# O4.9 Mandate security audits by third parties

{% tabs %}
{% tab title="Principle" %}
[O4 Assure data security by design](/safeguards/universal-dpi-safeguards-framework/principles/operational-principles/o4-assure-data-security-by-design.md)
{% endtab %}

{% tab title="Risks" %}
[RS2 Digital insecurity,](/safeguards/universal-dpi-safeguards-framework/risks/risks-to-safety.md) [SV1 Digital distrust](/safeguards/universal-dpi-safeguards-framework/risks/risks-to-structural-vulnerabilities.md)
{% endtab %}

{% tab title="Lifecycle Stages" %}
[L5 Operations and Maintenance](/safeguards/universal-dpi-safeguards-framework/responsible-authorities/r3-donor/l5-operations-and-maintenance-1.md)
{% endtab %}
{% endtabs %}

## Practices

* Develop guidelines and criteria for selecting qualified third-party auditors with expertise in data security, ensuring audits are thorough and credible.
* Mandate regular security audits for all DPI systems and require the findings to be transparently reported to relevant stakeholders, including government bodies and the public.
* Use audit results to identify vulnerabilities and enforce timely implementation of recommended security enhancements, ensuring continuous improvement of DPI system security.&#x20;


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://safedpi.gitbook.io/safeguards/universal-dpi-safeguards-framework/processes/o4.9-mandate-security-audits-by-third-parties.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
