29 In considering the question of how detailed
the verification of security systems would have to be, the Committee
confirmed that for all technical equipment, specified in the SSP,
100% verification was necessary, while for all operational (non-technical)
security measures a sample audit would be sufficient, to the level
necessary for the auditor to verify the whole operating system.