Germany

C5 (Germany)

121 controls. 48 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

121 controls 48 frameworks share controls with it Germany verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
C5-AM-01Asset Inventory31
C5-AM-02Acceptable Use and Safe Handling of Assets Policy30
C5-AM-03Commissioning of Hardware23
C5-AM-04Decommissioning of Hardware24
C5-AM-05Commitment to Permissible Use, Safe Handling and Return of Assets22
C5-AM-06Asset Classification and Labelling27
C5-BCM-01Top management responsibility20
C5-BCM-02Business impact analysis policies and instructions22
C5-BCM-03Planning business continuity26
C5-BCM-04Verification, updating and testing of the business continuity27
C5-COM-01Identification of applicable legal, regulatory, self-imposed or contractual requirements26
C5-COM-02Policy for planning and conducting audits26
C5-COM-03Internal audits of the information security management system31
C5-COM-04Information on information security performance and management assessment of the ISMS29
C5-COS-01Technical safeguards23
C5-COS-02Security requirements for connections in the Cloud Service Provider's network24
C5-COS-03Monitoring of connections in the Cloud Service Provider's network25
C5-COS-04Cross-network access25
C5-COS-05Networks for administration23
C5-COS-06Segregation of data traffic in jointly used network environments23
C5-COS-07Documentation of the network topology23
C5-COS-08Policies for data transmission26
C5-CRY-01Policy for the use of encryption procedures and key management23
C5-CRY-02Encryption of data for transmission (transport encryption)27
C5-CRY-03Encryption of sensitive data for storage27
C5-CRY-04Secure key management20
C5-DEV-01Policies for the development/procurement of information systems22
C5-DEV-02Outsourcing of the development20
C5-DEV-03Policies for changes to information systems23
C5-DEV-04Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools24
C5-DEV-05Risk assessment, categorisation and prioritisation of changes19
C5-DEV-06Testing changes19
C5-DEV-07Logging of changes21
C5-DEV-08Version Control14
C5-DEV-09Approvals for provision in the production environment20
C5-DEV-10Separation of environments22
C5-HR-01Verification of qualification and trustworthiness26
C5-HR-02Employment terms and conditions24
C5-HR-03Security training and awareness programme33
C5-HR-04Disciplinary measures18
C5-HR-05Responsibilities in the event of termination or change of employment24
C5-HR-06Confidentiality agreements19
C5-IDM-01Policy for user accounts and access rights29
C5-IDM-02Granting and change of user accounts and access rights27
C5-IDM-03Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins25
C5-IDM-04Withdraw or adjust access rights as the task area changes25
C5-IDM-05Regular review of access rights26
C5-IDM-06Privileged access rights29
C5-IDM-07Access to cloud customer data23
C5-IDM-08Confidentiality of authentication information28
C5-IDM-09Authentication mechanisms32
C5-INQ-01Legal Assessment of Investigative Inquiries11
C5-INQ-02Informing Cloud Customers about Investigation Requests5
C5-INQ-03Conditions for Access to or Disclosure of Data in Investigation Requests8
C5-INQ-04Limiting Access to or Disclosure of Data in Investigation Requests4
C5-OIS-01Information Security Management System (ISMS)27
C5-OIS-02Information Security Policy27
C5-OIS-03Interfaces and Dependencies23
C5-OIS-04Segregation of Duties25
C5-OIS-05Contact with Relevant Government Agencies and Interest Groups19
C5-OIS-06Risk Management Policy34
C5-OIS-07Application of the Risk Management Policy34
C5-OPS-01Capacity Management - Planning11
C5-OPS-02Capacity Management - Monitoring8
C5-OPS-03Capacity Management - Controlling of Resources14
C5-OPS-04Protection Against Malware - Concept24
C5-OPS-05Protection Against Malware - Implementation28
C5-OPS-06Data Backup and Recovery - Concept24
C5-OPS-07Data Backup and Recovery - Monitoring20
C5-OPS-08Data Backup and Recovery - Regular Testing24
C5-OPS-09Data Backup and Recovery - Storage25
C5-OPS-10Logging and Monitoring - Concept30
C5-OPS-11Logging and Monitoring - Metadata Management Concept23
C5-OPS-12Logging and Monitoring - Access, Storage and Deletion26
C5-OPS-13Logging and Monitoring - Identification of Events34
C5-OPS-14Logging and Monitoring - Storage of the Logging Data27
C5-OPS-15Logging and Monitoring - Accountability26
C5-OPS-16Logging and Monitoring - Configuration24
C5-OPS-17Logging and Monitoring - Availability of the Monitoring Software15
C5-OPS-18Managing Vulnerabilities, Malfunctions and Errors - Concept31
C5-OPS-19Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests29
C5-OPS-20Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures31
C5-OPS-21Involvement of Cloud Customers in the Event of Incidents19
C5-OPS-22Testing and Documentation of known Vulnerabilities30
C5-OPS-23Managing Vulnerabilities, Malfunctions and Errors - System Hardening29
C5-OPS-24Separation of Datasets in the Cloud Infrastructure25
C5-PI-01Documentation and safety of input and output interfaces15
C5-PI-02Contractual agreements for the provision of data17
C5-PI-03Secure deletion of data30
C5-PS-01Physical Security and Environmental Control Requirements25
C5-PS-02Redundancy model18
C5-PS-03Perimeter Protection19
C5-PS-04Physical site access control22
C5-PS-05Protection from fire and smoke12
C5-PS-06Protection against interruptions caused by power failures and other such risks13
C5-PS-07Surveillance of operational and environmental parameters14
C5-PSS-01Guidelines and Recommendations for Cloud Customers14
C5-PSS-02Identification of Vulnerabilities of the Cloud Service21
C5-PSS-03Online Register of Known Vulnerabilities16
C5-PSS-04Error handling and Logging Mechanisms20
C5-PSS-05Authentication Mechanisms26
C5-PSS-06Session Management18
C5-PSS-07Confidentiality of Authentication Information26
C5-PSS-08Roles and Rights Concept23
C5-PSS-09Authorisation Mechanisms22
C5-PSS-10Software Defined Networking14
C5-PSS-11Images for Virtual Machines and Containers23
C5-PSS-12Locations of Data Processing and Storage20
C5-SIM-01Policy for security incident management32
C5-SIM-02Processing of security incidents32
C5-SIM-03Documentation and reporting of security incidents31
C5-SIM-04Duty of the users to report security incidents to a central body25
C5-SIM-05Evaluation and learning process25
C5-SP-01Documentation, communication and provision of policies and instructions30
C5-SP-02Review and Approval of Policies and Instructions25
C5-SP-03Exceptions from Existing Policies and Instructions20
C5-SSO-01Policies and instructions for controlling and monitoring third parties32
C5-SSO-02Risk assessment of service providers and suppliers32
C5-SSO-03Directory of service providers and suppliers25
C5-SSO-04Monitoring of compliance with requirements30
C5-SSO-05Exit strategy for the receipt of benefits16

Tell me when C5 (Germany) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Control testing plan
  • Test results
  • Effectiveness metrics
  • Remediation plan
  • internal audit plan and schedule
  • internal audit reports of the ISMS
  • secure development / CI-CD security awareness programme
  • training records for development and operations staff
  • Awareness programme content
  • Completion metrics

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for C5 (Germany), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition