User Security Self-Assessment

Has the meaning given to that expression in Section G8.18 (Categories of Security Assurance Assessment).

A “User Security Self-Assessment” shall be an assessment carried out by a User, the outcome of which
is reviewed by the User Independent Security Assurance Service Provider, to identify any material
increase in the security risk relating to the Systems, Data, functionality and processes of that User falling
within Section G5.14 (Information Security: Obligations on Users) since the last occasion on which a
User Security Assessment was carried out in respect of that User.

