4.1 | Relation between this document and ISO/IEC 27002:2022 | 0 |
4.2 | Structure of this document | 0 |
4.3.1 | Supplier relationships in cloud services | 0 |
4.3.2 | Relationships between CSCs and CSPs | 0 |
4.3.3 | Managing information security risks in cloud services | 0 |
5.1 | Policies for information security | 0 |
5.11 | Return of assets | 0 |
5.13 | Labelling of information | 0 |
5.16 | Identity management | 0 |
5.17 | Authentication information | 0 |
5.18 | Access rights | 0 |
5.19 | Information security in supplier relationships | 0 |
5.2 | Information security roles and responsibilities | 0 |
5.20 | Addressing information security within supplier agreements | 0 |
5.21 | Managing information security in the ICT supply chain | 0 |
5.23 | Information security for use of cloud services | 0 |
5.24 | Information security incident management planning and preparation | 0 |
5.28 | Collection of evidence | 0 |
5.31 | Legal, statutory, regulatory and contractual requirements | 0 |
5.32 | Intellectual property rights | 0 |
5.33 | Protection of records | 0 |
5.35 | Independent review of information security | 0 |
5.37 | Documented operating procedures | 0 |
5.38 | CLD - Shared roles and responsibilities within a cloud computing environment | 0 |
5.39 | CLD - Agreement on the roles and responsibilities of the cloud service partner | 0 |
5.9 | Inventory of information and other associated assets | 0 |
6.3 | Information security awareness, education and training | 0 |
6.8 | Information security event reporting | 0 |
7.14 | Secure disposal or re-use of equipment | 0 |
8.13 | Information backup | 0 |
8.15 | Logging | 0 |
8.16 | Monitoring activities | 0 |
8.17 | Clock synchronization | 0 |
8.18 | Use of privileged utility programs | 0 |
8.2 | Privileged access rights | 0 |
8.20 | Networks security | 0 |
8.22 | Segregation of networks | 0 |
8.24 | Use of cryptography | 0 |
8.25 | Secure development life cycle | 0 |
8.26 | Application security requirements | 0 |
8.3 | Information access restriction | 0 |
8.32 | Change management | 0 |
8.35 | CLD - Segregation in virtual computing environments | 0 |
8.36 | CLD - Detection and prevention of unauthorized use of cloud services | 0 |
8.6 | Capacity management | 0 |
8.8 | Management of technical vulnerabilities | 0 |
8.9 | Configuration management | 0 |