Control Objectives: Uncategorized
No control objectives match the current filters.
1 Inventory and Control of Enterprise Assets
SNow
State: Published
Actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/Internet of Things (IoT) devices; and servers) connected to the infrastructure physically, virtually, remotely, and those within cloud environments,
10 Malware Defenses
SNow
State: Published
Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.
Children (7)
- 10.1 Deploy and Maintain Anti-Malware Software
- 10.2 Configure Automatic Anti-Malware Signature Updates
- 10.3 Disable Autorun and Autoplay for Removable Media
- 10.4 Configure Automatic Anti-Malware Scanning of Removable ...
- 10.5 Enable Anti-Exploitation Features
- 10.6 Centrally Manage Anti-Malware Software
- 10.7 Use Behavior-Based Anti-Malware Software
11 Data Recovery
SNow
State: Published
Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state.
12 Network Infrastructure Management
SNow
State: Published
Establish, implement, and actively manage (track, report, correct) network devices, in order to prevent attackers from exploiting vulnerable network services and access points.
Children (8)
- 12.1 Ensure Network Infrastructure is Up-to-Date
- 12.2 Establish and Maintain a Secure Network Architecture
- 12.3 Securely Manage Network Infrastructure
- 12.4 Establish and Maintain Architecture Diagram(s)
- 12.5 Centralize Network Authentication, Authorization, and A...
- 12.6 Use of Secure Network Management and Communication Prot...
- 12.7 Ensure Remote Devices Utilize a VPN and are Connecting ...
- 12.8 Establish and Maintain Dedicated Computing Resources fo...
13 Network Monitoring and Defense
SNow
State: Published
Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprises network infrastructure and user base.
Children (11)
- 13.1 Centralize Security Event Alerting
- 13.10 Perform Application Layer Filtering
- 13.11 Tune Security Event Alerting Thresholds
- 13.2 Deploy a Host-Based Intrusion Detection Solution
- 13.3 Deploy a Network Intrusion Detection Solution
- 13.4 Perform Traffic Filtering Between Network Segments
- 13.5 Manage Access Control for Remote Assets
- 13.6 Collect Network Traffic Flow Logs
- 13.7 Deploy a Host-Based Intrusion Prevention Solution
- 13.8 Deploy a Network Intrusion Prevention Solution
- 13.9 Deploy Port-Level Access Control
14 Security Awareness and Skills Training
SNow
State: Published
Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.
Children (9)
- 14.1 Establish and Maintain a Security Awareness Program
- 14.2 Train Workforce Members to Recognize Social Engineering...
- 14.3 Train Workforce Members on Authentication Best Practice...
- 14.4 Train Workforce on Data Handling Best Practices
- 14.5 Train Workforce Members on Causes of Unintentional Data...
- 14.6 Train Workforce Members on Recognizing and Reporting Se...
- 14.7 Train Workforce on How to Identify and Report if Their ...
- 14.8 Train Workforce on the Dangers of Connecting to and Tra...
- 14.9 Conduct Role-Specific Security Awareness and Skills Tra...
14.1 Establish and Maintain a Security Awareness Program
SNow
Classification: ProtectState: Published
Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprises workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, o
14.2 Train Workforce Members to Recognize Social Engineering Attacks
SNow
Classification: ProtectState: Published
Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.
14.3 Train Workforce Members on Authentication Best Practices
SNow
Classification: ProtectState: Published
Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management.
14.4 Train Workforce on Data Handling Best Practices
SNow
Classification: ProtectState: Published
Train workforce members on how to identify and properly store, transfer, archive, and destroy sensitive data. This also includes training workforce members on clear screen and desk best practices, such as locking their screen when they step away from their enterprise asset, erasing physical and virt
14.5 Train Workforce Members on Causes of Unintentional Data Exposure
SNow
Classification: ProtectState: Published
Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, or publishing data to unintended audiences.
14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
SNow
Classification: ProtectState: Published
Train workforce members to be able to recognize a potential incident and be able to report such an incident.
14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
SNow
Classification: ProtectState: Published
Train workforce to understand how to verify and report out-of-date software patches or any failures in automated processes and tools. Part of this training should include notifying IT personnel of any failures in automated processes and tools.
14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
SNow
Classification: ProtectState: Published
Train workforce members on the dangers of connecting to, and transmitting data over, insecure networks for enterprise activities. If the enterprise has remote workers, training must include guidance to ensure that all users securely configure their home network infrastructure.
14.9 Conduct Role-Specific Security Awareness and Skills Training
SNow
Classification: ProtectState: Published
Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, (OWASP® Top 10 vulnerability awareness and prevention training for web application developers, and advanced social engineering awareness training f
15 Service Provider Management
SNow
State: Published
Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprises critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.
Children (7)
- 15.1 Establish and Maintain an Inventory of Service Provider...
- 15.2 Establish and Maintain a Service Provider Management Po...
- 15.3 Classify Service Providers
- 15.4 Ensure Service Provider Contracts Include Security Requ...
- 15.5 Assess Service Providers
- 15.6 Monitor Service Providers
- 15.7 Securely Decommission Service Providers
15.1 Establish and Maintain an Inventory of Service Providers
SNow
Classification: IdentifyState: Published
Establish and maintain an inventory of service providers. The inventory is to list all known service providers, include classification(s), and designate an enterprise contact for each service provider. Review and update the inventory annually, or when significant enterprise changes occur that could
15.2 Establish and Maintain a Service Provider Management Policy
SNow
Classification: IdentifyState: Published
Establish and maintain a service provider management policy. Ensure the policy addresses the classification, inventory, assessment, monitoring, and decommissioning of service providers. Review and update the policy annually, or when significant enterprise changes occur that could impact this Safegua
15.3 Classify Service Providers
SNow
Classification: IdentifyState: Published
Classify service providers. Classification consideration may include one or more characteristics, such as data sensitivity, data volume, availability requirements, applicable regulations, inherent risk, and mitigated risk. Update and review classifications annually, or when significant enterprise ch
15.4 Ensure Service Provider Contracts Include Security Requirements
SNow
Classification: ProtectState: Published
Ensure service provider contracts include security requirements. Example requirements may include minimum security program requirements, security incident and/or data breach notification and response, data encryption requirements, and data disposal commitments. These security requirements must be co
15.5 Assess Service Providers
SNow
Classification: IdentifyState: Published
Assess service providers consistent with the enterprises service provider management policy. Assessment scope may vary based on classification(s), and may include review of standardized assessment reports, such as Service Organization Control 2 (SOC 2) and Payment Card Industry (PCI) Attestation of
16 Application Software Security
SNow
State: Published
Manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise.
Children (14)
- 16.1 Establish and Maintain a Secure Application Development...
- 16.10 Apply Secure Design Principles in Application Architec...
- 16.11 Leverage Vetted Modules or Services for Application Se...
- 16.12 Implement Code-Level Security Checks
- 16.13 Conduct Application Penetration Testing
- 16.14 Conduct Threat Modeling
- 16.2 Establish and Maintain a Process to Accept and Address ...
- 16.3 Perform Root Cause Analysis on Security Vulnerabilities
- 16.4 Establish and Manage an Inventory of Third-Party Softwa...
- 16.5 Use Up-to-Date and Trusted Third-Party Software Compone...
- 16.6 Establish and Maintain a Severity Rating System and Pro...
- 16.7 Use Standard Hardening Configuration Templates for Appl...
- 16.8 Separate Production and Non-Production Systems
- 16.9 Train Developers in Application Security Concepts and S...
17 Incident Response Management
SNow
State: Published
Establish a program to develop and maintain an incident response capability (e.g., policies, plans, procedures, defined roles, training, and communications) to prepare, detect, and quickly respond to an attack.
Children (9)
- 17.1 Designate Personnel to Manage Incident Handling
- 17.2 Establish and Maintain Contact Information for Reportin...
- 17.3 Establish and Maintain an Enterprise Process for Report...
- 17.4 Establish and Maintain an Incident Response Process
- 17.5 Assign Key Roles and Responsibilities
- 17.6 Define Mechanisms for Communicating During Incident Res...
- 17.7 Conduct Routine Incident Response Exercises
- 17.8 Conduct Post-Incident Reviews
- 17.9 Establish and Maintain Security Incident Thresholds
17.1 Designate Personnel to Manage Incident Handling
SNow
Classification: RespondState: Published
Designate one key person, and at least one backup, who will manage the enterprises incident handling process. Management personnel are responsible for the coordination and documentation of incident response and recovery efforts and can consist of employees internal to the enterprise, third-party ve
17.2 Establish and Maintain Contact Information for Reporting Security Incidents
SNow
Classification: RespondState: Published
Establish and maintain contact information for parties that need to be informed of security incidents. Contacts may include internal staff, third-party vendors, law enforcement, cyber insurance providers, relevant government agencies, Information Sharing and Analysis Center (ISAC) partners, or other
17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
SNow
Classification: RespondState: Published
Establish and maintain an enterprise process for the workforce to report security incidents. The process includes reporting timeframe, personnel to report to, mechanism for reporting, and the minimum information to be reported. Ensure the process is publicly available to all of the workforce. Review
17.4 Establish and Maintain an Incident Response Process
SNow
Classification: RespondState: Published
Establish and maintain an incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.
17.5 Assign Key Roles and Responsibilities
SNow
Classification: RespondState: Published
Assign key roles and responsibilities for incident response, including staff from legal, IT, information security, facilities, public relations, human resources, incident responders, and analysts, as applicable. Review annually, or when significant enterprise changes occur that could impact this Saf
17.6 Define Mechanisms for Communicating During Incident Response
SNow
Classification: RespondState: Published
Determine which primary and secondary mechanisms will be used to communicate and report during a security incident. Mechanisms can include phone calls, emails, or letters. Keep in mind that certain mechanisms, such as emails, can be affected during a security incident. Review annually, or when signi
17.7 Conduct Routine Incident Response Exercises
SNow
Classification: RespondState: Published
Plan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a mi
17.8 Conduct Post-Incident Reviews
SNow
Classification: RespondState: Published
Conduct post-incident reviews. Post-incident reviews help prevent incident recurrence through identifying lessons learned and follow-up action.
17.9 Establish and Maintain Security Incident Thresholds
SNow
Classification: RespondState: Published
Establish and maintain security incident thresholds, including, at a minimum, differentiating between an incident and an event. Examples can include: abnormal activity, security vulnerability, security weakness, data breach, privacy incident, etc. Review annually, or when significant enterprise chan
18 Penetration Testing
SNow
State: Published
Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and technology), and simulating the objectives and actions of an attacker.
18.1 Establish and Maintain a Penetration Testing Program
SNow
Classification: IdentifyState: Published
Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise contro
Parent
18.5 Perform Periodic Internal Penetration Tests
SNow
Classification: IdentifyState: Published
Perform periodic internal penetration tests based on program requirements, no less than annually. The testing may be clear box or opaque box.
Parent
2 Inventory and Control of Software Assets
SNow
State: Published
Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
3 Data Protection
SNow
State: Published
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
Children (14)
- 3.1 Establish and Maintain a Data Management Process
- 3.10 Encrypt Sensitive Data in Transit
- 3.11 Encrypt Sensitive Data at Rest
- 3.12 Segment Data Processing and Storage Based on Sensitivit...
