1,174 words, 44 clausesno date on the pageread 25/08/2026source
·Updated 22 minutes ago
| Control | Status |
|---|---|
| Information transferInformation transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties. | |
| Privileged access rightsThe allocation and use of privileged access rights shall be restricted and managed. | |
| Secure authenticationSecure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control. | |
| Web filteringAccess to external websites shall be managed to reduce exposure to malicious content. | |
| Clock synchronizationThe clocks of information processing systems used by the organization shall be synchronized to approved time sources. | |
| Application security requirementsInformation security requirements shall be identified, specified and approved when developing or acquiring applications. | |
| Secure system architecture and engineering principlesPrinciples for engineering secure systems shall be established, documented, maintained and applied to any information system development activities. |
| Control | Status |
|---|---|
| Determining the scope of the information security management systemThe organization shall determine the boundaries and applicability of the information security management system to establish its scope. When determining this scope, the organization shall consider: a) the external and internal issues referred to in 4.1; b) the requirements referred to in 4.2; c) interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations. The scope shall be available as documented information. | |
| ScreeningBackground verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis taking into consideration applicable laws, regulations and ethics and be proportional to the business requirements, the classification of the information to be accessed and the perceived risks. | |
| Responsibilities after termination or change of employmentInformation security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced and communicated to relevant personnel and other interested parties. | |
| Operation planning and controlThe organization shall plan, implement and control the processes needed to meet requirements, and to implement the actions determined in Clause 6, by: - establishing criteria for the processes; - implementing control of the processes in accordance with the criteria. Documented information shall be available to the extent necessary to have confidence that the processes have been carried out as planned. The organization shall control planned changes and review the consequences of unintended changes, taking action to mitigate any adverse effects, as necessary. The organization shall ensure that externally provided processes, products or services that are relevant to the information security management system are controlled. | |
| Physical security perimetersSecurity perimeters shall be defined and used to protect areas that contain information and other associated assets. | |
| Securing offices, rooms and facilitiesPhysical security for offices, rooms and facilities shall be designed and implemented. | |
| Protecting against physical and environmental threatsProtection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented. | |
| Working in secure areasSecurity measures for working in secure areas shall be designed and implemented. | |
| Information security awareness, education and trainingPersonnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organization's information security policy, topic-specific policies and procedures, as relevant for their job function. |
| Control | Status |
|---|---|
| Secure development life cycleRules for the secure development of software and systems shall be established and applied. | |
| Secure codingSecure coding principles shall be applied to software development. |
| Control | Status |
|---|---|
| ICT readiness for business continuityICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements. | |
| Internal Audit - GeneralThe organization shall conduct internal audits at planned intervals to provide information on whether the information security management system: a) conforms to the organization's own requirements for its information security management system; the requirements of this document; b) is effectively implemented and maintained. | |
| Internal Audit ProgramThe organization shall plan, establish, implement and maintain an audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting. When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits. The organization shall: a) define the audit criteria and scope for each audit; b) select auditors and conduct audits that ensure objectivity and the impartiality of the audit process; c) ensure that the results of the audits are reported to relevant management; Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results. | |
| Legal, statutory, regulatory and contractual requirementsLegal, statutory, regulatory and contractual requirements relevant to information security and the organization's approach to meet these requirements shall be identified, documented and kept up to date. | |
| Independent review of information securityThe organization's approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur. | |
| Protection of information systems during audit testingAudit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management. | |
| Understanding the organization and its contextThe organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system. | |
| Understanding the needs of interested partiesThe organization shall determine: a) interested parties that are relevant to the information security management system; b) the relevant requirements of these interested parties; c) which of these requirements will be addressed through the information security management system. | |
| Information security management systemThe organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of ISO . | |
| Information security objective and planning to achieve themThe organization shall establish information security objectives at relevant functions and levels. The information security objectives shall: a) be consistent with the information security policy; b) be measurable (if practicable); c) take into account applicable information security requirements, and results from risk assessment and risk treatment; d) be monitored; e) be communicated; f) be updated as appropriate; g) be available as documented information. The organization shall retain documented information on the information security objectives. When planning how to achieve its information security objectives, the organization shall determine: h) what will be done; i) what resources will be required; j) who will be responsible; k) when it will be completed; and l) how the results will be evaluated. |
| Control | Status |
|---|---|
| Classification of informationInformation shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements. | |
| Labelling of informationAn appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organization. | |
| Protection of recordsRecords shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release. | |
| Data maskingData masking shall be used in accordance with the organization's topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration. Top |