PL +48 502 366 305 biuro@lyktaofficial.eu
Home  ›  IT system accreditation

IT system security accreditation

We prepare IT systems to process classified information — security documentation, risk assessment and handling of the accreditation proceedings.

Security accreditation of an IT system is the document that authorises the system to process classified information.

Without accreditation, no system may lawfully process classified information. For systems handling information classified "confidential" and above, accreditation is granted by the Internal Security Agency (ABW) or the Military Counterintelligence Service (SKW), each within its remit. For the "restricted" level, accreditation is granted by the head of the organisational unit.

Accreditation is a prerequisite for organisations delivering projects in the security and defence sector, and for contractors applying for a first-level facility security clearance.

A key principle: security documentation is produced in parallel with designing the system, not after it has been built. Attempting to accredit a finished system that was not designed against these requirements usually ends in a costly rebuild.

Documentation

Documents required for accreditation

SWB

Specific Security Requirements

The document describing the system, its architecture, purpose, the classification level of the information processed and the protection measures applied — organisational, physical, cryptographic and technical. It is the principal document assessed during accreditation.

PBE

Secure Operating Procedures

The set of procedures defining how the system is to be operated securely: managing privileges, backups, incident response, maintenance, disposal of media, and the duties of the system administrator and the security inspector.

  • Risk assessment documentation — the methodology and results of the risk assessment for the specific system, together with the rationale for the security measures selected.
  • Security test results — confirmation that the security measures applied operate in line with the assumptions set out in the SWB.
  • List of post holders — the system administrator and the IT security inspector, together with the relevant clearances and training.
Scope of work

What accreditation preparation involves

  1. Analysis of the system and processing scope

    We establish what information will be processed and at what classification level, how the system is built, where the security boundaries run and which authority grants accreditation.

  2. Risk assessment methodology and execution

    Identifying threats and vulnerabilities, assessing risk and selecting appropriate security measures — with the rationale that goes into the accreditation documentation.

  3. Preparing the SWB and PBE

    Complete system security documentation, consistent with the actual architecture and operating model — not a template detached from the reality of your organisation.

  4. Support with implementing security measures

    Supervising the implementation of physical security, access control, cryptographic solutions and event logging mechanisms within the system.

  5. Preparing post holders

    Designating and training the system administrator and the IT security inspector, including preparation for their vetting procedures.

  6. Handling the accreditation proceedings

    Filing the documentation, responding to comments and requests for clarification, and preparing the organisation for the system security audit conducted by ABW or SKW.

  7. Maintaining accreditation

    Updating documentation when the system changes, periodic compliance reviews and support with re-accreditation once the term expires.

Frequently asked questions

Accreditation explained

Who grants accreditation?

For systems processing classified information at "confidential" level and above, accreditation is granted by ABW or SKW, each within its remit. For the "restricted" level, accreditation is granted by the head of the organisational unit, who approves the system security documentation.

Is accreditation valid indefinitely?

No. Accreditation is granted for a fixed term. In addition, material changes to the system — modifying the architecture, changing the classification level of the information processed, adding new components — require the documentation to be updated and, in some cases, fresh accreditation proceedings.

Can an existing system be accredited?

It can, but this usually entails rebuilding. Systems built without regard to classified information requirements rarely meet them as they stand — most often the network architecture, access control model and cryptographic solutions all have to change. That is why work on the documentation should begin in parallel with designing the system.

Do I need accreditation to obtain a facility security clearance?

It depends on the level of clearance. A first-level clearance covers the capability to process classified information in IT systems and therefore requires an accredited system. At second and third level that requirement does not arise.

Planning a system to process classified information?

The best time to talk is at the design stage. We will review your assumptions and identify what must be accounted for so that accreditation runs smoothly.

Book a consultation