- 3.13 Deploy a Data Loss Prevention Solution
- 3.14 Log Sensitive Data Access
- 3.2 Establish and Maintain a Data Inventory
- 3.3 Configure Data Access Control Lists
- 3.4 Enforce Data Retention
- 3.5 Securely Dispose of Data
- 3.6 Encrypt Data on End-User Devices
- 3.7 Establish and Maintain a Data Classification Scheme
- 3.8 Document Data Flows
- 3.9 Encrypt Data on Removable Media
4 Secure Configuration of Enterprise Assets and Software
SNow
State: Published
Establish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).
5 Account Management
SNow
State: Published
Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.
6 Access Control Management
SNow
State: Published
Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.
Children (8)
- 6.1 Establish an Access Granting Process
- 6.2 Establish an Access Revoking Process
- 6.3 Require MFA for Externally-Exposed Applications
- 6.4 Require MFA for Remote Network Access
- 6.5 Require MFA for Administrative Access
- 6.6 Establish and Maintain an Inventory of Authentication an...
- 6.7 Centralize Access Control
- 6.8 Define and Maintain Role-Based Access Control
7 Continuous Vulnerability Management
SNow
State: Published
Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprises infrastructure, in order to remediate, and minimize, the window of opportunity for attackers. Monitor public and private industry sources for new threat and vulnerability information.
Children (7)
- 7.1 Establish and Maintain a Vulnerability Management Proces...
- 7.2 Establish and Maintain a Remediation Process
- 7.3 Perform Automated Operating System Patch Management
- 7.4 Perform Automated Application Patch Management
- 7.5 Perform Automated Vulnerability Scans of Internal Enterp...
- 7.6 Perform Automated Vulnerability Scans of Externally-Expo...
- 7.7 Remediate Detected Vulnerabilities
8 Audit Log Management
SNow
State: Published
Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.
Children (12)
- 8.1 Establish and Maintain an Audit Log Management Process
- 8.10 Retain Audit Logs
- 8.11 Conduct Audit Log Reviews
- 8.12 Collect Service Provider Logs
- 8.2 Collect Audit Logs
- 8.3 Ensure Adequate Audit Log Storage
- 8.4 Standardize Time Synchronization
- 8.5 Collect Detailed Audit Logs
- 8.6 Collect DNS Query Audit Logs
- 8.7 Collect URL Request Audit Logs
- 8.8 Collect Command-Line Audit Logs
- 8.9 Centralize Audit Logs
9 Email and Web Browser Protections
SNow
State: Published
Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement.
Children (7)
- 9.1 Ensure Use of Only Fully Supported Browsers and Email Cl...
- 9.2 Use DNS Filtering Services
- 9.3 Maintain and Enforce Network-Based URL Filters
- 9.4 Restrict Unnecessary or Unauthorized Browser and Email C...
- 9.5 Implement DMARC
- 9.6 Block Unnecessary File Types
- 9.7 Deploy and Maintain Email Server Anti-Malware Protection...
A&A-01 Audit and Assurance Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.
A&A-02 Independent Assessments
SNow
State: Published
Conduct independent audit and assurance assessments according to relevant standards at least annually.
A&A-03 Risk Based Planning Assessment
SNow
State: Published
Perform independent audit and assurance assessments according to
risk-based plans and policies.
A&A-04 Requirements Compliance
SNow
State: Published
Verify compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit.
A&A-05 Audit Management Process
SNow
State: Published
Define and implement an Audit Management process to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, and review of past reports and supporting evidence.
A&A-06 Remediation
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain a risk-based corrective action plan to remediate audit findings, review and report remediation status to relevant stakeholders.
AIS-01 Application and Interface Security Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at lea
AIS-02 Application Security Baseline Requirements
SNow
State: Published
Establish, document and maintain baseline requirements for securing different applications.
AIS-03 Application Security Metrics
SNow
State: Published
Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.
AIS-04 Secure Application Design and Development
SNow
State: Published
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
AIS-05 Automated Application Security Testing
SNow
State: Published
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
AIS-06 Automated Secure Application Deployment
SNow
State: Published
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
AIS-07 Application Vulnerability Remediation
SNow
State: Published
Define and implement a process to remediate application security vulnerabilities, automating remediation when possible.
Approved hosting and processing locations
SNow
State: Retired
BCR-01 Business Continuity Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain business continuity management and operational resilience policies and procedures. Review and update the policies and procedures at least annually.
BCR-02 Risk Assessment and Impact Analysis
SNow
State: Published
Determine the impact of business disruptions and risks to establish criteria for developing business continuity and operational resilience strategies and capabilities.
BCR-03 Business Continuity Strategy
SNow
State: Published
Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.
BCR-04 Business Continuity Planning
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain a business continuity plan based on the results of the operational resilience strategies and capabilities.
BCR-05 Documentation
SNow
State: Published
Develop, identify, and acquire documentation that is relevant to support the business continuity and operational resilience programs. Make the documentation available to authorized stakeholders and review periodically.
BCR-06 Business Continuity Exercises
SNow
State: Published
Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.
BCR-07 Communication
SNow
State: Published
Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
BCR-08 Backup
SNow
State: Published
Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.
BCR-09 Disaster Response Plan
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.
BCR-10 Response Plan Exercise
SNow
State: Published
Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.
BCR-11 Equipment Redundancy
SNow
State: Published
Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.
CCC-01 Change Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally
CCC-02 Quality Testing
SNow
State: Published
Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.
CCC-03 Change Management Technology
SNow
State: Published
Manage the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced).
CCC-04 Unauthorized Change Protection
SNow
State: Published
Restrict the unauthorized addition, removal, update, and management of organization assets.
CCC-05 Change Agreements
SNow
State: Published
Include provisions limiting changes directly impacting CSCs owned environments/tenants to explicitly authorized requests within service level agreements between CSPs and CSCs.
CCC-06 Change Management Baseline
SNow
State: Published
Establish change management baselines for all relevant authorized changes on organization assets.
