Search Control Objectives

No control objectives match the current filters.
1 Inventory and Control of Enterprise Assets
SNow
State: PublishedCategory: Uncategorized
Actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/Internet of Things (IoT) devices; and servers) connected to the infrastructure physically, virtually, remotely, and those within cloud environments,
1.1 Secure Login (Multi-Factor Authentication).
Mapping
Category: Mapping
1.1 Establish and Maintain Detailed Enterprise Asset Inventory
SNow
Classification: IdentifyState: PublishedCategory: Devices
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network
1.2 Establish and Maintain Detailed Enterprise Asset Inventory
SNow
Classification: RespondState: PublishedCategory: Devices
Ensure that a process exists to address unauthorized assets on a weekly basis. The enterprise may choose to remove the asset from the network, deny the asset from connecting remotely to the network, or quarantine the asset.
1.3 Utilize an Active Discovery Tool
SNow
Classification: DetectState: PublishedCategory: Devices
Utilize an active discovery tool to identify assets connected to the enterprise’s network. Configure the active discovery tool to execute daily, or more frequently.
1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
SNow
Classification: IdentifyState: PublishedCategory: Devices
Use DHCP logging on all DHCP servers or Internet Protocol (IP) address management tools to update the enterprise’s asset inventory. Review and use logs to update the enterprise’s asset inventory weekly, or more frequently.
1.5 Use a Passive Asset Discovery Tool
SNow
Classification: DetectState: PublishedCategory: Devices
Use a passive discovery tool to identify assets connected to the enterprise’s network. Review and use scans to update the enterprise’s asset inventory at least weekly, or more frequently.
10.1 Deploy and Maintain Anti-Malware Software
SNow
Classification: ProtectState: PublishedCategory: Devices
Deploy and maintain anti-malware software on all enterprise assets.
10.1 Third Party Risk Management (TPRM)
Mapping
Category: Mapping
10.2 Configure Automatic Anti-Malware Signature Updates
SNow
Classification: ProtectState: PublishedCategory: Devices
Configure automatic updates for anti-malware signature files on all enterprise assets.
10.3 Disable Autorun and Autoplay for Removable Media
SNow
Classification: ProtectState: PublishedCategory: Devices
Disable autorun and autoplay auto-execute functionality for removable media.
10.4 Configure Automatic Anti-Malware Scanning of Removable Media
SNow
Classification: DetectState: PublishedCategory: Devices
Configure anti-malware software to automatically scan removable media.
10.5 Enable Anti-Exploitation Features
SNow
Classification: ProtectState: PublishedCategory: Devices
Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
10.6 Centrally Manage Anti-Malware Software
SNow
Classification: ProtectState: PublishedCategory: Devices
Centrally manage anti-malware software.
10.7 Use Behavior-Based Anti-Malware Software
SNow
Classification: DetectState: PublishedCategory: Devices
Use behavior-based anti-malware software.
11 Data Recovery
SNow
State: PublishedCategory: Uncategorized
Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state.
11.1 Establish and Maintain a Data Recovery Process
SNow
Classification: RespondState: PublishedCategory: Data
Establish and maintain a data recovery process. In the process, address the scope of data recovery activities, recovery prioritization, and the security of backup data. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
11.1 Security Policy and Exception Management
Mapping
Category: Mapping
11.2 Perform Automated Backups
SNow
Classification: RespondState: PublishedCategory: Data
Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
11.3 Protect Recovery Data
SNow
Classification: ProtectState: PublishedCategory: Data
Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.
11.4 Establish and Maintain an Isolated Instance of Recovery Data
SNow
Classification: RespondState: PublishedCategory: Data
Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
11.5 Test Data Recovery
SNow
Classification: RespondState: PublishedCategory: Data
Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.
12.1 Ensure Network Infrastructure is Up-to-Date
SNow
Classification: ProtectState: PublishedCategory: Network
Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
12.2 Establish and Maintain a Secure Network Architecture
SNow
Classification: ProtectState: PublishedCategory: Network
Establish and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum.
12.3 Securely Manage Network Infrastructure
SNow
Classification: ProtectState: PublishedCategory: Network
Securely manage network infrastructure. Example implementations include version-controlled-infrastructure-as-code, and the use of secure network protocols, such as SSH and HTTPS.
12.4 Establish and Maintain Architecture Diagram(s)
SNow
Classification: IdentifyState: PublishedCategory: Network
Establish and maintain architecture diagram(s) and/or other network system documentation. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
SNow
Classification: ProtectState: PublishedCategory: Network
Centralize network AAA.
12.6 Use of Secure Network Management and Communication Protocols
SNow
Classification: ProtectState: PublishedCategory: Network
Use secure network management and communication protocols (e.g., 802.1X, Wi-Fi Protected Access 2 (WPA2) Enterprise or greater).
12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
SNow
Classification: ProtectState: PublishedCategory: Devices
Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.
12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
SNow
Classification: ProtectState: PublishedCategory: Devices
Establish and maintain dedicated computing resources, either physically or logically separated, for all administrative tasks or tasks requiring administrative access. The computing resources should be segmented from the enterprise's primary network and not be allowed internet access.
13.1 Centralize Security Event Alerting
SNow
Classification: DetectState: PublishedCategory: Network
Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies
13.10 Perform Application Layer Filtering
SNow
Classification: ProtectState: PublishedCategory: Network
Perform application layer filtering. Example implementations include a filtering proxy, application layer firewall, or gateway.
13.11 Tune Security Event Alerting Thresholds
SNow
Classification: DetectState: PublishedCategory: Network
Tune security event alerting thresholds monthly, or more frequently.
13.2 Deploy a Host-Based Intrusion Detection Solution
SNow
Classification: DetectState: PublishedCategory: Devices
Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
13.3 Deploy a Network Intrusion Detection Solution
SNow
Classification: DetectState: PublishedCategory: Network
Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System (NIDS) or equivalent cloud service provider (CSP) service.
13.4 Perform Traffic Filtering Between Network Segments
SNow
Classification: ProtectState: PublishedCategory: Network
Perform traffic filtering between network segments, where appropriate.
13.5 Manage Access Control for Remote Assets
SNow
Classification: ProtectState: PublishedCategory: Devices
Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and ap
13.6 Collect Network Traffic Flow Logs
SNow
Classification: DetectState: PublishedCategory: Network
Collect network traffic flow logs and/or network traffic to review and alert upon from network devices.
13.7 Deploy a Host-Based Intrusion Prevention Solution
SNow
Classification: ProtectState: PublishedCategory: Devices
Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
13.8 Deploy a Network Intrusion Prevention Solution
SNow
Classification: ProtectState: PublishedCategory: Network
Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.
13.9 Deploy Port-Level Access Control
SNow
Classification: ProtectState: PublishedCategory: Devices
Deploy port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.
14.1 Establish and Maintain a Security Awareness Program
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, o
14.2 Train Workforce Members to Recognize Social Engineering Attacks
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.
14.3 Train Workforce Members on Authentication Best Practices
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management.
14.4 Train Workforce on Data Handling Best Practices
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce members on how to identify and properly store, transfer, archive, and destroy sensitive data. This also includes training workforce members on clear screen and desk best practices, such as locking their screen when they step away from their enterprise asset, erasing physical and virt
14.5 Train Workforce Members on Causes of Unintentional Data Exposure
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, or publishing data to unintended audiences.
14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce members to be able to recognize a potential incident and be able to report such an incident.
14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce to understand how to verify and report out-of-date software patches or any failures in automated processes and tools. Part of this training should include notifying IT personnel of any failures in automated processes and tools.
14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Train workforce members on the dangers of connecting to, and transmitting data over, insecure networks for enterprise activities. If the enterprise has remote workers, training must include guidance to ensure that all users securely configure their home network infrastructure.
14.9 Conduct Role-Specific Security Awareness and Skills Training
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, (OWASP® Top 10 vulnerability awareness and prevention training for web application developers, and advanced social engineering awareness training f
15 Service Provider Management
SNow
State: PublishedCategory: Uncategorized
Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprise’s critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.
15.1 Establish and Maintain an Inventory of Service Providers
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
Establish and maintain an inventory of service providers. The inventory is to list all known service providers, include classification(s), and designate an enterprise contact for each service provider. Review and update the inventory annually, or when significant enterprise changes occur that could
15.2 Establish and Maintain a Service Provider Management Policy
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
Establish and maintain a service provider management policy. Ensure the policy addresses the classification, inventory, assessment, monitoring, and decommissioning of service providers. Review and update the policy annually, or when significant enterprise changes occur that could impact this Safegua
15.3 Classify Service Providers
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
Classify service providers. Classification consideration may include one or more characteristics, such as data sensitivity, data volume, availability requirements, applicable regulations, inherent risk, and mitigated risk. Update and review classifications annually, or when significant enterprise ch
15.4 Ensure Service Provider Contracts Include Security Requirements
SNow
Classification: ProtectState: PublishedCategory: Uncategorized
Ensure service provider contracts include security requirements. Example requirements may include minimum security program requirements, security incident and/or data breach notification and response, data encryption requirements, and data disposal commitments. These security requirements must be co
15.5 Assess Service Providers
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
Assess service providers consistent with the enterprise’s service provider management policy. Assessment scope may vary based on classification(s), and may include review of standardized assessment reports, such as Service Organization Control 2 (SOC 2) and Payment Card Industry (PCI) Attestation of
15.6 Monitor Service Providers
SNow
Classification: DetectState: PublishedCategory: Data
Monitor service providers consistent with the enterprise’s service provider management policy. Monitoring may include periodic reassessment of service provider compliance, monitoring service provider release notes, and dark web monitoring.
15.7 Securely Decommission Service Providers
SNow
Classification: ProtectState: PublishedCategory: Data
Securely decommission service providers. Example considerations include user and service account deactivation, termination of data flows, and secure disposal of enterprise data within service provider systems.
16.1 Establish and Maintain a Secure Application Development Process
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish and maintain a secure application development process. In the process, address such items as: secure application design standards, secure coding practices, developer training, vulnerability management, security of third-party code, and application security testing procedures. Review and up
16.10 Apply Secure Design Principles in Application Architectures
SNow
Classification: ProtectState: PublishedCategory: Applications
Apply secure design principles in application architectures. Secure design principles include the concept of least privilege and enforcing mediation to validate every operation that the user makes, promoting the concept of "never trust user input." Examples include ensuring that explicit error check
16.11 Leverage Vetted Modules or Services for Application Security Components
SNow
Classification: ProtectState: PublishedCategory: Applications
Leverage vetted modules or services for application security components, such as identity management, encryption, and auditing and logging. Using platform features in critical security functions will reduce developers’ workload and minimize the likelihood of design or implementation errors. Modern o
16.12 Implement Code-Level Security Checks
SNow
Classification: ProtectState: PublishedCategory: Applications
Apply static and dynamic analysis tools within the application life cycle to verify that secure coding practices are being followed.
16.13 Conduct Application Penetration Testing
SNow
Classification: ProtectState: PublishedCategory: Applications
Conduct application penetration testing. For critical applications, authenticated penetration testing is better suited to finding business logic vulnerabilities than code scanning and automated security testing. Penetration testing relies on the skill of the tester to manually manipulate an applicat
16.14 Conduct Threat Modeling
SNow
Classification: ProtectState: PublishedCategory: Applications
Conduct threat modeling. Threat modeling is the process of identifying and addressing application security design flaws within a design, before code is created. It is conducted through specially trained individuals who evaluate the application design and gauge security risks for each entry point and
16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish and maintain a process to accept and address reports of software vulnerabilities, including providing a means for external entities to report. The process is to include such items as: a vulnerability handling policy that identifies reporting process, responsible party for handling vulnerab
16.3 Perform Root Cause Analysis on Security Vulnerabilities
SNow
Classification: ProtectState: PublishedCategory: Applications
Perform root cause analysis on security vulnerabilities. When reviewing vulnerabilities, root cause analysis is the task of evaluating underlying issues that create vulnerabilities in code, and allows development teams to move beyond just fixing individual vulnerabilities as they arise.
16.4 Establish and Manage an Inventory of Third-Party Software Components
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish and manage an updated inventory of third-party components used in development, often referred to as a “bill of materials,” as well as components slated for future use. This inventory is to include any risks that each third-party component could pose. Evaluate the list at least monthly to i
16.5 Use Up-to-Date and Trusted Third-Party Software Components
SNow
Classification: ProtectState: PublishedCategory: Applications
Use up-to-date and trusted third-party software components. When possible, choose established and proven frameworks and libraries that provide adequate security. Acquire these components from trusted sources or evaluate the software for vulnerabilities before use.
16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish and maintain a severity rating system and process for application vulnerabilities that facilitates prioritizing the order in which discovered vulnerabilities are fixed. This process includes setting a minimum level of security acceptability for releasing code or applications. Severity rati
16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
SNow
Classification: ProtectState: PublishedCategory: Applications
Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed
16.8 Separate Production and Non-Production Systems
SNow
Classification: ProtectState: PublishedCategory: Applications
Maintain separate environments for production and non-production systems.
16.9 Train Developers in Application Security Concepts and Secure Coding
SNow
Classification: ProtectState: PublishedCategory: Applications
Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities. Training can include general security principles and application security standard practices. Conduct training at least annually and design in a way
17.1 Designate Personnel to Manage Incident Handling
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Designate one key person, and at least one backup, who will manage the enterprise’s incident handling process. Management personnel are responsible for the coordination and documentation of incident response and recovery efforts and can consist of employees internal to the enterprise, third-party ve
17.2 Establish and Maintain Contact Information for Reporting Security Incidents
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Establish and maintain contact information for parties that need to be informed of security incidents. Contacts may include internal staff, third-party vendors, law enforcement, cyber insurance providers, relevant government agencies, Information Sharing and Analysis Center (ISAC) partners, or other
17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Establish and maintain an enterprise process for the workforce to report security incidents. The process includes reporting timeframe, personnel to report to, mechanism for reporting, and the minimum information to be reported. Ensure the process is publicly available to all of the workforce. Review
17.4 Establish and Maintain an Incident Response Process
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Establish and maintain an incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.
17.5 Assign Key Roles and Responsibilities
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Assign key roles and responsibilities for incident response, including staff from legal, IT, information security, facilities, public relations, human resources, incident responders, and analysts, as applicable. Review annually, or when significant enterprise changes occur that could impact this Saf
17.6 Define Mechanisms for Communicating During Incident Response
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Determine which primary and secondary mechanisms will be used to communicate and report during a security incident. Mechanisms can include phone calls, emails, or letters. Keep in mind that certain mechanisms, such as emails, can be affected during a security incident. Review annually, or when signi
17.7 Conduct Routine Incident Response Exercises
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Plan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a mi
17.8 Conduct Post-Incident Reviews
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Conduct post-incident reviews. Post-incident reviews help prevent incident recurrence through identifying lessons learned and follow-up action.
17.9 Establish and Maintain Security Incident Thresholds
SNow
Classification: RespondState: PublishedCategory: Uncategorized
Establish and maintain security incident thresholds, including, at a minimum, differentiating between an incident and an event. Examples can include: abnormal activity, security vulnerability, security weakness, data breach, privacy incident, etc. Review annually, or when significant enterprise chan
18 Penetration Testing
SNow
State: PublishedCategory: Uncategorized
Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and technology), and simulating the objectives and actions of an attacker.
18.1 Establish and Maintain a Penetration Testing Program
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise contro
18.2 Perform Periodic External Penetration Tests
SNow
Classification: IdentifyState: PublishedCategory: Network
Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conduc
18.3 Remediate Penetration Test Findings
SNow
Classification: ProtectState: PublishedCategory: Network
Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.
18.4 Validate Security Measures
SNow
Classification: ProtectState: PublishedCategory: Network
Validate security measures after each penetration test. If deemed necessary, modify rulesets and capabilities to detect the techniques used during testing.
18.5 Perform Periodic Internal Penetration Tests
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
Perform periodic internal penetration tests based on program requirements, no less than annually. The testing may be clear box or opaque box.
2 Inventory and Control of Software Assets
SNow
State: PublishedCategory: Uncategorized
Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
2. Network and Infrastructure Security
Mapping
Category: Mapping
2.1 Establish and Maintain a Software Inventory
SNow
Classification: IdentifyState: PublishedCategory: Applications
Establish and maintain a detailed inventory of all licensed software installed on enterprise assets. The software inventory must document the title, publisher, initial install/use date, and business purpose for each entry; where appropriate, include the Uniform Resource Locator (URL), app store(s),
2.2 Ensure Authorized Software is Currently Supported
SNow
Classification: IdentifyState: PublishedCategory: Applications
Ensure that only currently supported software is designated as authorized in the software inventory for enterprise assets. If software is unsupported, yet necessary for the fulfillment of the enterprise’s mission, document an exception detailing mitigating controls and residual risk acceptance. For
2.3 Address Unauthorized Software
SNow
Classification: RespondState: PublishedCategory: Applications
Ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. Review monthly, or more frequently.
2.4 Utilize Automated Software Inventory Tools
SNow
Classification: DetectState: PublishedCategory: Applications
Utilize software inventory tools, when possible, throughout the enterprise to automate the discovery and documentation of installed software.
2.5 Allowlist Authorized Software
SNow
Classification: ProtectState: PublishedCategory: Applications
Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.
2.6 Allowlist Authorized Libraries
SNow
Classification: ProtectState: PublishedCategory: Applications
Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, .so, etc., files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.
2.7 Allowlist Authorized Scripts
SNow
Classification: ProtectState: PublishedCategory: Applications
Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1, .py, etc., files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.
