111
(c)
requests the Director-General: State Security to perform an audit referred to in
subsection (1),
the Director-General: State Security must cause an audit to be performed on the
National Critical Information Infrastructure in order to evaluate compliance with the
provisions of section 58(6) of this Act.
(7)
No person may perform an audit on a National Critical Information
Structure pursuant to the provisions of subsection (6) unless he or she—
(a)
has been authorised in writing by the Director-General: State Security to perform
such audit;
(b)
is in possession of a certificate of appointment, in the prescribed form, issued by
the Director-General: State Security, which certificate must be produced on
demand; and
(c)
is accompanied by a person in control of the National Critical Information
Infrastructure or a person designated by such a person.
(8)
The person contemplated in subsection (7)(c) and any other
employee of the National Critical Information Structure must assist and provide
technical assistance and support to a person who is authorised to carry out an audit in
terms of subsection (7)(a).
(9)
The National Critical Information Structure which is audited
pursuant to the provisions of subsection (6) is responsible for the cost of the audit.
(10)
The owner of, or person in control of, a National Critical Information
Infrastructure who—
(a)
fails to cause an audit to be performed on a National Critical Information
Infrastructure in order to evaluate compliance with the provisions of section
58(6) of this Act as contemplated in subsection (1);
(b)
fails to notify the Director-General: State Security, in writing of an audit to be
performed as contemplated in subsection (2);
(c)
fails to—
(i)
report on the outcome of the audit within 30 days; or