86
(c)
implement measures, on the written request of the Director-General: State
Security, in order to assess and test National Critical Information Infrastructures,
including vulnerability assessments, threat and risk assessments and penetration
testing;
(d)
provide a reactive service to the State which includes—
(i)
responding to alerts and warnings;
(ii)
handling incidents by—
(iii)
(iv)
(e)
(aa)
incident analysis;
(bb)
providing incident responses on site;
(cc)
providing incident response support; and
(dd)
incident response coordination;
vulnerability handling by—
(aa)
analysing vulnerabilities;
(bb)
mitigating the effect of a vulnerability or repairing a vulnerability; and
(cc)
coordinating responses to vulnerabilities; and
artifact handling by—
(aa)
analysing artifacts;
(bb)
responding to artifacts; and
(cc)
artifact response coordination;
provide a proactive service to the State which includes—
(i)
intrusion alerts, vulnerability warnings, security advice and other similar
announcements;
(ii)
technical analysis of software, malware, intruder activities and related
trends in order to help identify future threats and vulnerabilities;
(iii)
the furnishing of security audits and assessments;
(iv)
the configuration and maintenance of equipment, software, hardware,
configurations and infrastructure;
(v)
the development of security tools;
(vi)
the provision of an intrusion detection service; and