Project

General

Profile

Actions

Task Tracker #186

open
RA NK

System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

Task Tracker #186: System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

Added by Redmine Admin 5 months ago. Updated 4 days ago.

Status:
In Progress
Priority:
Medium
Start date:
03/11/2026
Due date:
% Done:

30%

Estimated time:

Description

  1. OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

OMS does not perform regular information security risk assessments or apply risk treatment plans.


Files


Related issues 1 (1 open0 closed)

Related to Task Tracker #179: 31. Establish OMS IT Risk Reviews, Risk Register and Information Security Risk Treatment ProcessIn ProgressNtokozo Khanyile03/11/2026

Actions

RA Updated by Redmine Admin 5 months ago Actions #1

  • Subject changed from System Gap to System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

LM Updated by Liberty Mutabvuri 13 days ago Actions #2

  • Related to Task Tracker #179: 31. Establish OMS IT Risk Reviews, Risk Register and Information Security Risk Treatment Process added

LM Updated by Liberty Mutabvuri 13 days ago Actions #3

  • Assignee set to Ntokozo Khanyile

Assigned to Ntokozo Khanyile. Periodic risk assessments are governed and tracked through main risk ticket #179.

NK Updated by Ntokozo Khanyile 4 days ago Actions #4

A monthly review schedule and template have now been drafted as part of the broader #179 risk-governance work (see attached OMS_Risk_Review_Reporting_Workflow_Templates.docx, Section 1 – Monthly Risk Review Template).

This template defines the review cadence, the fields to be completed each month (register movement, High/Critical risk status, emerging risks, decisions/actions), and a sign-off section, satisfying the "planned review schedule" requirement.

This gap is not yet closed. The template's existence is not evidence of an operating process — #186's acceptance criterion requires at least one complete monthly review to actually be performed and evidenced. That is tracked as Step 6 in the Implementation Runbook attached to #179, and is blocked on the baseline risk data being populated in the Master Risk Register first.

Reference: #179 (main governance ticket, contains the full policy, register, and action plan this schedule sits under).

Leaving open until the first monthly review is run and the evidence link is added here.

Actions

Also available in: PDF Atom