3. Logging
Mapping
Category: Mapping
3.1 Establish and Maintain a Data Management Process
SNow
Classification: IdentifyState: PublishedCategory: Data
Establish and maintain a data management process. In the process, address data sensitivity, data owner, handling of data, data retention limits, and disposal requirements, based on sensitivity and retention standards for the enterprise. Review and update documentation annually, or when significant e
3.10 Encrypt Sensitive Data in Transit
SNow
Classification: ProtectState: PublishedCategory: Data
Encrypt sensitive data in transit. Example implementations can include: Transport Layer Security (TLS) and Open Secure Shell (OpenSSH).
3.11 Encrypt Sensitive Data at Rest
SNow
Classification: ProtectState: PublishedCategory: Data
Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as cli
3.12 Segment Data Processing and Storage Based on Sensitivity
SNow
Classification: ProtectState: PublishedCategory: Network
Segment data processing and storage based on the sensitivity of the data. Do not process sensitive data on enterprise assets intended for lower sensitivity data.
3.13 Deploy a Data Loss Prevention Solution
SNow
Classification: ProtectState: PublishedCategory: Data
Implement an automated tool, such as a host-based Data Loss Prevention (DLP) tool to identify all sensitive data stored, processed, or transmitted through enterprise assets, including those located onsite or at a remote service provider, and update the enterprise's sensitive data inventory.
3.14 Log Sensitive Data Access
SNow
Classification: DetectState: PublishedCategory: Data
Log sensitive data access, including modification and disposal.
3.2 Establish and Maintain a Data Inventory
SNow
Classification: IdentifyState: PublishedCategory: Data
Establish and maintain a data inventory, based on the enterprise’s data management process. Inventory sensitive data, at a minimum. Review and update inventory annually, at a minimum, with a priority on sensitive data.
3.3 Configure Data Access Control Lists
SNow
Classification: ProtectState: PublishedCategory: Data
Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.
3.4 Enforce Data Retention
SNow
Classification: ProtectState: PublishedCategory: Data
Retain data according to the enterprise’s data management process. Data retention must include both minimum and maximum timelines.
3.5 Securely Dispose of Data
SNow
Classification: ProtectState: PublishedCategory: Data
Securely dispose of data as outlined in the enterprise’s data management process. Ensure the disposal process and method are commensurate with the data sensitivity.
3.6 Encrypt Data on End-User Devices
SNow
Classification: ProtectState: PublishedCategory: Devices
Encrypt data on end-user devices containing sensitive data. Example implementations can include: Windows BitLocker®, Apple FileVault®, Linux® dm-crypt.
3.7 Establish and Maintain a Data Classification Scheme
SNow
Classification: IdentifyState: PublishedCategory: Data
Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as “Sensitive,” “Confidential,” and “Public,” and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise chan
3.8 Document Data Flows
SNow
Classification: IdentifyState: PublishedCategory: Data
Document data flows. Data flow documentation includes service provider data flows and should be based on the enterprise’s data management process. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
3.9 Encrypt Data on Removable Media
SNow
Classification: ProtectState: PublishedCategory: Data
Encrypt data on removable media.
4 Secure Configuration of Enterprise Assets and Software
SNow
State: PublishedCategory: Uncategorized
Establish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).
4.1 Establish and Maintain a Secure Configuration Process
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish and maintain a secure configuration process for enterprise assets (end-user devices, including portable and mobile, non-computing/IoT devices, and servers) and software (operating systems and applications). Review and update documentation annually, or when significant enterprise changes oc
4.10 Enforce Automatic Device Lockout on Portable End-User Devices
SNow
Classification: RespondState: PublishedCategory: Devices
Enforce automatic device lockout following a predetermined threshold of local failed authentication attempts on portable end-user devices, where supported. For laptops, do not allow more than 20 failed authentication attempts; for tablets and smartphones, no more than 10 failed authentication attemp
4.11 Enforce Remote Wipe Capability on Portable End-User Devices
SNow
Classification: ProtectState: PublishedCategory: Devices
Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.
4.12 Separate Enterprise Workspaces on Mobile End-User Devices
SNow
Classification: ProtectState: PublishedCategory: Devices
Ensure separate enterprise workspaces are used on mobile end-user devices, where supported. Example implementations include using an Apple® Configuration Profile or Android™ Work Profile to separate enterprise applications and data from personal applications and data.
4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
SNow
Classification: ProtectState: PublishedCategory: Network
Establish and maintain a secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
4.3 Configure Automatic Session Locking on Enterprise Assets
SNow
Classification: ProtectState: PublishedCategory: Users
Configure automatic session locking on enterprise assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes.
4.4 Implement and Manage a Firewall on Servers
SNow
Classification: ProtectState: PublishedCategory: Devices
Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.
4.5 Implement and Manage a Firewall on End-User Devices
SNow
Classification: ProtectState: PublishedCategory: Devices
Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
4.6 Securely Manage Enterprise Assets and Software
SNow
Classification: ProtectState: PublishedCategory: Network
Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled-infrastructure-as-code and accessing administrative interfaces over secure network protocols, such as Secure Shell (SSH) and Hypertext Transfer Protocol Secure (HTTPS). D
4.7 Manage Default Accounts on Enterprise Assets and Software
SNow
Classification: ProtectState: PublishedCategory: Users
Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
SNow
Classification: ProtectState: PublishedCategory: Devices
Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.
4.9 Configure Trusted DNS Servers on Enterprise Assets
SNow
Classification: ProtectState: PublishedCategory: Devices
Configure trusted DNS servers on enterprise assets. Example implementations include: configuring assets to use enterprise-controlled DNS servers and/or reputable externally accessible DNS servers.
5 Account Management
SNow
State: PublishedCategory: Uncategorized
Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.
5. Host and Endpoint Security
Mapping
Category: Mapping
5.1 Establish and Maintain an Inventory of Accounts
SNow
Classification: IdentifyState: PublishedCategory: Users
Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must include both user and administrator accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized,
5.2 Use Unique Passwords
SNow
Classification: ProtectState: PublishedCategory: Users
Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using MFA and a 14-character password for accounts not using MFA.
5.3 Disable Dormant Accounts
SNow
Classification: RespondState: PublishedCategory: Users
Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.
5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
SNow
Classification: ProtectState: PublishedCategory: Users
Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
5.5 Establish and Maintain an Inventory of Service Accounts
SNow
Classification: IdentifyState: PublishedCategory: Users
Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
5.6 Centralize Account Management
SNow
Classification: ProtectState: PublishedCategory: Users
Centralize account management through a directory or identity service.
6 Access Control Management
SNow
State: PublishedCategory: Uncategorized
Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.
6.1 Establish an Access Granting Process
SNow
Classification: ProtectState: PublishedCategory: Users
Establish and follow a process, preferably automated, for granting access to enterprise assets upon new hire, rights grant, or role change of a user
6.2 Establish an Access Revoking Process
SNow
Classification: ProtectState: PublishedCategory: Users
Establish and follow a process, preferably automated, for revoking access to enterprise assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails.
6.3 Require MFA for Externally-Exposed Applications
SNow
Classification: ProtectState: PublishedCategory: Users
Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.
6.4 Require MFA for Remote Network Access
SNow
Classification: ProtectState: PublishedCategory: Users
Require MFA for remote network access.
6.5 Require MFA for Administrative Access
SNow
Classification: ProtectState: PublishedCategory: Users
Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a third-party provider.
6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
SNow
Classification: IdentifyState: PublishedCategory: Users
Establish and maintain an inventory of the enterprise’s authentication and authorization systems, including those hosted on-site or at a remote service provider. Review and update the inventory, at a minimum, annually, or more frequently.
6.7 Centralize Access Control
SNow
Classification: ProtectState: PublishedCategory: Users
Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.
6.8 Define and Maintain Role-Based Access Control
SNow
Classification: ProtectState: PublishedCategory: Data
Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a r
7 Continuous Vulnerability Management
SNow
State: PublishedCategory: Uncategorized
Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise’s infrastructure, in order to remediate, and minimize, the window of opportunity for attackers. Monitor public and private industry sources for new threat and vulnerability information.
7. Application Security
Mapping
Category: Mapping
7.1 Establish and Maintain a Vulnerability Management Process
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
7.1 Vulnerability and Flaw Remediation
Mapping
Category: Mapping
7.2 Establish and Maintain a Remediation Process
SNow
Classification: RespondState: PublishedCategory: Applications
Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
7.3 Perform Automated Operating System Patch Management
SNow
Classification: ProtectState: PublishedCategory: Applications
Perform operating system updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
7.4 Perform Automated Application Patch Management
SNow
Classification: ProtectState: PublishedCategory: Applications
Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
SNow
Classification: IdentifyState: PublishedCategory: Applications
Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
SNow
Classification: IdentifyState: PublishedCategory: Applications
Perform automated vulnerability scans of externally-exposed enterprise assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis.
7.7 Remediate Detected Vulnerabilities
SNow
Classification: RespondState: PublishedCategory: Applications
Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
8. Privacy
Mapping
Category: Mapping
8.1 Establish and Maintain an Audit Log Management Process
SNow
Classification: ProtectState: PublishedCategory: Network
Establish and maintain an audit log management process that defines the enterprise’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that coul
8.1 Security in Development (Application Security)
Mapping
Category: Mapping
8.10 Retain Audit Logs
SNow
Classification: ProtectState: PublishedCategory: Network
Retain audit logs across enterprise assets for a minimum of 90 days.
