C5-AM-01 | Asset Inventory | 31 |
C5-AM-02 | Acceptable Use and Safe Handling of Assets Policy | 30 |
C5-AM-03 | Commissioning of Hardware | 23 |
C5-AM-04 | Decommissioning of Hardware | 24 |
C5-AM-05 | Commitment to Permissible Use, Safe Handling and Return of Assets | 22 |
C5-AM-06 | Asset Classification and Labelling | 27 |
C5-BCM-01 | Top management responsibility | 20 |
C5-BCM-02 | Business impact analysis policies and instructions | 22 |
C5-BCM-03 | Planning business continuity | 26 |
C5-BCM-04 | Verification, updating and testing of the business continuity | 27 |
C5-COM-01 | Identification of applicable legal, regulatory, self-imposed or contractual requirements | 26 |
C5-COM-02 | Policy for planning and conducting audits | 26 |
C5-COM-03 | Internal audits of the information security management system | 31 |
C5-COM-04 | Information on information security performance and management assessment of the ISMS | 29 |
C5-COS-01 | Technical safeguards | 23 |
C5-COS-02 | Security requirements for connections in the Cloud Service Provider's network | 24 |
C5-COS-03 | Monitoring of connections in the Cloud Service Provider's network | 25 |
C5-COS-04 | Cross-network access | 25 |
C5-COS-05 | Networks for administration | 23 |
C5-COS-06 | Segregation of data traffic in jointly used network environments | 23 |
C5-COS-07 | Documentation of the network topology | 23 |
C5-COS-08 | Policies for data transmission | 26 |
C5-CRY-01 | Policy for the use of encryption procedures and key management | 23 |
C5-CRY-02 | Encryption of data for transmission (transport encryption) | 27 |
C5-CRY-03 | Encryption of sensitive data for storage | 27 |
C5-CRY-04 | Secure key management | 20 |
C5-DEV-01 | Policies for the development/procurement of information systems | 22 |
C5-DEV-02 | Outsourcing of the development | 20 |
C5-DEV-03 | Policies for changes to information systems | 23 |
C5-DEV-04 | Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools | 24 |
C5-DEV-05 | Risk assessment, categorisation and prioritisation of changes | 19 |
C5-DEV-06 | Testing changes | 19 |
C5-DEV-07 | Logging of changes | 21 |
C5-DEV-08 | Version Control | 14 |
C5-DEV-09 | Approvals for provision in the production environment | 20 |
C5-DEV-10 | Separation of environments | 22 |
C5-HR-01 | Verification of qualification and trustworthiness | 26 |
C5-HR-02 | Employment terms and conditions | 24 |
C5-HR-03 | Security training and awareness programme | 33 |
C5-HR-04 | Disciplinary measures | 18 |
C5-HR-05 | Responsibilities in the event of termination or change of employment | 24 |
C5-HR-06 | Confidentiality agreements | 19 |
C5-IDM-01 | Policy for user accounts and access rights | 29 |
C5-IDM-02 | Granting and change of user accounts and access rights | 27 |
C5-IDM-03 | Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins | 25 |
C5-IDM-04 | Withdraw or adjust access rights as the task area changes | 25 |
C5-IDM-05 | Regular review of access rights | 26 |
C5-IDM-06 | Privileged access rights | 29 |
C5-IDM-07 | Access to cloud customer data | 23 |
C5-IDM-08 | Confidentiality of authentication information | 28 |
C5-IDM-09 | Authentication mechanisms | 32 |
C5-INQ-01 | Legal Assessment of Investigative Inquiries | 11 |
C5-INQ-02 | Informing Cloud Customers about Investigation Requests | 5 |
C5-INQ-03 | Conditions for Access to or Disclosure of Data in Investigation Requests | 8 |
C5-INQ-04 | Limiting Access to or Disclosure of Data in Investigation Requests | 4 |
C5-OIS-01 | Information Security Management System (ISMS) | 27 |
C5-OIS-02 | Information Security Policy | 27 |
C5-OIS-03 | Interfaces and Dependencies | 23 |
C5-OIS-04 | Segregation of Duties | 25 |
C5-OIS-05 | Contact with Relevant Government Agencies and Interest Groups | 19 |
C5-OIS-06 | Risk Management Policy | 34 |
