10.1 | Cryptographic controls | 3 |
10.1.1 | Policy on the use of cryptographic controls | 1 |
10.1.2 | Key management | 3 |
11.1 | Secure areas | 2 |
11.2 | Equipment | 1 |
11.2.1 | Equipment siting and protection | 6 |
11.2.2 | Supporting utilities | 1 |
11.2.3 | Cabling security | 2 |
11.2.4 | Equipment maintenance | 6 |
11.2.5 | Removal of assets | 0 |
11.2.6 | Security of equipment and assets off-premises | 1 |
11.2.7 | Secure disposal or re-use of equipment | 4 |
11.2.8 | Unattended user equipment | 0 |
11.2.9 | Clear desk and clear screen policy | 1 |
12.1 | Operational procedures and responsibilities | 5 |
12.1.1 | Documented operating procedures | 2 |
12.1.2 | Change management | 18 |
12.1.3 | Capacity management | 3 |
12.1.4 | Separation of development, testing and operational environments | 0 |
12.2 | Protection from malware | 8 |
12.3 | Backup | 1 |
12.3.1 | Information backup | 2 |
12.4 | Logging and monitoring | 18 |
12.4.1 | Event logging | 11 |
12.4.2 | Protection of log information | 1 |
12.4.3 | Administrator and operator logs | 0 |
12.4.4 | Clock synchronization | 2 |
12.5 | Control of operational software | 2 |
12.6 | Technical vulnerability management | 4 |
12.7 | Information systems audit considerations ISO/IEC 27018:2019 | 2 |
13.1 | Network security management | 6 |
13.2 | Information transfer | 7 |
13.2.1 | Information transfer policies and procedures | 6 |
13.2.2 | Agreements on information transfer | 0 |
13.2.3 | Electronic messaging | 0 |
13.2.4 | Confidentiality or non-disclosure agreements | 10 |
16.1 | Management of information security incidents and improvements | 2 |
16.1.1 | Responsibilities and procedures | 1 |
16.1.2 | Reporting information security events | 5 |
16.1.3 | Reporting information security weaknesses | 1 |
16.1.4 | Assessment of and decision on information security events | 1 |
16.1.5 | Response to information security incidents | 1 |
16.1.6 | Learning from information security incidents | 1 |
16.1.7 | Collection of evidence | 3 |
18.1 | Compliance with legal and contractual requirements | 2 |
18.2 | Information security reviews | 7 |
18.2.1 | Independent review of information security | 4 |
18.2.2 | Compliance with security policies and standards | 0 |
18.2.3 | Technical compliance review | 0 |
4.1 | Structure of this document | 2 |
4.2 | Control categories | 0 |
5.1 | Management direction for information security | 8 |
5.1.1 | Policies for information security | 4 |
5.1.2 | Review of the policies for information security | 3 |
6.1 | Internal organization | 3 |
6.1.1 | Information security roles and responsibilities | 6 |
6.1.2 | Segregation of duties | 6 |
6.1.3 | Contact with authorities | 6 |
6.1.4 | Contact with special interest groups | 4 |
7.1 | Prior to employment | 2 |
7.2.1 | Management responsibilities | 3 |
7.2.2 | Information security awareness, education and training | 0 |
7.2.3 | Disciplinary process | 2 |
7.3 | Termination and change of employment | 1 |
9.1 | Business requirements of access control | 2 |
9.2 | User access management | 5 |
9.2.1 | User registration and de-registration | 0 |
9.2.2 | User access provisioning | 4 |
9.2.3 | Management of privileged access rights | 7 |
9.2.4 | Management of secret authentication information of users | 0 |
9.2.5 | Review of user access rights | 2 |
9.2.6 | Removal or adjustment of access rights | 0 |
9.3 | User responsibilities | 3 |
9.3.1 | Use of secret authentication information | 1 |
9.4 | System and application access control | 3 |
9.4.1 | Information access restriction | 1 |
9.4.2 | Secure log-on procedures | 0 |
9.4.3 | Password management system | 1 |
9.4.4 | Use of privileged utility programs | 3 |
9.4.5 | Access control to program source code | 7 |
A.10 | Accountability | 0 |
A.10.1 | Notification of a data breach involving PII | 0 |
A.10.2 | Retention period for administrative security policies and guidelines | 0 |
A.10.3 | PII return, transfer and disposal | 0 |
A.11 | Information security | 0 |
A.11.1 | Confidentiality or non-disclosure agreements | 0 |
A.11.10 | User ID management | 0 |
A.11.11 | Contract measures | 0 |
A.11.12 | Sub-contracted PII processing | 0 |
A.11.13 | Access to data on pre-used data storage space | 0 |
A.11.2 | Restriction of the creation of hardcopy material | 0 |
A.11.3 | Control and logging of data restoration | 0 |
A.11.4 | Protecting data on storage media leaving the premises | 0 |
A.11.5 | Use of unencrypted portable storage media and devices | 0 |
A.11.6 | Encryption of PII transmitted over public data-transmission networks | 0 |
A.11.7 | Secure disposal of hardcopy materials | 0 |
A.11.8 | Unique use of user IDs | 0 |
A.11.9 | Records of authorized users | 0 |
A.12 | Privacy compliance | 0 |
A.12.1 | Geographical location of PII | 0 |
A.12.2 | Intended destination of PII | 0 |
A.2 | Consent and choice | 0 |
A.2.1 | Obligation to co-operate regarding PII principals' rights | 0 |
A.3 | Purpose legitimacy and specification | 0 |
A.3.1 | Public cloud PII processor's purpose | 0 |
A.3.2 | Public cloud PII processor's commercial use | 0 |
A.5 | Data minimization | 0 |
A.5.1 | Secure erasure of temporary files | 0 |
A.6 | Use, retention and disclosure limitation | 0 |
A.6.1 | PII disclosure notification | 0 |
A.6.2 | Recording of PII disclosures | 0 |
A.8 | Openness, transparency and notice | 0 |
A.8.1 | Disclosure of sub-contracted PII processing | 0 |