8.11 Conduct Audit Log Reviews
SNow
Classification: DetectState: PublishedCategory: Network
Conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis.
8.12 Collect Service Provider Logs
SNow
Classification: DetectState: PublishedCategory: Data
Collect service provider logs, where supported. Example implementations include collecting authentication and authorization events, data creation and disposal events, and user management events.
8.2 Collect Audit Logs
SNow
Classification: DetectState: PublishedCategory: Network
Collect audit logs. Ensure that logging, per the enterprise’s audit log management process, has been enabled across enterprise assets.
8.3 Ensure Adequate Audit Log Storage
SNow
Classification: ProtectState: PublishedCategory: Network
Ensure that logging destinations maintain adequate storage to comply with the enterprise’s audit log management process.
8.4 Standardize Time Synchronization
SNow
Classification: ProtectState: PublishedCategory: Network
Standardize time synchronization. Configure at least two synchronized time sources across enterprise assets, where supported.
8.5 Collect Detailed Audit Logs
SNow
Classification: DetectState: PublishedCategory: Network
Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation.
8.6 Collect DNS Query Audit Logs
SNow
Classification: DetectState: PublishedCategory: Network
Collect DNS query audit logs on enterprise assets, where appropriate and supported.
8.7 Collect URL Request Audit Logs
SNow
Classification: DetectState: PublishedCategory: Network
Collect URL request audit logs on enterprise assets, where appropriate and supported.
8.8 Collect Command-Line Audit Logs
SNow
Classification: DetectState: PublishedCategory: Devices
Collect command-line audit logs. Example implementations include collecting audit logs from PowerShell®, BASH™, and remote administrative terminals.
8.9 Centralize Audit Logs
SNow
Classification: DetectState: PublishedCategory: Network
Centralize, to the extent possible, audit log collection and retention across enterprise assets.
9 Email and Web Browser Protections
SNow
State: PublishedCategory: Uncategorized
Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement.
9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
SNow
Classification: ProtectState: PublishedCategory: Applications
Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
9.2 Use DNS Filtering Services
SNow
Classification: ProtectState: PublishedCategory: Network
Use DNS filtering services on all enterprise assets to block access to known malicious domains.
9.3 Maintain and Enforce Network-Based URL Filters
SNow
Classification: ProtectState: PublishedCategory: Network
Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise asset
9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
SNow
Classification: ProtectState: PublishedCategory: Applications
Restrict, either through uninstalling or disabling, any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications.
9.5 Implement DMARC
SNow
Classification: ProtectState: PublishedCategory: Network
To lower the chance of spoofed or modified emails from valid domains, implement DMARC policy and verification, starting with implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail (DKIM) standards.
9.6 Block Unnecessary File Types
SNow
Classification: ProtectState: PublishedCategory: Network
Block unnecessary file types attempting to enter the enterprise’s email gateway.
9.7 Deploy and Maintain Email Server Anti-Malware Protections
SNow
Classification: ProtectState: PublishedCategory: Network
Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.
A&A-01 Audit and Assurance Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.
A&A-02 Independent Assessments
SNow
State: PublishedCategory: Uncategorized
Conduct independent audit and assurance assessments according to relevant standards at least annually.
A&A-03 Risk Based Planning Assessment
SNow
State: PublishedCategory: Uncategorized
Perform independent audit and assurance assessments according to risk-based plans and policies.
A&A-04 Requirements Compliance
SNow
State: PublishedCategory: Uncategorized
Verify compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit.
A&A-05 Audit Management Process
SNow
State: PublishedCategory: Uncategorized
Define and implement an Audit Management process to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, and review of past reports and supporting evidence.
A&A-06 Remediation
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain a risk-based corrective action plan to remediate audit findings, review and report remediation status to relevant stakeholders.
AIS-01 Application and Interface Security Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at lea
AIS-02 Application Security Baseline Requirements
SNow
State: PublishedCategory: Uncategorized
Establish, document and maintain baseline requirements for securing different applications.
AIS-03 Application Security Metrics
SNow
State: PublishedCategory: Uncategorized
Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.
AIS-04 Secure Application Design and Development
SNow
State: PublishedCategory: Uncategorized
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
AIS-05 Automated Application Security Testing
SNow
State: PublishedCategory: Uncategorized
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
AIS-06 Automated Secure Application Deployment
SNow
State: PublishedCategory: Uncategorized
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
AIS-07 Application Vulnerability Remediation
SNow
State: PublishedCategory: Uncategorized
Define and implement a process to remediate application security vulnerabilities, automating remediation when possible.
Access to the manufacturing system should be restricted based on communication source (trusted network, external network, wireless network).
SNow
Classification: ProtectState: PublishedCategory: Technical security
Access to the manufacturing system should be restricted based on communication source (trusted network, external network, wireless network).
Access to the manufacturing system should be restricted to authorized users/devices/3rd parties only and follow the principle of least privilege.
SNow
Classification: ProtectState: PublishedCategory: Identity and Access
Access to the manufacturing system should be restricted to authorized users/devices/3rd parties only and follow the principle of least privilege.
Accounts and authenticators management for the Manufacturing system and applications should be based (where technically possible) on the Active Directory (AD).
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
Accounts and authenticators management for the Manufacturing system and applications should be based (where technically possible) on the Active Directory (AD).
Acquisition or sale of facilities, technology, and services
SNow
Classification: IT Impact ZoneState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Acquisition or sale of facilities, technology, and services
Activate audit logging
SNow
Classification: DetectState: PublishedCategory: Network
Ensure that local logging has been enabled on all systems and networking devices.
Activate the continuity plan if the damage assessment report indicates the activation criterion has been met.
SNow
Classification: CorrectiveState: PublishedCategory: Systems continuity
Activate the continuity plan if the damage assessment report indicates the activation criterion has been met.
Activate third party maintenance accounts and User IDs as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Activate third party maintenance accounts and User IDs as necessary.
Add all devices requiring access control to the Access Control List.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Add all devices requiring access control to the Access Control List.
Add inventoried assets to the asset register database, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Add inventoried assets to the asset register database, as necessary.
Address Unauthorized Assets
SNow
Classification: RespondState: PublishedCategory: Devices
Ensure that unauthorized assets are either removed from the network, quarantined, or the inventory is updated in a timely manner.
Address unapproved software
SNow
Classification: RespondState: PublishedCategory: Applications
Ensure that unauthorized software is either removed or the inventory is updated in a timely manner.
Adhere to Privacy Principles
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
As stated in the Roche Code of Conduct, "Any information related to an identified or identifiable person must be collected and processed in compliance with applicable data privacy laws (e.g. Swiss Federal Act on Data Protection, EU General Data Protection Regulation and the US Health Insurance Porta
Adhere to RoBOT Standard for Chatbots and Robotic Process Automation
SNow
Classification: MandatedState: PublishedCategory: Roche Security Standards
Software RPA Robots and Chatbots must be implemented and operated in compliance with Roche Software RoBOT security standard
Adhere to Roche Cloud Security Standards
SNow
State: RetiredCategory: Roche Security Standards
Adhere to operating procedures as defined in the Standard Operating Procedures Manual.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Adhere to operating procedures as defined in the Standard Operating Procedures Manual.
Alert appropriate personnel when rogue network devices are discovered.
SNow
Classification: CorrectiveState: PublishedCategory: Technical security
Alert appropriate personnel when rogue network devices are discovered.
Alert interested personnel when suspicious activity is detected by an Intrusion Detection System or Intrusion Prevention System.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Alert interested personnel when suspicious activity is detected by an Intrusion Detection System or Intrusion Prevention System.
Alert on Account Login Behavior Deviation
SNow
Classification: DetectState: PublishedCategory: Users
Alert when users deviate from normal login behavior, such as time-of-day, workstation location and duration.
Align critical Information Technology resource availability planning with capacity planning.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Align critical Information Technology resource availability planning with capacity planning.
Allocate sufficient resources to protect Information Systems during capital planning.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Allocate sufficient resources to protect Information Systems during capital planning.
Alternative solutions for data transfer should be evaluated or implemented (data gateway, secure storage media solutions...)
SNow
Classification: ProtectState: PublishedCategory: Technical security
Analyze and evaluate training records to improve the training program.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Analyze and evaluate training records to improve the training program.
Analyze and quantify the risks to in scope systems and information.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Analyze and quantify the risks to in scope systems and information.
Analyze security violations in Suspicious Activity Reports.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Analyze security violations in Suspicious Activity Reports.
Analyze system audit reports and determine the need to perform more tests.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Analyze system audit reports and determine the need to perform more tests.
Any domain controller connected to the manufacturing system must be hardened and comply with the established vulnerability scanning and patch management procedures.
