Article 45 – Information Security
49020.11.1.2 Message Integrity
-
An assessment of security risks should be carried out to determine whether message integrity is required and to identify the most appropriate method of implementation. Data output from an application shall be validated to ensure that the processing of stored information is correct.
-
Output validation may include:
-
Plausibility checks to test whether the output data is reasonable;
-
Reconciliation control counts to ensure processing of all data;
-
Providing sufficient information for a reader or subsequent processing system to determine the accuracy, completeness, precision, and classification of the information;
-
Procedures for responding to output validation tests;
-
Defining the responsibilities of all personnel involved in the data output process;
-
Creating a log of activities in the data output validation process.
-