(4) Držitel povolení musí pravidelně hodnotit úroveň zabezpečení počítačových systémů včetně jejich pravidelného bezpečnostního testování.