SNow
Classification: ProtectState: PublishedCategory: Operational management
Any domain controller connected to the manufacturing system must be hardened and comply with the established vulnerability scanning and patch management procedures.
Apply Host-based Firewalls or Port Filtering
SNow
Classification: ProtectState: PublishedCategory: Devices
Apply host-based firewalls or port filtering tools on end systems, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
Apply Static and Dynamic Code Analysis Tools
SNow
Classification: DetectState: PublishedCategory: Applications
Apply static and dynamic analysis tools to verify that secure coding practices are being adhered to for internally developed software.
Approve all compliance documents.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Approve all compliance documents.
Approve and authorize the newly implemented system.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Approve and authorize the newly implemented system.
Approve change requests prior to implementing approved changes.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Approve change requests prior to implementing approved changes.
Approve each system's Configurable Items (and changes to those Configurable Items).
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Approve each system's Configurable Items (and changes to those Configurable Items).
Approve risk assessment methodologies at the executive management level within the organization.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Approve risk assessment methodologies at the executive management level within the organization.
Approve the results of the risk assessment as documented in the risk assessment report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Approve the results of the risk assessment as documented in the risk assessment report.
Approve the risk assessment report of operational risks as a part of the acquisition feasibility study.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Approve the risk assessment report of operational risks as a part of the acquisition feasibility study.
Approved Hosting and Processing Locations
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Business sensitive information and data with compliance requirements (e.g. GxP, Personal Data), must be processed by an approved supplier at approved processing locations.
Approved hosting and processing locations
SNow
State: RetiredCategory: Uncategorized
Archive outdated cryptographic keys.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Archive outdated cryptographic keys.
Archive the audit trail in accordance with compliance requirements.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Archive the audit trail in accordance with compliance requirements.
Artificial Intelligence Security Requirements
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Data Science is a multidisciplinary field that encompasses various techniques, methods, and processes for extracting knowledge and gaining insights from data. In the context of artificial intelligence (AI), data science plays a crucial role as a foundational component. Therefore, to process the da
Assess all security incidents to determine what information was accessed.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Assess all security incidents to determine what information was accessed.
Assess customer satisfaction.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Assess customer satisfaction.
Assess the potential level of business impact risk associated with control weaknesses.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Assess the potential level of business impact risk associated with control weaknesses.
Assess the quality of the audit program in regards to the staff and their qualifications.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Assess the quality of the audit program in regards to the staff and their qualifications.
Assign Information System access authorizations if implementing segregation of duties.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign Information System access authorizations if implementing segregation of duties.
Assign Job Titles and Duties for Incident Response
SNow
Classification: ProtectState: PublishedCategory: Users
Assign job titles and duties for handling computer and network incidents to specific individuals and ensure tracking and documentation throughout the incident through resolution.
Assign a probability of occurrence to all types of threats in the threat and risk classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Assign a probability of occurrence to all types of threats in the threat and risk classification scheme.
Assign and maintain user accounts and User Access Management for all systems.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign and maintain user accounts and User Access Management for all systems.
Assign and staff all roles appropriately.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Assign and staff all roles appropriately.
Assign biometric authentication to user accounts as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign biometric authentication to user accounts as necessary.
Assign ownership of the information security governance program to the appropriate role.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Assign ownership of the information security governance program to the appropriate role.
Assign ownership of the internal control framework to the appropriate organizational role.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Assign ownership of the internal control framework to the appropriate organizational role.
Assign passwords or passphrases to user accounts as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign passwords or passphrases to user accounts as necessary.
Assign penetration testing to a qualified internal resource or external third party.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Assign penetration testing to a qualified internal resource or external third party.
Assign resources to implement the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Assign resources to implement the internal control framework.
Assign the audit to impartial auditors.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Assign the audit to impartial auditors.
Assign the corporate governance of Information Technology to the compliance oversight committee.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Assign the corporate governance of Information Technology to the compliance oversight committee.
Assign the internal Information Technology audit staff to be independent from the Information Technology group reporting to the Board of Directors.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Assign the internal Information Technology audit staff to be independent from the Information Technology group reporting to the Board of Directors.
Assign the review of Information Technology policies and procedures to the compliance oversight committee.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Assign the review of Information Technology policies and procedures to the compliance oversight committee.
Assign the review of custom code changes to individuals other than the code author.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Assign the review of custom code changes to individuals other than the code author.
Assign the role of asset physical security to applicable controls.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Assign the role of asset physical security to applicable controls.
Assign the role of information security management as a part of developing systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Assign the role of information security management as a part of developing systems.
Assign the role of logical access control to applicable controls.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Assign the role of logical access control to applicable controls.
Assign the role of the Quality Management committee to applicable controls.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Assign the role of the Quality Management committee to applicable controls.
Assign the roles and responsibilities for the Board of Directors and senior management in the Audit function.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Assign the roles and responsibilities for the Board of Directors and senior management in the Audit function.
Assign token-based authentication or Smart Card Logon to user accounts as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign token-based authentication or Smart Card Logon to user accounts as necessary.
Assign user permissions based on job responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign user permissions based on job responsibilities.
Assign user privileges after they have management sign off.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Assign user privileges after they have management sign off.
Assign vulnerability scanning to a qualified internal resource or external third party.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Assign vulnerability scanning to a qualified internal resource or external third party.
Associate Active Ports, Services and Protocols to Asset Inventory
SNow
Classification: IdentifyState: PublishedCategory: Devices
Associate active ports, services and protocols to the hardware assets in the asset inventory.
Associate records with their security attributes.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Associate records with their security attributes.
Audit all modifications to the application being developed.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Audit all modifications to the application being developed.
Audit in scope audit items and compliance documents as defined in the audit scope.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Audit in scope audit items and compliance documents as defined in the audit scope.
Audit the in scope system according to the test plan using relevant evidence.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Audit the in scope system according to the test plan using relevant evidence.
Audits and risk management
SNow
Classification: IT Impact ZoneState: PublishedCategory: Audits and risk management
Audits and risk management
Authorize visitors before granting entry to physical areas containing restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Authorize visitors before granting entry to physical areas containing restricted data or restricted information.
Automate a programmatic process to remove stored data and records that exceed retention requirements.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Automate a programmatic process to remove stored data and records that exceed retention requirements.
Automate the continuous monitoring of Configuration Management, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Automate the continuous monitoring of Configuration Management, as necessary.
Automatically respond when an integrity violation is detected.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Automatically respond when an integrity violation is detected.
BCR-01 Business Continuity Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain business continuity management and operational resilience policies and procedures. Review and update the policies and procedures at least annually.
BCR-02 Risk Assessment and Impact Analysis
SNow
State: PublishedCategory: Uncategorized
Determine the impact of business disruptions and risks to establish criteria for developing business continuity and operational resilience strategies and capabilities.
BCR-03 Business Continuity Strategy
SNow
State: PublishedCategory: Uncategorized
Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.
BCR-04 Business Continuity Planning
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain a business continuity plan based on the results of the operational resilience strategies and capabilities.
BCR-05 Documentation
SNow
State: PublishedCategory: Uncategorized
Develop, identify, and acquire documentation that is relevant to support the business continuity and operational resilience programs. Make the documentation available to authorized stakeholders and review periodically.
BCR-06 Business Continuity Exercises
SNow
State: PublishedCategory: Uncategorized
Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.
BCR-07 Communication
SNow
State: PublishedCategory: Uncategorized
Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
BCR-08 Backup
SNow
State: PublishedCategory: Uncategorized
Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.
BCR-09 Disaster Response Plan
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.
BCR-10 Response Plan Exercise
SNow
State: PublishedCategory: Uncategorized
Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.
BCR-11 Equipment Redundancy
SNow
State: PublishedCategory: Uncategorized
Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.
Back up audit trails according to backup procedures.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Back up audit trails according to backup procedures.
Back up logs according to backup procedures.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Back up logs according to backup procedures.
Backup and Restore
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Data backup and restore testing procedures aligned with business requirements are in place to prevent data loss.
Block Unnecessary File Types
SNow
Classification: ProtectState: PublishedCategory: Network
Block all e-mail attachments entering the organization's e-mail gateway if the file types are unnecessary for the organization's business.
Block and/or remove unused software and unauthorized software.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Block and/or remove unused software and unauthorized software.
Budget appropriately for Information Security.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Budget appropriately for Information Security.
CCC-01 Change Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally
CCC-02 Quality Testing
SNow
State: PublishedCategory: Uncategorized
Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.
CCC-03 Change Management Technology
SNow
State: PublishedCategory: Uncategorized
Manage the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced).
CCC-04 Unauthorized Change Protection
SNow
State: PublishedCategory: Uncategorized
Restrict the unauthorized addition, removal, update, and management of organization assets.
CCC-05 Change Agreements
SNow
State: PublishedCategory: Uncategorized
Include provisions limiting changes directly impacting CSCs owned environments/tenants to explicitly authorized requests within service level agreements between CSPs and CSCs.
