5.1 | Policies for information security | 0 |
5.14 | Information transfer | 0 |
5.16 | Identity management | 0 |
5.2 | Information security roles and responsibilities | 0 |
5.26 | Response to information security incidents | 0 |
5.35 | Independent review of information security | 0 |
6.3 | Information security awareness, education and training | 0 |
7.14 | Secure disposal or re-use of equipment | 0 |
8.13 | Information backup | 0 |
8.15 | Logging | 0 |
8.24 | Use of cryptography | 0 |
8.31 | Separation of development, test and production environments | 0 |
8.5 | Secure authentication | 0 |
A.10 | Accountability | 0 |
A.10.1 | Notification of a data breach involving PII | 0 |
A.10.2 | Retention period for administrative security policies and guidelines | 0 |
A.10.3 | PII return, transfer and disposal | 0 |
A.11 | Information security | 0 |
A.11.1 | Confidentiality or non-disclosure agreements | 0 |
A.11.10 | Records of authorized users | 0 |
A.11.11 | Contract measures | 0 |
A.11.12 | Sub-contracted PII processing | 0 |
A.11.13 | Access to data on pre-used data storage space | 0 |
A.11.2 | Restriction of the creation of hardcopy material | 0 |
A.11.3 | Control and logging of data restoration | 0 |
A.11.4 | Protecting data on storage media leaving the premises | 0 |
A.11.5 | Use of unencrypted portable storage media and devices | 0 |
A.11.6 | Encryption of PII transmitted over public data-transmission networks | 0 |
A.11.7 | Secure disposal of hardcopy materials | 0 |
A.11.8 | Unique use of user IDs | 0 |
A.11.9 | User ID management | 0 |
A.12 | Privacy compliance | 0 |
A.12.1 | Geographical location of PII | 0 |
A.12.2 | Intended destination of PII | 0 |
A.2 | Consent and choice | 0 |
A.2.1 | Obligation to co-operate regarding PII principals' rights | 0 |
A.3 | Purpose legitimacy and specification | 0 |
A.3.1 | Public cloud PII processor's purpose | 0 |
A.3.2 | Public cloud PII processor's commercial use | 0 |
A.5 | Data minimization | 0 |
A.5.1 | Secure erasure of temporary files | 0 |
A.6 | Use, retention and disclosure limitation | 0 |
A.6.1 | PII disclosure notification | 0 |
A.6.2 | Recording of PII disclosures | 0 |
A.8 | Openness, transparency and notice | 0 |
A.8.1 | Disclosure of sub-contracted PII processing | 0 |