CCC-07 Detection of Baseline Deviation
SNow
State: Published
Implement detection measures with proactive notification in case of changes deviating from the established baseline.
CCC-08 Exception Management
SNow
State: Published
Implement a procedure for the management of exceptions, including emergencies, in the change and configuration process. Align the procedure with the requirements of GRC-04: Policy Exception Process.'
CCC-09 Change Restoration
SNow
State: Published
Define and implement a process to proactively roll back changes to a previous known good state in case of errors or security concerns.
CEK-01 Encryption and Key Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.
CEK-02 CEK Roles and Responsibilities
SNow
State: Published
Define and implement cryptographic, encryption and key management roles and responsibilities.
CEK-03 Data Encryption
SNow
State: Published
Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
CEK-04 Encryption Algorithm
SNow
State: Published
Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
CEK-05 Encryption Change Management
SNow
State: Published
Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.
CEK-06 Encryption Change Cost Benefit Analysis
SNow
State: Published
Manage and adopt changes to cryptography-, encryption-, and key management-related systems (including policies and procedures) that fully account for downstream effects of proposed changes, including residual risk, cost, and benefits analysis.
CEK-07 Encryption Risk Management
SNow
State: Published
Establish and maintain an encryption and key management risk program that includes provisions for risk assessment, risk treatment, risk context, monitoring, and feedback.
CEK-08 CSC Key Management Capability
SNow
State: Published
CSPs must provide the capability for CSCs to manage their own data encryption keys.
CEK-09 Encryption and Key Management Audit
SNow
State: Published
Audit encryption and key management systems, policies, and processes with a frequency that is proportional to the risk exposure of the system with audit occurring preferably continuously but at least annually and after any security event(s).
CEK-10 Key Generation
SNow
State: Published
Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.
CEK-11 Key Purpose
SNow
State: Published
Manage cryptographic secret and private keys that are provisioned for a unique purpose.
CEK-12 Key Rotation
SNow
State: Published
Rotate cryptographic keys in accordance with the calculated cryptoperiod, which includes provisions for considering the risk of information disclosure and legal and regulatory requirements.
CEK-13 Key Revocation
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to revoke and remove cryptographic keys prior to the end of its established cryptoperiod, when a key is compromised, or an entity is no longer part of the organization, which include provisions for legal and regulatory requi
CEK-14 Key Destruction
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.
CEK-15 Key Activation
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to create keys in a pre-activated state when they have been generated but not authorized for use, which include provisions for legal and regulatory requirements.
CEK-16 Key Suspension
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to monitor, review and approve key transitions from any state to/from suspension, which include provisions for legal and regulatory requirements.
CEK-17 Key Deactivation
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to deactivate keys at the time of their expiration date, which include provisions for legal and regulatory requirements.
CEK-18 Key Archival
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
CEK-19 Key Compromise
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
CEK-20 Key Recovery
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to assess the risk to operational continuity versus the risk of the keying material and the information it protects being exposed if control of the keying material is lost, which include provisions for legal and regulatory r
CEK-21 Key Inventory Management
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
Centralized identity management
SNow
State: Retired
Change management
SNow
State: Published
All Services must adhere to Roche Global Change Management Process
Citations (3)
Compliance Assessment with Internal Controls for Financial Reporting (ICFR)
SNow
State: Published
Compliance with Roche COREMAP Requirements
SNow
State: Published
Computerised System Validation
SNow
State: Published
Computerised Systems Validation (CSV) ensures that new and existing GxP relevant computerized systems consistently fulfill their intended use and produce accurate and reliable results that ensure regulatory compliance, product quality and patient safety.
Action: For systems delivered by Informatics
Citations (85)
- AS.164.308.a8
- Ability to Generate Copies
- Applicability to ER/ES
- Archiving
- Authority Checks
- Availability for Inspection
- Backup and Restore
- Biometric Safeguards
- Business Continuity
- CS Inventory
- Change Management
- Collusion Prevention
- Credential Maintenance
- Definition: Act (FD&C Act)
- Definition: Agency (FDA)
- Definition: Biometrics
- Definition: Closed System
- Definition: Digital Signature
- Definition: Electronic Record
- Definition: Electronic Signature
- Definition: Handwritten Signature
- Definition: Open System
- Device (Terminal) Checks
- Device Testing
- Dual-Component Requirement: Single Session and New Session P...
- Education & Training
- Electronic Records (Audit trail in human readable format)
- Electronic Records (Audit trail)
- Electronic Records (Data Integrity)
- Electronic Records (Data Review)
- Electronic Records (Data availbility in human readable forma...
- Electronic Records (Security and Access Management)
- Electronic Signature
- Electronic Signature (Qualifiied Person)
- Electronic in lieu of Paper
- Electronic records/signatures in lieu of paper (Maintained r...
- GV.OC-03
- IT Supplier Audit Reports
- Identity Verification
- Incident Management
- Individual Accountability
- Infrastructure Qualification
- Legal Binding Certification
- Limiting System Access
- Loss Management
- Non-Repudiation Letter
- Ongoing Validation
- Open System Controls
- Operational Checks
- Owner Exclusivity
- PR.PS-04
- Periodic Review
- Protection/Retention
- Qualified Test Environment
- Quality Management System (in house)
- Quality Management System (supplier)
- Risk Management
- Roles and Responsibilties
- Secure development life cycle
- Security Controls
- Security Monitoring
- Security testing in development and acceptance
- Signature Equivalence
- Signature Manifestations
- Signature Uniqueness
- Signature/Record Linking
- Submissions to the Agency (Specific formats/media)
- System Authorization
- System Description
- System Documentation Ctrl
- System Performance
- Test Evidences
- Testing Tools Validation
- Time-stamped Audit Trails
- Traceability
- Training of Personnel
- Trustworthiness & Reliability
- Uniqueness of ID/Password
- User requirement specifications
- Validation
- Validation Approach
- Validation Documentation (Change control and Deviations)
- Validation Documentation (Planning and Reporting)
- Validation of Systems
- Vendor Documentation
Consent
SNow
State: Published
If "Consent" is selected as a legal basis, confirm the following requirements are covered:
-Consent is presented in an intelligible and easily accessible form, using clear and plain language adapted to the target user.
