Authentic statutory obligations decomposed into atomic machine-actionable conditions, actions, and verification standards.
Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and interested parties.
Statutory verification and compliance logging required.
{
"annual_executive_review": true,
"all_staff_acknowledgement": true
}Secure coding principles shall be applied to software development to maintain information security throughout the software development life cycle.
Statutory verification and compliance logging required.
{
"peer_review_mandatory": true,
"sast_dast_in_pipeline": true
}Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.
Statutory verification and compliance logging required.
{
"kms_key_rotation_annual": true,
"strong_ciphers_mandated": true
}Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.
Statutory verification and compliance logging required.
{
"exit_strategy_defined": true,
"cloud_governance_framework": true
}Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
Statutory verification and compliance logging required.
{
"rbac_matrix": true,
"privilege_segregation": true
}Information about technical vulnerabilities of information systems being used shall be obtained, the organization's exposure evaluated and appropriate measures taken.
Statutory verification and compliance logging required.
{
"critical_sla_14_days": true,
"weekly_vulnerability_scans": true
}