Project

General

Profile

Actions

Task Tracker #186

open
RA NK

System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

Task Tracker #186: System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

Added by Redmine Admin 7 months ago. Updated 27 days ago.

Status:
In Progress
Priority:
Medium
Start date:
03/11/2026
Due date:
% Done:

40%

Estimated time:

Description

  1. OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

OMS does not perform regular information security risk assessments or apply risk treatment plans.


Files


Related issues 1 (1 open — 0 closed)

Related to Task Tracker #179: 31. Establish OMS IT Risk Reviews, Risk Register and Information Security Risk Treatment ProcessIn ProgressNtokozo Khanyile03/11/2026

Actions

RA Updated by Redmine Admin 7 months ago Actions #1

  • Subject changed from System Gap to System Gap- 21 OMS has not yet performed information security risk assessments at planned intervals as per the requirements of the standard.

LM Updated by Liberty Mutabvuri 2 months ago Actions #2

  • Related to Task Tracker #179: 31. Establish OMS IT Risk Reviews, Risk Register and Information Security Risk Treatment Process added

LM Updated by Liberty Mutabvuri 2 months ago Actions #3

  • Assignee set to Ntokozo Khanyile

Assigned to Ntokozo Khanyile. Periodic risk assessments are governed and tracked through main risk ticket #179.

NK Updated by Ntokozo Khanyile 2 months ago Actions #4

A monthly review schedule and template have now been drafted as part of the broader #179 risk-governance work (see attached OMS_Risk_Review_Reporting_Workflow_Templates.docx, Section 1 – Monthly Risk Review Template).

This template defines the review cadence, the fields to be completed each month (register movement, High/Critical risk status, emerging risks, decisions/actions), and a sign-off section, satisfying the "planned review schedule" requirement.

This gap is not yet closed. The template's existence is not evidence of an operating process — #186's acceptance criterion requires at least one complete monthly review to actually be performed and evidenced. That is tracked as Step 6 in the Implementation Runbook attached to #179, and is blocked on the baseline risk data being populated in the Master Risk Register first.

Reference: #179 (main governance ticket, contains the full policy, register, and action plan this schedule sits under).

Leaving open until the first monthly review is run and the evidence link is added here.

NK Updated by Ntokozo Khanyile 27 days ago Actions #5

  • % Done changed from 30 to 40

Progress Update - 2026-09-03

System Gap-21: Information Security Risk Assessments

✅ COMPLETED:

Governance Framework:
✅ Vulnerability Management Procedure created and approved
✅ Monthly Risk Review Template created and approved
✅ MANCO Reporting Template created and approved
✅ Residual-Risk Acceptance Workflow created and approved
✅ Risk Escalation & Overdue-Action Procedure created and approved
✅ Review schedule defined (monthly)
✅ Executive Risk Owner and Process Owner appointed

Risk Register:
✅ Master Risk Register template created with all required fields
✅ SecurityScorecard findings mapped (10 risks)
✅ Risk statements documented in cause-event-impact format
✅ Likelihood, Impact and Risk Rating criteria applied
✅ Treatment actions assigned with owners and target dates

Evidence Locations:

  • Vulnerability Management Procedure: /root/vulnerability_management_procedure.md
  • Templates: OMS_Risk_Review_Reporting_Workflow_Templates.docx (Section 1-4)
  • Risk Register: OMS_Master_IT_Security_Risk_Register.xlsx

⏳ PENDING:

Baseline Assessment (Requires Asset Register #438):
⏳ Identity, access, MFA, privileged accounts assessment
⏳ Source code, CI/CD, deployment controls assessment
⏳ Environment separation assessment
⏳ Secrets and API-key ownership assessment
⏳ Backups, DR, business continuity assessment
⏳ M365, SharePoint, email, domains, DNS assessment
⏳ Cloud, Coolify, databases, storage assessment
⏳ OBSE, CVEvolve, OMS apps assessment
⏳ Network exposure and pen-test remediation assessment
⏳ Devices, laptops, physical security assessment

First Monthly Review:
⏳ Conduct first monthly risk review (requires register populated)
⏳ Present first MANCO risk report

Acceptance Criteria Status:

  • ✅ Review schedule defined (monthly)
  • ✅ Templates created and approved
  • ✅ Process owners appointed
  • ⏳ First review conducted (pending baseline assessment)
  • ⏳ First MANCO report presented (pending review)

Next Steps:

  1. Complete asset register (#438) to enable full baseline assessment
  2. Populate Risk Register with all assets and risks
  3. Run first monthly risk review
  4. Present first MANCO report
Actions

Also available in: PDF Atom