10.1 | Cryptographic controls | 3 |
10.1.1 | Policy on the use of cryptographic controls | 0 |
10.1.2 | Key management | 0 |
11.1 | Secure areas | 2 |
11.2 | Equipment | 2 |
11.2.7 | Secure disposal or re-use of equipment | 0 |
12.1 | Operational procedures and responsibilities | 5 |
12.1.2 | Change management | 0 |
12.1.3 | Capacity management | 0 |
12.2 | Protection from malware | 8 |
12.3 | Backup | 1 |
12.3.1 | Information backup | 0 |
12.4 | Logging and monitoring | 18 |
12.4.1 | Event logging | 0 |
12.4.3 | Administrator and operator logs | 0 |
12.4.4 | Clock synchronization | 0 |
12.5 | Control of operational software | 2 |
12.6 | Technical vulnerability management | 4 |
12.6.1 | Management of technical vulnerabilities | 0 |
12.7 | Information systems audit considerations | 2 |
13.1 | Network security management | 6 |
13.1.3 | Segregation in networks | 0 |
13.2 | Information transfer | 7 |
14.1 | Security requirements of information systems | 3 |
14.1.1 | Information security requirements analysis and specification | 0 |
14.2 | Security in development and support processes | 1 |
14.2.1 | Secure development policy | 0 |
14.3 | Test data | 1 |
15.1 | Information security in supplier relationships | 4 |
15.1.1 | Information security policy for supplier relationships | 0 |
15.1.2 | Addressing security within supplier agreements | 0 |
15.1.3 | Information and communication technology supply chain | 0 |
15.2 | Supplier service delivery management | 1 |
16.1 | Management of information security incidents and improvements | 2 |
16.1.1 | Responsibilities and procedures | 0 |
16.1.2 | Reporting information security events | 0 |
16.1.7 | Collection of evidence | 0 |
17.1 | Information security continuity | 4 |
17.2 | Redundancies | 0 |
18.1 | Compliance with legal and contractual requirements | 2 |
18.1.1 | Identification of applicable legislation and contractual requirements | 0 |
18.1.2 | Intellectual property rights | 0 |
18.1.3 | Protection of records | 0 |
18.1.5 | Regulation of cryptographic controls | 0 |
18.2 | Information security reviews | 7 |
18.2.1 | Independent review of information security | 0 |
2.1 | Identical Recommendations | International Standards | 0 |
2.2 | Additional References | 0 |
3.1 | Terms defined elsewhere | 0 |
4.2 | Supplier relationships in cloud services | 1 |
4.3 | Relationships between cloud service customers and cloud service providers | 0 |
4.4 | Managing information security risks in cloud services | 1 |
4.5 | Structure of this standard | 0 |
5.1 | Management direction for information security | 8 |
5.1.1 | Policies for information security | 0 |
6.1 | Internal organization | 3 |
6.1.1 | Information security roles and responsibilities | 0 |
6.1.3 | Contact with authorities | 0 |
6.2 | Mobile devices and teleworking | 2 |
7.1 | Prior to employment | 2 |
7.2 | During employment | 2 |
7.2.2 | Information security awareness, education and training | 0 |
7.3 | Termination and change of employment | 0 |
8.1 | Responsibility for assets | 2 |
8.1.1 | Inventory of assets | 0 |
8.1.2 | Ownership of assets | 0 |
8.2 | Information classification | 6 |
8.2.2 | Labelling of information | 0 |
8.3 | Media handling | 0 |
9.1 | Business requirements of access control | 2 |
9.2 | User access management | 5 |
9.2.1 | User registration and de-registration | 0 |
9.2.2 | User access provisioning | 0 |
9.2.3 | Management of privileged access rights | 0 |
9.2.4 | Management of secret authentication information of users | 0 |
9.3 | User responsibilities | 3 |
9.4 | System and application access control | 3 |
9.4.1 | Information access restriction | 0 |
9.4.4 | Use of privileged utility programs | 0 |
CLD.12.1.5 | Administrator's operational security | 0 |
CLD.12.4.5 | Monitoring of cloud services | 0 |
CLD.13.1.4 | Alignment of security management for virtual and physical networks | 0 |
CLD.6.3.1 | Shared roles and responsibilities within a cloud computing environment | 0 |
CLD.8.1.5 | Removal of cloud service customer assets | 0 |
CLD.9.5.1 | Segregation in virtual computing environments | 0 |
CLD.9.5.2 | Virtual machine hardening | 0 |