109

(c)

must cause the necessary accounting and other related records to be kept.
(6)

Any money in the Fund which is not required for immediate use

must be invested by the Director-General: State Security with a banking institution
approved by the Cabinet member responsible for State security, in consultation with the
Cabinet member responsible for national financial matters, and may be withdrawn when
required.
(7)

Any unexpended balance of the money in the Fund at the end of

any financial year must be carried forward as a credit in the Fund to the next financial
year.
(8)

The Fund and the records referred to in subsection (5)(c) must be

audited by the Auditor-General.
(9)
(a)

(b)

For purposes of this section—

“disaster management measure” means any measure aimed at—
(i)

preventing or reducing the risk of a disaster;

(ii)

mitigating the severity or consequences of a disaster;

(iii)

emergency preparedness;

(iv)

rapid and effective responses to a disaster; and

(v)

post-disaster recovery and rehabilitation; and

“disaster situation” means a progressive or sudden, widespread or localised
occurrence, which takes place or is imminent and which causes or may cause
substantial damage to a National Critical Information Infrastructure or any part
thereof and which is of such a magnitude that it exceeds the ability of such a
National Critical Information Infrastructure affected by the disaster to cope with its
effects using its own resources only.

Auditing of National Critical Information Infrastructures to ensure compliance

60.

(1)

The owner of, or person in control of, a National Critical Information

Infrastructure must, at least once a year, cause an audit to be performed on the

Select target paragraph3