-Consent is freely given.
-Consent clearly describes the purpose for collecting
Cross Border Transfers
SNow
State: Published
In the event personal data is transferred to another country, the data transfers must be mapped in the RoPA Questionnaire and you must ensure compliance with the obligations regarding cross border data transfers.
DCS-01 Off-Site Equipment Disposal Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible mus
DCS-02 Off-Site Transfer Authorization Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable autho
DCS-03 Secure Area Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.
DCS-04 Secure Media Transportation Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.
DCS-05 Assets Classification
SNow
State: Published
Classify and document the physical, and logical assets (e.g., applications) based on the organizational business risk.
DCS-06 Assets Cataloguing and Tracking
SNow
State: Published
Catalogue and track all relevant physical and logical assets located at all of the CSP's sites within a secured system.
DCS-07 Controlled Access Points
SNow
State: Published
Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.
DCS-08 Equipment Identification
SNow
State: Published
Use equipment identification as a method for connection authentication.
DCS-09 Secure Area Authorization
SNow
State: Published
Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.
DCS-10 Surveillance System
SNow
State: Published
Implement, maintain, and operate datacenter surveillance systems at the external perimeter and at all the ingress and egress points to detect unauthorized ingress and egress attempts.
DCS-11 Unauthorized Access Response Training
SNow
State: Published
Train datacenter personnel to respond to unauthorized ingress or egress attempts.
DCS-12 Cabling Security
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures that ensure a risk-based protection of power and telecommunication cables from a threat of interception, interference or damage at all facilities, offices and rooms.
DCS-13 Environmental Systems
SNow
State: Published
Implement and maintain data center environmental control systems that monitor, maintain and test for continual effectiveness the temperature and humidity conditions within accepted industry standards.
DCS-14 Secure Utilities
SNow
State: Published
Secure, monitor, maintain, and test utilities services for continual effectiveness at planned intervals.
DCS-15 Equipment Location
SNow
State: Published
Keep business-critical equipment away from locations subject to high probability for environmental risk events.
DSP-01 Security and Privacy Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and proced
DSP-02 Secure Disposal
SNow
State: Published
Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.
DSP-03 Data Inventory
SNow
State: Published
Create and maintain a data inventory, at least for any sensitive data and personal data.
DSP-04 Data Classification
SNow
State: Published
Classify data according to its type and sensitivity level.
DSP-05 Data Flow Documentation
SNow
State: Published
Create data flow documentation to identify what data is processed, stored or transmitted where. Review data flow documentation at defined intervals, at least annually, and after any change.
DSP-06 Data Ownership and Stewardship
SNow
State: Published
Document ownership and stewardship of all relevant documented personal and sensitive data. Perform review at least annually.
DSP-07 Data Protection by Design and Default
SNow
State: Published
Develop systems, products, and business practices based upon a principle of security by design and industry best practices.
DSP-08 Data Privacy by Design and Default
SNow
State: Published
Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.
DSP-09 Data Protection Impact Assessment
SNow
State: Published
Conduct a Data Protection Impact Assessment (DPIA) to evaluate the origin, nature, particularity and severity of the risks upon the processing of personal data, according to any applicable laws, regulations and industry best practices.
DSP-10 Sensitive Data Transfer
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.
DSP-11 Personal Data Access, Reversal, Rectification and Deletion
SNow
State: Published
Define and implement, processes, procedures and technical measures to enable data subjects to request access to, modification, or deletion of their personal data, according to any applicable laws and regulations.
DSP-12 Limitation of Purpose in Personal Data Processing
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to ensure that personal data is processed according to any applicable laws and regulations and for the purposes declared to the data subject.
DSP-13 Personal Data Sub-processing
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for the transfer and sub-processing of personal data within the service supply chain, according to any applicable laws and regulations.
DSP-14 Disclosure of Data Sub-processors
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to disclose the details of any personal or sensitive data access by sub-processors to the data owner prior to initiation of that processing.
DSP-15 Limitation of Production Data Use
SNow
State: Published
Obtain authorization from data owners, and manage associated risk before replicating or using production data in non-production environments.
DSP-16 Data Retention and Deletion
SNow
State: Published
Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.
DSP-17 Sensitive Data Protection
SNow
State: Published
Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
DSP-18 Disclosure Notification
SNow
State: Published
The CSP must have in place, and describe to CSCs the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations. The CSP must give special attention to the notification procedure to interested CSCs, unless o
DSP-19 Data Location
SNow
State: Published
Define and implement, processes, procedures and technical measures to specify and document the physical locations of data, including any locations in which data is processed or backed up.
Data Accuracy
SNow
State: Published
Personal data must be accurate and kept up-to-date. Describe the processes you have in place to ensure that personal information is attributed to the correct individual and is accurate, complete, and up-to-date.
Data Breach
SNow
State: Published
Data security breaches must be detected, reported, and managed.
Describe how do you detect, report and manage data security breaches.
Data Minimization
SNow
State: Published
Data Minimization requires that personal data shall be adequate, relevant, and limited to what is necessary for the purposes of processing. Define the minimization controls.
Data Subject Rights
SNow
State: Published
Personal Data needs to be erased, corrected, retrievable and/or access restricted or blocked upon request. Describe how do you ensure execution of data subject rights.
Documented operating procedures
SNow
State: Published
Documenting Operating Procedures and working instructions is in place to ensure effective operation of all services and shall be documented and made available to personnel who need them
GRC-01 Governance Program Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.
