86

(c)

implement measures, on the written request of the Director-General: State
Security, in order to assess and test National Critical Information Infrastructures,
including vulnerability assessments, threat and risk assessments and penetration
testing;

(d)

provide a reactive service to the State which includes—
(i)

responding to alerts and warnings;

(ii)

handling incidents by—

(iii)

(iv)

(e)

(aa)

incident analysis;

(bb)

providing incident responses on site;

(cc)

providing incident response support; and

(dd)

incident response coordination;

vulnerability handling by—
(aa)

analysing vulnerabilities;

(bb)

mitigating the effect of a vulnerability or repairing a vulnerability; and

(cc)

coordinating responses to vulnerabilities; and

artifact handling by—
(aa)

analysing artifacts;

(bb)

responding to artifacts; and

(cc)

artifact response coordination;

provide a proactive service to the State which includes—
(i)

intrusion alerts, vulnerability warnings, security advice and other similar
announcements;

(ii)

technical analysis of software, malware, intruder activities and related
trends in order to help identify future threats and vulnerabilities;

(iii)

the furnishing of security audits and assessments;

(iv)

the configuration and maintenance of equipment, software, hardware,
configurations and infrastructure;

(v)

the development of security tools;

(vi)

the provision of an intrusion detection service; and

Select target paragraph3