Control records
Page 2 of 10. 979 records.
Browse the catalog · First JSON page
control
MEA04 — Managed Assurance
control
E1 — Exercises Board Risk Oversight
control
E10 — Identifies Risk
control
E11 — Assesses Severity of Risk
control
E12 — Prioritizes Risks
control
E13 — Implements Risk Responses
control
E14 — Develops Portfolio View
control
E15 — Assesses Substantial Change
control
E16 — Reviews Risk and Performance
control
E17 — Pursues Improvement in Enterprise Risk Management
control
E18 — Leverages Information and Technology
control
E19 — Communicates Risk Information
control
E2 — Establishes Operating Structures
control
E20 — Reports on Risk, Culture, and Performance
control
E3 — Defines Desired Culture
control
E4 — Demonstrates Commitment to Core Values
control
E5 — Attracts, Develops, and Retains Capable Individuals
control
E6 — Analyzes Business Context
control
E7 — Defines Risk Appetite
control
E8 — Evaluates Alternative Strategies
control
E9 — Formulates Business Objectives
control
P1 — The organization demonstrates a commitment to integrity and ethical values.
control
P10 — The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
control
P11 — The organization selects and develops general control activities over technology to support the achievement of objectives.
control
P12 — The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.
control
P13 — The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.
control
P14 — The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
control
P15 — The organization communicates with external parties regarding matters affecting the functioning of internal control.
control
P16 — The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
control
P17 — The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.
control
P2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
control
P3 — Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
control
P4 — The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
control
P5 — The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
control
P6 — The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
control
P7 — The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
control
P8 — The organization considers the potential for fraud in assessing risks to the achievement of objectives.
control
P9 — The organization identifies and assesses changes that could significantly impact the system of internal control.
control
DORA-Art17-23 — ICT-related incident management, classification and reporting
control
DORA-Art24-27 — Digital operational resilience testing (incl. threat-led penetration testing)
control
DORA-Art28-44 — Managing of ICT third-party risk
control
DORA-Art45 — Information and intelligence sharing arrangements
control
DORA-Art5 — Governance and organisation (management body responsibility)
control
DORA-Ch2 — ICT risk management framework (Art 5-16)
control
AIA-Art10 — Data and data governance (high-risk)
control
AIA-Art11 — Technical documentation (high-risk)
control
AIA-Art12 — Record-keeping / logging (high-risk)
control
AIA-Art13 — Transparency and provision of information to deployers (high-risk)
control
AIA-Art14 — Human oversight (high-risk)
control
AIA-Art15 — Accuracy, robustness and cybersecurity (high-risk)
control
AIA-Art16 — Obligations of providers of high-risk AI systems
control
AIA-Art17 — Quality management system (providers of high-risk AI systems)
control
AIA-Art18 — Documentation keeping — 10-year retention of technical documentation, QMS records and conformity documents (providers)
control
AIA-Art19 — Automatically generated logs — provider retention of high-risk system logs (minimum six months)
control
AIA-Art20 — Corrective actions and duty of information for non-conforming high-risk AI systems
control
AIA-Art21-22 — Cooperation with competent authorities; authorised representatives of non-EU providers
control
AIA-Art23-25 — Obligations of importers and distributors; responsibilities along the AI value chain
control
AIA-Art26 — Obligations of deployers of high-risk AI systems
control
AIA-Art27 — Fundamental rights impact assessment for high-risk AI systems (deployers)
control
AIA-Art43 — Conformity assessment of high-risk AI systems
control
AIA-Art47-49 — EU declaration of conformity, CE marking and registration in the EU database
control
AIA-Art5 — Prohibited AI practices
control
AIA-Art50 — Transparency obligations for certain AI systems (deepfakes, chatbots, emotion recognition)
control
AIA-Art53 — Obligations for providers of general-purpose AI (GPAI) models
control
AIA-Art55 — Obligations for GPAI models with systemic risk
control
AIA-Art6-7 — Risk-based classification of high-risk AI systems
control
AIA-Art72 — Post-market monitoring by providers of high-risk AI systems
control
AIA-Art73 — Reporting of serious incidents (providers; deployers inform providers)
control
AIA-Art9 — Risk management system (high-risk)
control
GDPR-Art12-14 — Transparency and information to data subjects
control
GDPR-Art15-22 — Data subject rights (access, rectification, erasure, portability, objection, automated decisions)
control
GDPR-Art24 — Responsibility of the controller
control
GDPR-Art25 — Data protection by design and by default
control
GDPR-Art28 — Processor obligations and data processing agreements
control
GDPR-Art30 — Records of processing activities (RoPA)
control
GDPR-Art32 — Security of processing
control
GDPR-Art33 — Notification of a personal data breach to the supervisory authority
control
GDPR-Art34 — Communication of a breach to the data subject
control
GDPR-Art35 — Data protection impact assessment (DPIA)
control
GDPR-Art37-39 — Designation and tasks of the Data Protection Officer
control
GDPR-Art44-49 — International transfers of personal data
control
GDPR-Art5 — Principles relating to processing of personal data
control
GDPR-Art6 — Lawfulness of processing
control
GDPR-Art7 — Conditions for consent
control
GDPR-Art9 — Processing of special categories of data
control
HIPAA-164.308 — Administrative safeguards (security management, risk analysis, workforce security, training, contingency plan, evaluation, BAAs)
control
HIPAA-164.310 — Physical safeguards (facility access controls, workstation use/security, device and media controls)
control
HIPAA-164.312(a) — Technical access control for ePHI (unique user ID, emergency access, automatic logoff, encryption/decryption)
control
HIPAA-164.312(b) — Audit controls recording activity in systems with ePHI
control
HIPAA-164.312(c) — Integrity controls protecting ePHI from improper alteration or destruction
control
HIPAA-164.312(d) — Person or entity authentication before ePHI access
control
HIPAA-164.312(e) — Transmission security for ePHI (integrity controls and encryption in transit)
control
HIPAA-164.314 — Organizational requirements (business associate contracts, group health plan requirements)
control
HIPAA-164.316 — Policies and procedures and documentation requirements
control
HIPAA-164.400-414 — Breach notification to individuals, media, and HHS (incl. business-associate duties)
control
HIPAA-164.502 — Uses and disclosures of PHI (permitted/required uses, minimum necessary)
control
HIPAA-164.508 — Authorizations required for other uses and disclosures of PHI
control
HIPAA-164.514 — De-identification of PHI and limited data sets
control
HIPAA-164.520 — Notice of privacy practices for PHI
control
HIPAA-164.524 — Individual right of access to PHI