GRC-02 Risk Management Program
SNow
State: Published
Establish a formal, documented, and leadership-sponsored Enterprise Risk Management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks.
GRC-03 Organizational Policy Reviews
SNow
State: Published
Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.
GRC-04 Policy Exception Process
SNow
State: Published
Establish and follow an approved exception process as mandated by the governance program whenever a deviation from an established policy occurs.
GRC-05 Information Security Program
SNow
State: Published
Develop and implement an Information Security Program, which includes programs for all the relevant domains of the CCM.
GRC-06 Governance Responsibility Model
SNow
State: Published
Define and document roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs.
GRC-07 Information System Regulatory Mapping
SNow
State: Published
Identify and document all relevant standards, regulations, legal/contractual, and statutory requirements, which are applicable to your organization.
GRC-08 Special Interest Groups
SNow
State: Published
Establish and maintain contact with cloud-related special interest groups and other relevant entities in line with business context.
HRS-01 Background Screening Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for background verification of all new employees (including but not limited to remote employees, contractors, and third parties) according to local laws, regulations, ethics, and contractual constraints a
HRS-02 Acceptable Use of Technology Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets. Review and update the policies and procedures at least annually.
HRS-03 Clean Desk Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures that require unattended workspaces to not have openly visible confidential data. Review and update the policies and procedures at least annually.
HRS-04 Remote and Home Working Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
HRS-05 Asset returns
SNow
State: Published
Establish and document procedures for the return of organization-owned assets by terminated employees.
HRS-06 Employment Termination
SNow
State: Published
Establish, document, and communicate to all personnel the procedures outlining the roles and responsibilities concerning changes in employment.
HRS-07 Employment Agreement Process
SNow
State: Published
Employees sign the employee agreement prior to being granted access to organizational information systems, resources and assets.
HRS-08 Employment Agreement Content
SNow
State: Published
The organization includes within the employment agreements provisions and/or terms for adherence to established information governance and security policies.
HRS-09 Personnel Roles and Responsibilities
SNow
State: Published
Document and communicate roles and responsibilities of employees, as they relate to information assets and security.
HRS-10 Non-Disclosure Agreements
SNow
State: Published
Identify, document, and review, at planned intervals, requirements for non-disclosure/confidentiality agreements reflecting the organization's needs for the protection of data and operational details.
HRS-11 Security Awareness Training
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain a security awareness training program for all employees of the organization and provide regular training updates.
HRS-12 Personal and Sensitive Data Awareness and Training
SNow
State: Published
Provide all employees with access to sensitive organizational and personal data with appropriate security awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization.
HRS-13 Compliance User Responsibility
SNow
State: Published
Make employees aware of their roles and responsibilities for maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations.
IAM-01 Identity and Access Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.
IAM-02 Strong Password Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, implement, apply, evaluate and maintain strong password policies and procedures. Review and update the policies and procedures at least annually.
IAM-03 Identity Inventory
SNow
State: Published
Manage, store, and review the information of system identities, and level of access.
IAM-04 Separation of Duties
SNow
State: Published
Employ the separation of duties principle when implementing information system access.
IAM-05 Least Privilege
SNow
State: Published
Employ the least privilege principle when implementing information system access.
IAM-06 User Access Provisioning
SNow
State: Published
Define and implement a user access provisioning process which authorizes, records, and communicates access changes to data and assets.
IAM-07 User Access Changes and Revocation
SNow
State: Published
De-provision or respectively modify access of movers / leavers or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.
IAM-08 User Access Review
SNow
State: Published
Review and revalidate user access for least privilege and separation of duties with a frequency that is commensurate with organizational risk tolerance.
IAM-09 Segregation of Privileged Access Roles
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for the segregation of privileged access roles such that administrative access to data, encryption and key management capabilities and logging capabilities are distinct and separated.
IAM-10 Management of Privileged Access Roles
SNow
State: Published
Define and implement an access process to ensure privileged access roles and rights are granted for a time limited period, and implement procedures to prevent the culmination of segregated privileged access.
IAM-11 CSCs Approval for Agreed Privileged Access Roles
SNow
State: Published
Define, implement and evaluate processes and procedures for customers to participate, where applicable, in the granting of access for agreed, high risk (as defined by the organizational risk assessment) privileged access roles.
IAM-12 Safeguard Logs Integrity
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it is controlled through a procedure that ensures the segregation of duties and
IAM-13 Uniquely Identifiable Users
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures that ensure users are identifiable through unique IDs or which can associate individuals to the usage of user IDs.
IAM-14 Strong Authentication
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for authenticating access to systems, application and data assets, including multifactor authentication for at least privileged user and sensitive data access. Adopt digital certificates or alternatives which achieve an equi
IAM-15 Passwords Management
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for the secure management of passwords.
IAM-16 Authorization Mechanisms
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.
IPY-01 Interoperability and Portability Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for interoperability and portability including requirements for:
a. Communications between application interfaces
b. Information processing interoperability
c. Application development portability
d. Infor
IPY-02 Application Interface Availability
SNow
State: Published
Provide application interface(s) to CSCs so that they programmatically retrieve their data to enable interoperability and portability.
IPY-03 Secure Interoperability and Portability Management
SNow
State: Published
Implement cryptographically secure and standardized network protocols for the management, import and export of data.
IPY-04 Data Portability Contractual Obligations
SNow
State: Published
Agreements must include provisions specifying CSCs access to data upon contract termination and will include:
a. Data format
b. Length of time the data will be stored
c. Scope of the data retained and made available to the CSCs
d. Data deletion policy
IVS-01 Infrastructure and Virtualization Security Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for infrastructure and virtualization security. Review and update the policies and procedures at least annually.
IVS-02 Capacity and Resource Planning
SNow
State: Published
Plan and monitor the availability, quality, and adequate capacity of resources in order to deliver the required system performance as determined by the business.
