In its article 17, the Regulation of safety measures requires a mandatory audit for mid-level files. By referring to the mid-level files it covers also high-level ones. For information systems that were in operation when the Regulation entered into force on June 26, 1999, the mid-level security measures (including the audit) should be implemented within a year, which runs until June 26, 2000.