CCC-06 Change Management Baseline
SNow
State: PublishedCategory: Uncategorized
Establish change management baselines for all relevant authorized changes on organization assets.
CCC-07 Detection of Baseline Deviation
SNow
State: PublishedCategory: Uncategorized
Implement detection measures with proactive notification in case of changes deviating from the established baseline.
CCC-08 Exception Management
SNow
State: PublishedCategory: Uncategorized
Implement a procedure for the management of exceptions, including emergencies, in the change and configuration process. Align the procedure with the requirements of GRC-04: Policy Exception Process.'
CCC-09 Change Restoration
SNow
State: PublishedCategory: Uncategorized
Define and implement a process to proactively roll back changes to a previous known good state in case of errors or security concerns.
CEK-01 Encryption and Key Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.
CEK-02 CEK Roles and Responsibilities
SNow
State: PublishedCategory: Uncategorized
Define and implement cryptographic, encryption and key management roles and responsibilities.
CEK-03 Data Encryption
SNow
State: PublishedCategory: Uncategorized
Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
CEK-04 Encryption Algorithm
SNow
State: PublishedCategory: Uncategorized
Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
CEK-05 Encryption Change Management
SNow
State: PublishedCategory: Uncategorized
Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.
CEK-06 Encryption Change Cost Benefit Analysis
SNow
State: PublishedCategory: Uncategorized
Manage and adopt changes to cryptography-, encryption-, and key management-related systems (including policies and procedures) that fully account for downstream effects of proposed changes, including residual risk, cost, and benefits analysis.
CEK-07 Encryption Risk Management
SNow
State: PublishedCategory: Uncategorized
Establish and maintain an encryption and key management risk program that includes provisions for risk assessment, risk treatment, risk context, monitoring, and feedback.
CEK-08 CSC Key Management Capability
SNow
State: PublishedCategory: Uncategorized
CSPs must provide the capability for CSCs to manage their own data encryption keys.
CEK-09 Encryption and Key Management Audit
SNow
State: PublishedCategory: Uncategorized
Audit encryption and key management systems, policies, and processes with a frequency that is proportional to the risk exposure of the system with audit occurring preferably continuously but at least annually and after any security event(s).
CEK-10 Key Generation
SNow
State: PublishedCategory: Uncategorized
Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.
CEK-11 Key Purpose
SNow
State: PublishedCategory: Uncategorized
Manage cryptographic secret and private keys that are provisioned for a unique purpose.
CEK-12 Key Rotation
SNow
State: PublishedCategory: Uncategorized
Rotate cryptographic keys in accordance with the calculated cryptoperiod, which includes provisions for considering the risk of information disclosure and legal and regulatory requirements.
CEK-13 Key Revocation
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to revoke and remove cryptographic keys prior to the end of its established cryptoperiod, when a key is compromised, or an entity is no longer part of the organization, which include provisions for legal and regulatory requi
CEK-14 Key Destruction
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.
CEK-15 Key Activation
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to create keys in a pre-activated state when they have been generated but not authorized for use, which include provisions for legal and regulatory requirements.
CEK-16 Key Suspension
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to monitor, review and approve key transitions from any state to/from suspension, which include provisions for legal and regulatory requirements.
CEK-17 Key Deactivation
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to deactivate keys at the time of their expiration date, which include provisions for legal and regulatory requirements.
CEK-18 Key Archival
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
CEK-19 Key Compromise
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
CEK-20 Key Recovery
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to assess the risk to operational continuity versus the risk of the keying material and the information it protects being exposed if control of the keying material is lost, which include provisions for legal and regulatory r
CEK-21 Key Inventory Management
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
Capture the records required by organizational compliance requirements.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Capture the records required by organizational compliance requirements.
Categorize all suppliers in the supply chain management program.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Categorize all suppliers in the supply chain management program.
Categorize the systems, information, and data by risk profile in the threat and risk classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Categorize the systems, information, and data by risk profile in the threat and risk classification scheme.
Central Log Management
SNow
Classification: DetectState: PublishedCategory: Network
Ensure that appropriate logs are being aggregated to a central log management system for analysis and review.
Centralize Anti-malware Logging
SNow
Classification: DetectState: PublishedCategory: Devices
The important aspect of this requirement is getting the logs off of the endpoint so a malware infection doesn’t clear them out.
Centralize network time servers to as few as practical.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Centralize network time servers to as few as practical.
Centralized Identity Management
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
A framework of policies, processes, and technologies that facilitates the management of digital identities (e.g. user accounts, service accounts) and the relevant entitlements (access permissions) granted to an identity or a group of identities. Initiate, capture, record, and manage the entire lifec
Centralized identity management
SNow
State: RetiredCategory: Uncategorized
Change Default Passwords
SNow
Classification: ProtectState: PublishedCategory: Users
Before deploying any new asset, change all default passwords to have values consistent with administrative level accounts.
Change all default passwords.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Change all default passwords.
Change cipher lock codes every 90 days.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Change cipher lock codes every 90 days.
Change cipher lock codes upon authorized personnel status change or termination.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Change cipher lock codes upon authorized personnel status change or termination.
Change cryptographic keys, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Change cryptographic keys, as necessary.
Change management
SNow
State: PublishedCategory: Uncategorized
All Services must adhere to Roche Global Change Management Process
Change the default community string for Simple Network Management Protocol.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Change the default community string for Simple Network Management Protocol.
Change vendor-supplied default configurations as appropriate.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Change vendor-supplied default configurations as appropriate.
Check that personal data is complete.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Check that personal data is complete.
Check the accuracy of personal data.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Check the accuracy of personal data.
Classify restricted data or restricted information in Records Management systems according to the data or information's sensitivity.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Classify restricted data or restricted information in Records Management systems according to the data or information's sensitivity.
Client and Server Malware Protection
SNow
Classification: PreventiveState: PublishedCategory: Host and Endpoint Security
Anti-virus/Anti-malware software is used to provide virus and malware protection and forensic capabilities to computer systems, such as servers or workstations, that will store and process Roche data.
Cloud Security Configuration Monitoring
SNow
Classification: DetectiveState: PublishedCategory: Logging, Monitoring, Threat Detection, and Analytics
Enable automated security and configuration monitoring of cloud environments to help detect potential threats and vulnerabilities to data or systems in the cloud.
Collect all work papers for the audit and audit report into an engagement file.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Collect all work papers for the audit and audit report into an engagement file.
Collect data in a fair and lawful way.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Collect data in a fair and lawful way.
Collect data in a proper information framework.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Collect data in a proper information framework.
Collect evidence from the incident scene.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Collect evidence from the incident scene.
Collect evidence of each supplier's supply chain due diligence processes.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Collect evidence of each supplier's supply chain due diligence processes.
Communicate information about risks to all interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Communicate information about risks to all interested personnel and affected parties.
Communicate organizational security policies and security procedures as a part of security awareness.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Communicate organizational security policies and security procedures as a part of security awareness.
Communicate proposed changes to all interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Communicate proposed changes to all interested personnel and affected parties.
Communicate security awareness and the internal control framework to all interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Communicate security awareness and the internal control framework to all interested personnel and affected parties.
Communicate the Information Technology plans to all interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Communicate the Information Technology plans to all interested personnel and affected parties.
Communicate updates to the Governance, Risk, and Compliance framework to interested personnel and affected parties, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Communicate updates to the Governance, Risk, and Compliance framework to interested personnel and affected parties, as necessary.
Communicate with the organization about any missing audit documentation.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Communicate with the organization about any missing audit documentation.
Compare Back-to-back Vulnerability Scans
SNow
Classification: RespondState: PublishedCategory: Applications
Regularly compare the results from back-to-back vulnerability scans to verify that vulnerabilities have been remediated in a timely manner.
Compare actual Information Technology costs to forecasted Information Technology budgets.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Compare actual Information Technology costs to forecasted Information Technology budgets.
Compare system performance metrics to organizational standards and industry benchmarks.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Compare system performance metrics to organizational standards and industry benchmarks.
Compile the event logs of multiple components into a system-wide time-correlated audit trail.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Compile the event logs of multiple components into a system-wide time-correlated audit trail.
Compliance Assessment with Internal Controls for Financial Reporting (ICFR)
SNow
State: PublishedCategory: Uncategorized
Compliance with China Privacy & Cybersecurity Regulations
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
China publishes CSL (Cyber Security Law), DSL (Data Security Law) and PIPL (Personal Information Protection Law) and the relevant regulations and demands are rapidly evolving. Given the law is broad in nature, the expectation of this control is that you involve China Legal and China information Secu
Compliance with Export Control & Economic Sanctions
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Export control and economic sanctions (EC&S) requirements apply to the access to and use of software, systems, digital solutions and services across jurisdictions. These apply both to software and solutions developed by Roche as well as external hardware, software and solutions used by Roche based
Compliance with Internal Controls over Financial Reporting (ICFR)
SNow
Classification: MandatedState: PublishedCategory: Governance, Risk and Compliance
ICFR framework defines control activities to detect and prevent errors/fraud in financial reporting.
