In conducting our audit we took precautions against inadvertently compromising information held on
Agencies internal computer systems and the risk that our attacks could seriously impede performance
Or ‘crash’ agency computer systems. For example, where agencies had large and complex computing environments and provided critical services, we advised senior management of the testing we were going to perform. This enabled them to advise us of any foreseeable risks. They were asked not to inform the staff directly responsible for detecting and responding to incidents, and not to assume any detected activity was necessarily from the audit office. The remaining agencies were advised more generally that we would test their ability to detect and respond to threats that arise in their computing infrastructure and networks.