IVS-03 Network Security
SNow
State: Published
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating
IVS-04 OS Hardening and Base Controls
SNow
State: Published
Harden host and guest OS, hypervisor or infrastructure control plane according to their respective best practices, and supported by technical controls, as part of a security baseline.
IVS-05 Production and Non-Production Environments
SNow
State: Published
Separate production and non-production environments.
IVS-06 Segmentation and Segregation
SNow
State: Published
Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.
IVS-07 Migration to Cloud Environments
SNow
State: Published
Use secure and encrypted communication channels when migrating servers, services, applications, or data to cloud environments. Such channels must include only up-to-date and approved protocols.
IVS-08 Network Architecture Documentation
SNow
State: Published
Identify and document high-risk environments.
IVS-09 Network Defense
SNow
State: Published
Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.
Information security in project management
SNow
State: Published
Information Security is integrated into Project Management
Inventory of information and other associated assets
SNow
State: Published
All Services including supporting components must be registered in the CMDB
LOG-01 Logging and Monitoring Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.
LOG-02 Audit Logs Protection
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
LOG-03 Security Monitoring and Alerting
SNow
State: Published
Identify and monitor security-related events within applications and the underlying infrastructure. Define and implement a system to generate alerts to responsible stakeholders based on such events and corresponding metrics.
LOG-04 Audit Logs Access and Accountability
SNow
State: Published
Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.
LOG-05 Audit Logs Monitoring and Response
SNow
State: Published
Monitor security audit logs to detect activity outside of typical or expected patterns. Establish and follow a defined process to review and take appropriate and timely actions on detected anomalies.
LOG-06 Clock Synchronization
SNow
State: Published
Use a reliable time source across all relevant information processing systems.
LOG-07 Logging Scope
SNow
State: Published
Establish, document and implement which information meta/data system events should be logged. Review and update the scope at least annually or whenever there is a change in the threat environment.
LOG-08 Log Records
SNow
State: Published
Generate audit records containing relevant security information.
LOG-09 Log Protection
SNow
State: Published
The information system protects audit records from unauthorized access, modification, and deletion.
LOG-10 Encryption Monitoring and Reporting
SNow
State: Published
Establish and maintain a monitoring and internal reporting capability over the operations of cryptographic, encryption and key management policies, processes, procedures, and controls.
LOG-11 Transaction/Activity Logging
SNow
State: Published
Log and monitor key lifecycle management events to enable auditing and reporting on usage of cryptographic keys.
LOG-12 Access Control Logs
SNow
State: Published
Monitor and log physical access using an auditable access control system.
LOG-13 Failures and Anomalies Reporting
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for the reporting of anomalies and failures of the monitoring system and provide immediate notification to the accountable party.
Legal Basis
SNow
State: Published
Personal data processing must have a legal basis.
Legitimate Interest
SNow
State: Published
Review the Legitimate Interest Assessment conducted in the PIA. If your processing activity is covered, ensure compliance with such LIA. If your processing activity is not convered, a new LIA must be conducted.
Permission management
SNow
State: Retired
Policies for information security
SNow
State: Published
All Services should adhere to Roche Information Security Policies / Standard / Processes
Privacy Notice
SNow
State: Published
Data subjects need to be informed about the processing of their personal data and regarding their data subject rights. Explain how the privacy notice will be provided to the data subject and add the link to the privacy notice if available.
Protect Data at rest
SNow
State: Retired
Protect Data in transit
SNow
State: Retired
Purpose of the processing activity
SNow
State: Published
Personal data must be collected for specified, explicit, and legitimate purposes: ensure the personal data is collected for a specific purpose and clearly define the purposes for which the personal data will be processed within the solution.
SAP source outage
SNow
State: Published
SEF-01 Security Incident Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics. Review and update the policies and procedures at least annually.
SEF-02 Service Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the timely management of security incidents. Review and update the policies and procedures at least annually.
SEF-03 Incident Response Plans
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.'
SEF-04 Incident Response Testing
SNow
State: Published
Test and update as necessary incident response plans at planned intervals or upon significant organizational or environmental changes for effectiveness.
SEF-05 Incident Response Metrics
SNow
State: Published
Establish and monitor information security incident metrics.
SEF-06 Event Triage Processes
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures supporting business processes to triage security-related events.
SEF-07 Security Breach Notification
SNow
State: Published
Define and implement, processes, procedures and technical measures for security breach notifications. Report security breaches and assumed security breaches including any relevant supply chain breaches, as per applicable SLAs, laws and regulations.
SEF-08 Points of Contact Maintenance
SNow
State: Published
Maintain points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities.
SRA (risk assessment artifact capturing risk profile)
SNow
Classification: IdentifyState: Published
STA-01 SSRM Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the application of the Shared Security Responsibility Model (SSRM) within the organization. Review and update the policies and procedures at least annually.
STA-02 SSRM Supply Chain
SNow
State: Published
Apply, document, implement and manage the SSRM throughout the supply chain for the cloud service offering.
STA-03 SSRM Guidance
SNow
State: Published
Provide SSRM Guidance to the CSC detailing information about the SSRM applicability throughout the supply chain.
STA-04 SSRM Control Ownership
SNow
State: Published
Delineate the shared ownership and applicability of all CSA CCM controls according to the SSRM for the cloud service offering.
STA-05 SSRM Documentation Review
SNow
State: Published
Review and validate SSRM documentation for all cloud services offerings the organization uses.
STA-06 SSRM Control Implementation
SNow
State: Published
Implement, operate, and audit or assess the portions of the SSRM which the organization is responsible for.
STA-07 Supply Chain Inventory
SNow
State: Published
Develop and maintain an inventory of all supply chain relationships.
