Critical risk status, emerging risks, decisions/actions), and a sign-off section, satisfying the "planned review schedule" requirement.
This gap is not yet closed. The template's existence is not evidence of an operating process — #186's acceptance criterion requires at least one complete monthly review to actually be performed and evidenced. That is tracked as Step 6 in the Implementation Runbook attached to #179, and is blocked on the baseline risk data being populated in the Master Risk Register first.
Reference: #179 (main governance ticket, contains the full policy, register, and action plan this schedule sits under).
Leaving open until the first monthly review is run and the evidence link is added here.