Compliance with Roche COREMAP Requirements
SNow
State: PublishedCategory: Uncategorized
Compliance with Roche eDiscovery Requirements
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Solutions containing business records (mainly document repositories, communication, and collaboration tools) are required to have the ability to: 1) preserve material that is or becomes subject to Legal/Law Hold; and 2) extract the material, if needed, in an eDiscovery-compliant format. "Material" i
Compliance with US Privacy Laws
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Projects must ensure solutions/services processing Personal Data of US residents are compliant with the requirements set forth in the applicable US national and state-level privacy laws.
Compliant Privacy Notice
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
It must be ensured that all legally required privacy information (e.g. “privacy policy”/”privacy notice” and text used for consent) is provided correctly and at the right point in time.
Computerised System Validation
SNow
State: PublishedCategory: Uncategorized
Computerised Systems Validation (CSV) ensures that new and existing GxP relevant computerized systems consistently fulfill their intended use and produce accurate and reliable results that ensure regulatory compliance, product quality and patient safety. Action: For systems delivered by Informatics
Conduct Periodic Incident Scenario Sessions for Personnel
SNow
Classification: ProtectState: PublishedCategory: Users
Plan and conduct routine incident response exercises and scenarios for the workforce involved in the incident response to maintain awareness and comfort in responding to real world threats. Exercises should test communication channels, decision making, and incident responders technical capabilities
Conduct Quality Control to ensure adherence to Information Technology policies, standards, and procedures.
SNow
Classification: DetectiveState: PublishedCategory: Leadership and high level objectives
Conduct Quality Control to ensure adherence to Information Technology policies, standards, and procedures.
Conduct Regular External and Internal Penetration Tests
SNow
Classification: DetectState: PublishedCategory: Data
Conduct regular external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit enterprise systems successfully.
Conduct a Business Impact Analysis based on the risk assessment findings in the risk assessment report.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Conduct a Business Impact Analysis based on the risk assessment findings in the risk assessment report.
Conduct a design review at each milestone or quality gate.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Conduct a design review at each milestone or quality gate.
Conduct a management level post implementation review.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Conduct a management level post implementation review.
Conduct a performance review of the external auditor's performance during the audit process.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Conduct a performance review of the external auditor's performance during the audit process.
Conduct a post implementation review when the system design project ends.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Conduct a post implementation review when the system design project ends.
Conduct a preliminary investigation before new system development projects begin.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Conduct a preliminary investigation before new system development projects begin.
Conduct a risk assessment to determine operational risks as a part of the acquisition feasibility study.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Conduct a risk assessment to determine operational risks as a part of the acquisition feasibility study.
Conduct a wireless site survey to determine the proper location for Wireless Access Points.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Conduct a wireless site survey to determine the proper location for Wireless Access Points.
Conduct all parts of the supply chain due diligence process.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Conduct all parts of the supply chain due diligence process.
Conduct an acquisition feasibility study prior to acquiring Information Technology assets.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Conduct an acquisition feasibility study prior to acquiring Information Technology assets.
Conduct application security reviews, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Conduct application security reviews, as necessary.
Conduct cross-training or staff backup training to minimize dependency on critical individuals.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Conduct cross-training or staff backup training to minimize dependency on critical individuals.
Conduct maintenance with authorized personnel.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Conduct maintenance with authorized personnel.
Conduct secure coding and development training for developers.
SNow
Classification: CorrectiveState: PublishedCategory: Human Resources management
Conduct secure coding and development training for developers.
Conduct staff performance reviews, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Conduct staff performance reviews, as necessary.
Conduct tests and evaluate training.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Conduct tests and evaluate training.
Confidentiality Disclaimer at Login
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Roche systems containing business critical, C3/C4, sensitive personal data intended for internal use must present a confidentiality disclaimer to users when storing or processing Roche business critical data.
Configure Anti-Malware Scanning of Removable Devices
SNow
Classification: DetectState: PublishedCategory: Devices
Most AVs have this capability turned on by default, but it’s still important to verify that it’s actually still enabled. Malware coming in via a USB stick is a viable attack vector for nearly every organization.
Configure Centralized Point of Authentication
SNow
Classification: ProtectState: PublishedCategory: Users
Configure access for all accounts through as few centralized points of authentication as possible, including network, security, and cloud systems.
Configure Devices Not To Auto-run Content
SNow
Classification: ProtectState: PublishedCategory: Devices
For the same reason why you do not want to scan it, you also don’t want it to run when it’s mounted. This is a pretty quick setting to enable, and both CIS and DISA hardening guides have step-by-step instructions on disabling auto-run. Some SCM tools can quickly check every endpoint in your environm
Configure Monitoring Systems to Record Network Packets
SNow
Classification: DetectState: PublishedCategory: Network
Configure monitoring systems to record network packets passing through the boundary at each of the organization's network boundaries.
Configure Network Access and Control Components to protect restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Configure Network Access and Control Components to protect restricted data or restricted information.
Configure Session Configuration settings in accordance with organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure Session Configuration settings in accordance with organizational standards.
Configure System Integrity settings in accordance with organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure System Integrity settings in accordance with organizational standards.
Configure accounts with administrative privilege.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure accounts with administrative privilege.
Configure additional custom Wireless Access Points, Intrusion Detection System and Intrusion Prevention System settings in accordance with organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure additional custom Wireless Access Points, Intrusion Detection System and Intrusion Prevention System settings in accordance with organizational standards.
Configure additional log settings.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure additional log settings.
Configure automatic logout to terminate sessions based on inactivity according to organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure automatic logout to terminate sessions based on inactivity according to organizational standards.
Configure each user's authentication mechanism (system attribute) properly.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure each user's authentication mechanism (system attribute) properly.
Configure firewalls to deny all traffic by default, except explicitly designated traffic.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Configure firewalls to deny all traffic by default, except explicitly designated traffic.
Configure mobile environment Portable Electronic Device settings in accordance with organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure mobile environment Portable Electronic Device settings in accordance with organizational standards.
Configure passwords so that group passwords or shared passwords are prohibited.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure passwords so that group passwords or shared passwords are prohibited.
Configure passwords so that users will change their passwords on a regular basis.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure passwords so that users will change their passwords on a regular basis.
Configure passwords to comply with organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure passwords to comply with organizational standards.
Configure sufficient log storage capacity, and configure the system to prevent the capacity from being exceeded.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure sufficient log storage capacity, and configure the system to prevent the capacity from being exceeded.
Configure system accounting/system events.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure system accounting/system events.
Configure system clocks for synchronization (SYN) of time to an accurate and universal time source, preferably an organizational Network Time Protocol (NTP) server.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure system clocks for synchronization (SYN) of time to an accurate and universal time source, preferably an organizational Network Time Protocol (NTP) server.
Configure the "Turn off AutoPlay" setting.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the "Turn off AutoPlay" setting.
Configure the "require new users to change their password on first logon" password setting to organizations standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the "require new users to change their password on first logon" password setting to organizations standards.
Configure the Access Control List to restrict connections between untrusted networks and any system that holds restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the Access Control List to restrict connections between untrusted networks and any system that holds restricted data or restricted information.
Configure the Lockout duration to a predefined time period.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the Lockout duration to a predefined time period.
Configure the Password Complexity setting.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the Password Complexity setting.
Configure the Password history setting so that users cannot submit a new password that is the same as the previous few used.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the Password history setting so that users cannot submit a new password that is the same as the previous few used.
Configure the Password length to the least allowable.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the Password length to the least allowable.
Configure the Wireless Access Point transmit power setting to the lowest level possible.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the Wireless Access Point transmit power setting to the lowest level possible.
Configure the account lockout duration to organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the account lockout duration to organizational standards.
Configure the alternate facility to meet the least needed operational capabilities.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Configure the alternate facility to meet the least needed operational capabilities.
Configure the amount of idle time required before disconnecting an idle session.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the amount of idle time required before disconnecting an idle session.
Configure the detailed data elements to be captured for all logs so that events are identified by type, location, subject, user, what data was accessed, etc.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the detailed data elements to be captured for all logs so that events are identified by type, location, subject, user, what data was accessed, etc.
Configure the log settings for specific Operating System functions.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log settings for specific Operating System functions.
Configure the log to capture Object access to key directories or key files.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture Object access to key directories or key files.
Configure the log to capture access to restricted data or restricted information.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture access to restricted data or restricted information.
Configure the log to capture actions taken by individuals with root privileges or administrative privileges and add logging option to the root file system.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture actions taken by individuals with root privileges or administrative privileges and add logging option to the root file system.
Configure the log to capture all access to the audit trail.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture all access to the audit trail.
Configure the log to capture audit log initialization, along with auditable event selection.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture audit log initialization, along with auditable event selection.
Configure the log to capture both access and access attempts to security-relevant objects and security-relevant directories.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture both access and access attempts to security-relevant objects and security-relevant directories.