C5-OIS-07 | Application of the Risk Management Policy | 34 |
C5-OPS-01 | Capacity Management - Planning | 11 |
C5-OPS-02 | Capacity Management - Monitoring | 8 |
C5-OPS-03 | Capacity Management - Controlling of Resources | 14 |
C5-OPS-04 | Protection Against Malware - Concept | 24 |
C5-OPS-05 | Protection Against Malware - Implementation | 28 |
C5-OPS-06 | Data Backup and Recovery - Concept | 24 |
C5-OPS-07 | Data Backup and Recovery - Monitoring | 20 |
C5-OPS-08 | Data Backup and Recovery - Regular Testing | 24 |
C5-OPS-09 | Data Backup and Recovery - Storage | 25 |
C5-OPS-10 | Logging and Monitoring - Concept | 30 |
C5-OPS-11 | Logging and Monitoring - Metadata Management Concept | 23 |
C5-OPS-12 | Logging and Monitoring - Access, Storage and Deletion | 26 |
C5-OPS-13 | Logging and Monitoring - Identification of Events | 34 |
C5-OPS-14 | Logging and Monitoring - Storage of the Logging Data | 27 |
C5-OPS-15 | Logging and Monitoring - Accountability | 26 |
C5-OPS-16 | Logging and Monitoring - Configuration | 24 |
C5-OPS-17 | Logging and Monitoring - Availability of the Monitoring Software | 15 |
C5-OPS-18 | Managing Vulnerabilities, Malfunctions and Errors - Concept | 31 |
C5-OPS-19 | Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests | 29 |
C5-OPS-20 | Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures | 31 |
C5-OPS-21 | Involvement of Cloud Customers in the Event of Incidents | 19 |
C5-OPS-22 | Testing and Documentation of known Vulnerabilities | 30 |
C5-OPS-23 | Managing Vulnerabilities, Malfunctions and Errors - System Hardening | 29 |
C5-OPS-24 | Separation of Datasets in the Cloud Infrastructure | 25 |
C5-PI-01 | Documentation and safety of input and output interfaces | 15 |
C5-PI-02 | Contractual agreements for the provision of data | 17 |
C5-PI-03 | Secure deletion of data | 30 |
C5-PS-01 | Physical Security and Environmental Control Requirements | 25 |
C5-PS-02 | Redundancy model | 18 |
C5-PS-03 | Perimeter Protection | 19 |
C5-PS-04 | Physical site access control | 22 |
C5-PS-05 | Protection from fire and smoke | 12 |
C5-PS-06 | Protection against interruptions caused by power failures and other such risks | 13 |
C5-PS-07 | Surveillance of operational and environmental parameters | 14 |
C5-PSS-01 | Guidelines and Recommendations for Cloud Customers | 14 |
C5-PSS-02 | Identification of Vulnerabilities of the Cloud Service | 21 |
C5-PSS-03 | Online Register of Known Vulnerabilities | 16 |
C5-PSS-04 | Error handling and Logging Mechanisms | 20 |
C5-PSS-05 | Authentication Mechanisms | 26 |
C5-PSS-06 | Session Management | 18 |
C5-PSS-07 | Confidentiality of Authentication Information | 26 |
C5-PSS-08 | Roles and Rights Concept | 23 |
C5-PSS-09 | Authorisation Mechanisms | 22 |
C5-PSS-10 | Software Defined Networking | 14 |
C5-PSS-11 | Images for Virtual Machines and Containers | 23 |
C5-PSS-12 | Locations of Data Processing and Storage | 20 |
C5-SIM-01 | Policy for security incident management | 32 |
C5-SIM-02 | Processing of security incidents | 32 |
C5-SIM-03 | Documentation and reporting of security incidents | 31 |
C5-SIM-04 | Duty of the users to report security incidents to a central body | 25 |
C5-SIM-05 | Evaluation and learning process | 25 |
C5-SP-01 | Documentation, communication and provision of policies and instructions | 30 |
C5-SP-02 | Review and Approval of Policies and Instructions | 25 |
C5-SP-03 | Exceptions from Existing Policies and Instructions | 20 |
C5-SSO-01 | Policies and instructions for controlling and monitoring third parties | 32 |
C5-SSO-02 | Risk assessment of service providers and suppliers | 32 |
C5-SSO-03 | Directory of service providers and suppliers | 25 |
C5-SSO-04 | Monitoring of compliance with requirements | 30 |
C5-SSO-05 | Exit strategy for the receipt of benefits | 16 |