Connect with us

Kingdom

Cybersecurity: The Ministry of Economy and Finance Launches the Technical Audit of Its IS

The objective is to identify the technical and functional vulnerabilities of the information systems, analyze their criticality level, and determine the risks in light of business stakes. The details.

Published


Updated

The Ministry of Economy and Finance continues to strengthen its digital defense in the face of the growing power of cyberattacks.

After having entrusted, in mid-February, to the company Dataprotect the managed services for surveillance, detection, and response to security incidents of its Security Operations Center (SOC), the department led by Nadia Fettah is launching a new, equally strategic project: the technical audit of the security of its information systems (IS).

With a total estimated budget of 3.4 million dirhams (MDH), this contract, split into three lots, aims to assess the overall security of the ministry’s information systems. The objective is to identify technical and functional vulnerabilities, analyze their criticality level, and determine the risks in light of business stakes.

The services, which will extend over a period of one year renewable by tacit renewal without exceeding three years, will cover the information systems of the ministry’s twelve directorates. They will involve application and network penetration tests, architecture and configuration audits, as well as environmental and physical audits, not forgetting source code review.

Identifying IS Vulnerabilities

In detail, the provider will be responsible for assessing the compliance of systems with security standards and best practices, as well as analyzing the robustness of existing protection devices. It will also have to identify vulnerabilities that could be exploited, whether for attempts at fraud, unauthorized access or manipulation of data, interception of sensitive information, or even viral attacks.

The mission will also include identifying system and application vulnerabilities, evaluating their resistance against different attack scenarios, and formulating clear and operational recommendations. The provider will furthermore have to support the ministry in addressing the weaknesses detected in order to improve the overall resilience of its information systems.

In addition to developing action plans following each audit activity, the selected company, whose identity should be known on April 28 next, may also be called upon to support the ministry’s teams in the effective implementation of the recommended measures.