All records
Page 4 of 17. 1677 records.
Browse the catalog · First JSON page
control
A.5.31 — Legal, statutory, regulatory and contractual requirements
control
A.5.32 — Intellectual property rights
control
A.5.33 — Protection of records
control
A.5.34 — Privacy and protection of personal identifiable information (PII)
control
A.5.35 — Independent review of information security
control
A.5.36 — Compliance with policies, rules and standards for information security
control
A.5.37 — Documented operating procedures
control
A.5.4 — Management responsibilities
control
A.5.5 — Contact with authorities
control
A.5.6 — Contact with special interest groups
control
A.5.7 — Threat intelligence
control
A.5.8 — Information security in project management
control
A.5.9 — Inventory of information and other associated assets
control
A.6.1 — Screening
control
A.6.2 — Terms and conditions of employment
control
A.6.3 — Information security awareness, education and training
control
A.6.4 — Disciplinary process
control
A.6.5 — Responsibilities after termination or change of employment
control
A.6.6 — Confidentiality or non-disclosure agreements
control
A.6.7 — Remote working
control
A.6.8 — Information security event reporting
control
A.7.1 — Physical security perimeters
control
A.7.10 — Storage media
control
A.7.11 — Supporting utilities
control
A.7.12 — Cabling security
control
A.7.13 — Equipment maintenance
control
A.7.14 — Secure disposal or re-use of equipment
control
A.7.2 — Physical entry
control
A.7.3 — Securing offices, rooms and facilities
control
A.7.4 — Physical security monitoring
control
A.7.5 — Protecting against physical and environmental threats
control
A.7.6 — Working in secure areas
control
A.7.7 — Clear desk and clear screen
control
A.7.8 — Equipment siting and protection
control
A.7.9 — Security of assets off-premises
control
A.8.1 — User endpoint devices
control
A.8.10 — Information deletion
control
A.8.11 — Data masking
control
A.8.12 — Data leakage prevention
control
A.8.13 — Information backup
control
A.8.14 — Redundancy of information processing facilities
control
A.8.15 — Logging
control
A.8.16 — Monitoring activities
control
A.8.17 — Clock synchronization
control
A.8.18 — Use of privileged utility programs
control
A.8.19 — Installation of software on operational systems
control
A.8.2 — Privileged access rights
control
A.8.20 — Networks security
control
A.8.21 — Security of network services
control
A.8.22 — Segregation of networks
control
A.8.23 — Web filtering
control
A.8.24 — Use of cryptography
control
A.8.25 — Secure development life cycle
control
A.8.26 — Application security requirements
control
A.8.27 — Secure system architecture and engineering principles
control
A.8.28 — Secure coding
control
A.8.29 — Security testing in development and acceptance
control
A.8.3 — Information access restriction
control
A.8.30 — Outsourced development
control
A.8.31 — Separation of development, test and production environments
control
A.8.32 — Change management
control
A.8.33 — Test information
control
A.8.34 — Protection of information systems during audit testing
control
A.8.4 — Access to source code
control
A.8.5 — Secure authentication
control
A.8.6 — Capacity management
control
A.8.7 — Protection against malware
control
A.8.8 — Management of technical vulnerabilities
control
A.8.9 — Configuration management
control
31000-FW1 — Leadership and commitment
control
31000-FW2 — Integration
control
31000-FW3 — Design
control
31000-FW4 — Implementation
control
31000-FW5 — Evaluation
control
31000-FW6 — Improvement
control
31000-P1 — Integrated
control
31000-P2 — Structured and comprehensive
control
31000-P3 — Customized
control
31000-P4 — Inclusive
control
31000-P5 — Dynamic
control
31000-P6 — Best available information
control
31000-P7 — Human and cultural factors
control
31000-P8 — Continual improvement
control
31000-PR1 — Communication and consultation
control
31000-PR2 — Scope, context and criteria
control
31000-PR3 — Risk assessment: risk identification
control
31000-PR4 — Risk assessment: risk analysis
control
31000-PR5 — Risk assessment: risk evaluation
control
31000-PR6 — Risk treatment
control
31000-PR7 — Monitoring and review
control
31000-PR8 — Recording and reporting
control
A.10.2 — Allocating responsibilities
control
A.10.3 — Suppliers
control
A.10.4 — Customers
control
A.2.2 — AI policy
control
A.2.3 — Alignment with other organizational policies
control
A.2.4 — Review of the AI policy
control
A.3.2 — AI roles and responsibilities
control
A.3.3 — Reporting of concerns
control
A.4.2 — Resource documentation