STA-08 Supply Chain Risk Management
SNow
State: Published
CSPs periodically review risk factors associated with all organizations within their supply chain.
STA-09 Primary Service and Contractual Agreement
SNow
State: Published
Service agreements between CSPs and CSCs (tenants) must incorporate at least the following mutually-agreed upon provisions and/or terms:
Scope, characteristics and location of business relationship and services offered
Information security requirements (including SSRM)
Change management proces
STA-10 Supply Chain Agreement Review
SNow
State: Published
Review supply chain agreements between CSPs and CSCs at least annually.
STA-11 Internal Compliance Testing
SNow
State: Published
Define and implement a process for conducting internal assessments to confirm conformance and effectiveness of standards, policies, procedures, and service level agreement activities at least annually.
STA-12 Supply Chain Service Agreement Compliance
SNow
State: Published
Implement policies requiring all CSPs throughout the supply chain to comply with information security, confidentiality, access control, privacy, audit, personnel policy and service level requirements and standards.
STA-13 Supply Chain Governance Review
SNow
State: Published
Periodically review the organization's supply chain partners' IT governance policies and procedures.
STA-14 Supply Chain Data Security Assessment
SNow
State: Published
Define and implement a process for conducting security assessments periodically for all organizations within the supply chain.
Security Design Document
SNow
State: Published
The security design document aims to be audit/inspection ready, being able to demonstrate that key security controls are properly integrated into the system design. The security concept document contains all security relevant information needed to demonstrate the system design is secure and all risk
Security Scorecard Rating is reviewed on a yearly basis
SNow
Classification: DetectiveState: Published
On a yearly basis the SSC rating is reviewed, in case the rating is below the agreed threshold (B Rating) a new Vendor Security Assessment needs to be executed.
Security concept review with Security Expert
SNow
State: Published
The Security Expert Review (SER) is a specialized control that solution teams can leverage to enhance their information security posture. It involves an in-depth assessment of key security controls' effectiveness in mitigating identified risks within the specific context of a system.
Security logging and incident management
SNow
State: Retired
Storage Duration
SNow
State: Published
A storage duration must be defined for each type of data and justified by the legal requirements and/or processing needs. Define the data retention period and erasure mechanism at the end of the storage duration.
System Inventory
SNow
Classification: IdentifyState: Published
System Risk Assessment (artifact capturing risk profile)
SNow
Classification: IdentifyState: Retired
TVM-01 Threat and Vulnerability Management Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to identify, report and prioritize the remediation of vulnerabilities, in order to protect systems against vulnerability exploitation. Review and update the policies and procedures at least annually.
TVM-02 Malware Protection Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect against malware on managed assets. Review and update the policies and procedures at least annually.
TVM-03 Vulnerability Remediation Schedule
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to enable both scheduled and emergency responses to vulnerability identifications, based on the identified risk.
TVM-04 Detection Updates
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to update detection tools, threat signatures, and indicators of compromise on a weekly, or more frequent basis.
TVM-05 External Library Vulnerabilities
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to identify updates for applications which use third party or open source libraries according to the organization's vulnerability management policy.
TVM-06 Penetration Testing
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for the periodic performance of penetration testing by independent third parties.
TVM-07 Vulnerability Identification
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures for the detection of vulnerabilities on organizationally managed assets at least monthly.
TVM-08 Vulnerability Prioritization
SNow
State: Published
Use a risk-based model for effective prioritization of vulnerability remediation using an industry recognized framework.
TVM-09 Vulnerability Management Reporting
SNow
State: Published
Define and implement a process for tracking and reporting vulnerability identification and remediation activities that includes stakeholder notification.
TVM-10 Vulnerability Management Metrics
SNow
State: Published
Establish, monitor and report metrics for vulnerability identification and remediation at defined intervals.
Third Party Management
SNow
State: Published
Third Parties are identified and governed by a contract.
For data processors, a data processing agreement is executed between the parties and the reference is provided in the RoPA questionnaire.
UEM-01 Endpoint Devices Policy and Procedures
SNow
State: Published
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for all endpoints. Review and update the policies and procedures at least annually.
UEM-02 Application and Service Approval
SNow
State: Published
Define, document, apply and evaluate a list of approved services, applications and sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data.
UEM-03 Compatibility
SNow
State: Published
Define and implement a process for the validation of the endpoint device's compatibility with operating systems and applications.
UEM-04 Endpoint Inventory
SNow
State: Published
Maintain an inventory of all endpoints used to store and access company data.
UEM-05 Endpoint Management
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-06 Automatic Lock Screen
SNow
State: Published
Configure all relevant interactive-use endpoints to require an automatic lock screen.
UEM-07 Operating Systems
SNow
State: Published
Manage changes to endpoint operating systems, patch levels, and/or applications through the company's change management processes.
UEM-08 Storage Encryption
SNow
State: Published
Protect information from unauthorized disclosure on managed endpoint devices with storage encryption.
UEM-09 Anti-Malware Detection and Prevention
SNow
State: Published
Configure managed endpoints with anti-malware detection and prevention technology and services.
UEM-10 Software Firewall
SNow
State: Published
Configure managed endpoints with properly configured software firewalls.
UEM-11 Data Loss Prevention
SNow
State: Published
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
UEM-12 Remote Locate
SNow
State: Published
Enable remote geo-location capabilities for all managed mobile endpoints.
UEM-13 Remote Wipe
SNow
State: Published
Define, implement and evaluate processes, procedures and technical measures to enable the deletion of company data remotely on managed endpoint devices.
UEM-14 Third-Party Endpoint Security Posture
SNow
State: Published
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.
Vendor Quality Assessment
SNow
State: Published
Vendor Quality Assessments are mandatory for GxP systems
Vendor Security Assessment is not older than 3 years
SNow
Classification: PreventiveState: Published
test_ elena
SNow
State: Retired