A.1.1 | Consent and choice | 0 |
A.1.1 | Consent and choice | 0 |
A.10.1 | Information security | 6 |
A.10.1 | Information security | 6 |
A.10.10 | User ID management | 0 |
A.10.11 | Contract measures | 0 |
A.10.12 | Sub-contracted PII processing | 0 |
A.10.13 | Access to data on pre-used data-storage space | 0 |
A.10.2 | Confidentiality obligations of personnel | 13 |
A.10.2 | Confidentiality obligations of personnel | 13 |
A.10.3 | Restriction of creation of hardcopy material | 4 |
A.10.3 | Restriction of creation of hardcopy material | 4 |
A.10.4 | Control and logging of data restoration | 6 |
A.10.4 | Control and logging of data restoration | 6 |
A.10.5 | Protection of data on storage media leaving premises | 0 |
A.10.5 | Protection of data on storage media leaving premises | 0 |
A.10.6 | PII transmission | 1 |
A.10.6 | PII transmission | 1 |
A.10.7 | Disclosure of PII | 0 |
A.10.7 | Disclosure of PII | 0 |
A.10.8 | Unique use of user IDs | 0 |
A.10.9 | Records of authorized users | 0 |
A.11.1 | Geographical location of PII | 0 |
A.11.1 | Geographical location of PII | 0 |
A.11.2 | Intended destination of PII | 0 |
A.11.2 | Intended destination of PII | 0 |
A.11.3 | Disposal of PII | 0 |
A.11.4 | Temporary files | 1 |
A.11.5 | PII transmission | 1 |
A.12.1 | Notification of a data breach | 0 |
A.12.1 | Notification of a data breach | 0 |
A.12.2 | Return, transfer and disposal of PII | 1 |
A.12.2 | Return, transfer and disposal of PII | 1 |
A.12.3 | Periodic audits and reviews | 0 |
A.2.1 | Purpose legitimacy and specification | 0 |
A.2.1 | Purpose legitimacy and specification | 0 |
A.3.1 | Collection limitation | 0 |
A.3.1 | Collection limitation | 0 |
A.4.1 | Data minimization | 0 |
A.4.1 | Data minimization | 0 |
A.5.1 | Use, retention and disclosure limitation | 0 |
A.5.1 | Use, retention and disclosure limitation | 0 |
A.6.1 | Accuracy and quality | 1 |
A.6.1 | Accuracy and quality | 1 |
A.7.1 | Openness, transparency and notice | 0 |
A.7.1 | Openness, transparency and notice | 0 |
A.8.1 | Individual participation and access | 0 |
A.8.1 | Individual participation and access | 0 |
A.9.1 | Accountability | 0 |
A.9.1 | Accountability | 0 |
ISO27018-01 | Shared responsibility model definition | 135 |
ISO27018-02 | Cloud security policy and strategy | 14 |
ISO27018-03 | Cloud risk assessment | 123 |
ISO27018-04 | Regulatory compliance for cloud services | 58 |
ISO27018-05 | Cloud security roles and responsibilities | 14 |
ISO27018-06 | Cloud identity management | 34 |
ISO27018-07 | Multi-factor authentication for cloud | 69 |
ISO27018-08 | Privileged access in cloud environments | 64 |
ISO27018-09 | Federation and single sign-on | 0 |
ISO27018-10 | API security and access tokens | 0 |
ISO27018-11 | Data classification for cloud | 120 |
ISO27018-12 | Encryption of cloud-stored data | 112 |
ISO27018-13 | Data residency and sovereignty | 0 |
ISO27018-14 | Data backup and recovery in cloud | 142 |
ISO27018-15 | Secure data deletion in cloud | 89 |
ISO27018-16 | Virtual network segmentation | 55 |
ISO27018-17 | Container and serverless security | 0 |
ISO27018-18 | Cloud workload protection | 0 |
ISO27018-19 | Image and template hardening | 43 |
ISO27018-20 | Cloud configuration management | 43 |
ISO27018-21 | Cloud security monitoring and logging | 79 |
ISO27018-22 | Incident response in cloud | 109 |
ISO27018-23 | Cloud vulnerability management | 53 |
ISO27018-24 | Cloud change management | 34 |
ISO27018-25 | Service level agreement management | 0 |