Configure the log to capture changes to User privileges, audit policies, and trust policies by enabling audit policy changes.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture changes to User privileges, audit policies, and trust policies by enabling audit policy changes.
Configure the log to capture configuration changes.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture configuration changes.
Configure the log to capture each auditable event's origination.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture each auditable event's origination.
Configure the log to capture each event's success or failure indication.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture each event's success or failure indication.
Configure the log to capture hardware access attempts and software access attempts.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture hardware access attempts and software access attempts.
Configure the log to capture identification and authentication mechanism use.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture identification and authentication mechanism use.
Configure the log to capture logons, logouts, logon attempts, and logout attempts.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture logons, logouts, logon attempts, and logout attempts.
Configure the log to capture remote access information.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture remote access information.
Configure the log to capture successful hardware and software access.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture successful hardware and software access.
Configure the log to capture system level object creation and deletion.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture system level object creation and deletion.
Configure the log to capture the type of each event.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture the type of each event.
Configure the log to capture the user's identification information.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture the user's identification information.
Configure the log to capture user authenticator changes.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Configure the log to capture user authenticator changes.
Configure the log to contain a timestamp.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to contain a timestamp.
Configure the log to send alerts for each auditable events success or failure.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to send alerts for each auditable events success or failure.
Configure the log to track date entries and time entries.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to track date entries and time entries.
Configure the log to uniquely identify each asset.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the log to uniquely identify each asset.
Configure the maximum password age.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the maximum password age.
Configure the minimum password age.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the minimum password age.
Configure the network to limit zone transfers to trusted servers.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Configure the network to limit zone transfers to trusted servers.
Configure the off-site electronic media storage facilities to utilize timely and effective recovery operations.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Configure the off-site electronic media storage facilities to utilize timely and effective recovery operations.
Configure the password policy to ban or allow passwords as words found in dictionaries as appropriate.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the password policy to ban or allow passwords as words found in dictionaries as appropriate.
Configure the secure name/address resolution service (authoritative source).
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Configure the secure name/address resolution service (authoritative source).
Configure the secure name/address resolution service (recursive or caching resolver).
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Configure the secure name/address resolution service (recursive or caching resolver).
Configure the security parameters for all logs.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the security parameters for all logs.
Configure the storage parameters for all logs.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the storage parameters for all logs.
Configure the system account settings and the permission settings in accordance with the organizational access control policies.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system account settings and the permission settings in accordance with the organizational access control policies.
Configure the system logon banner contents.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system logon banner contents.
Configure the system security parameters to prevent system misuse or information misappropriation.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system security parameters to prevent system misuse or information misappropriation.
Configure the system to encrypt passwords.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system to encrypt passwords.
Configure the system to lock out User IDs after not more than a predefined number of access attempts.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system to lock out User IDs after not more than a predefined number of access attempts.
Configure the system to log all access attempts to all systems.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system to log all access attempts to all systems.
Configure the system to prevent unencrypted password use.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system to prevent unencrypted password use.
Configure the system to require a password before it unlocks the Screen saver.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system to require a password before it unlocks the Screen saver.
Configure the system to use asterisks to mask passwords.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the system to use asterisks to mask passwords.
Configure the test environment similar to the production environment.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Configure the test environment similar to the production environment.
Configure the time server in accordance with organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the time server in accordance with organizational standards.
Configure the time server to synchronize with specifically designated hosts.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the time server to synchronize with specifically designated hosts.
Configure the user account expiration date.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure the user account expiration date.
Configure user accounts.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Configure user accounts.
Connect the Public Key Infrastructure to the organization's identity and access management system.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Connect the Public Key Infrastructure to the organization's identity and access management system.
Constrain the information flow of restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Constrain the information flow of restricted data or restricted information.
Consult with Procurement for Contractual Requirements
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Consultation with procurement to establish the applicable contractual requirements necessary to ensure the adequate protection of Roche confidential data and legal compliance with the processing of personal data.
Contain the incident to prevent further loss and preserve the system for forensic analysis.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Contain the incident to prevent further loss and preserve the system for forensic analysis.
Continuous Vulnerability Management
SNow
Classification: DetectState: PublishedCategory: Applications
Continuously acquire, assess, and take action on new information in order to identify vulnerabilities, remediate, and minimize the window of opportunity for attackers.
Control access to restricted storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Control access to restricted storage media.
Control all methods of remote access and teleworking.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Control all methods of remote access and teleworking.
Control and Monitor Accounts Associated with Penetration Testing
SNow
Classification: DetectState: PublishedCategory: Users
Any user or system accounts used to perform penetration testing should be controlled and monitored to make sure they are only being used for legitimate purposes, and are removed or restored to normal function after testing is over.
Control and monitor all maintenance tools.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Control and monitor all maintenance tools.
Control cryptographic keys with split knowledge and dual control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Control cryptographic keys with split knowledge and dual control.
Control data elements that contain any password, Personal Identification Number, or Card Security Code as restricted data.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Control data elements that contain any password, Personal Identification Number, or Card Security Code as restricted data.
Control error handling during data input.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Control error handling during data input.
Control physical access to network cables.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Control physical access to network cables.
Control remote access through a network access control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Control remote access through a network access control.
Control remote maintenance according to the system's asset classification.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Control remote maintenance according to the system's asset classification.
Control the addition and modification of User IDs, credentials, or other object identifiers.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Control the addition and modification of User IDs, credentials, or other object identifiers.
Control the delivery of assets through physical entry points and physical exit points.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Control the delivery of assets through physical entry points and physical exit points.
Control the removal of assets through physical entry points and physical exit points.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Control the removal of assets through physical entry points and physical exit points.
Control the storage of restricted storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Control the storage of restricted storage media.
Control the transiting and internal distribution or external distribution of restricted storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Control the transiting and internal distribution or external distribution of restricted storage media.
Control user privileges.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Control user privileges.
Controlled Access Based on the Need to Know
SNow
Classification: ProtectState: PublishedCategory: Network
The processes and tools used to track/control/prevent/correct secure access to critical assets (e.g., information, resources, systems) according to the formal determination of which persons, computers, and applications have a need and right to access these critical assets based on an approved classi
Controlled Use of Administrative Privileges
SNow
Classification: DetectState: PublishedCategory: Users
The processes and tools used to track/control/prevent/correct the use, assignment, and configuration of administrative privileges on computers, networks, and applications.
Coordinate backup procedures as defined in the system continuity plan with backup procedures necessary for incident response procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Coordinate backup procedures as defined in the system continuity plan with backup procedures necessary for incident response procedures.
Coordinate testing the continuity plan with all applicable business units and critical business functions.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Coordinate testing the continuity plan with all applicable business units and critical business functions.
Copy logs from all predefined hosts onto a log management infrastructure.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Copy logs from all predefined hosts onto a log management infrastructure.
Correct all found deficiencies according to organizational standards after a web application policy compliance review.
SNow
Classification: CorrectiveState: PublishedCategory: Technical security
Correct all found deficiencies according to organizational standards after a web application policy compliance review.
Correct code anomalies and code deficiencies in custom code and retest before release.
SNow
Classification: CorrectiveState: PublishedCategory: Systems design, build, and implementation
Correct code anomalies and code deficiencies in custom code and retest before release.
Correct vulnerabilities and repeat penetration testing.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Correct vulnerabilities and repeat penetration testing.
Correct vulnerabilities and repeat vulnerability scanning.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Correct vulnerabilities and repeat vulnerability scanning.
Correlate the Acceptable Use Policy with the approved product list.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Correlate the Acceptable Use Policy with the approved product list.
Correlate the business impact of identified risks in the risk assessment report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Correlate the business impact of identified risks in the risk assessment report.
Create Incident Scoring and Prioritization Schema
SNow
Classification: ProtectState: PublishedCategory: Users
Create incident scoring and prioritization schema based on known or potential impact to your organization. Utilize score to define frequency of status updates and escalation procedures.
Create Separate Wireless Network for Personal and Untrusted Devices
SNow
Classification: ProtectState: PublishedCategory: Network
Create a separate wireless network for personal or untrusted devices. Enterprise access from this network should be treated as untrusted and filtered and audited accordingly.
Create Test Bed for Elements Not Typically Tested in Production
SNow
Classification: DetectState: PublishedCategory: Applications/Network
Create a test bed that mimics a production environment for specific penetration tests and Red Team attacks against elements that are not typically tested in production, such as attacks against supervisory control and data acquisition and other control systems.
Create a baseline configuration document before releasing the system into a production environment.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Create a baseline configuration document before releasing the system into a production environment.
Create a plan of action to correct control deficiencies identified in an audit.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Create a plan of action to correct control deficiencies identified in an audit.
Create a secure system image of the baseline configuration to be used for building new systems.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Create a secure system image of the baseline configuration to be used for building new systems.
Create an access control list on Network Access and Control Components to restrict access.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Create an access control list on Network Access and Control Components to restrict access.
Create specific test plans to test each system component.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Create specific test plans to test each system component.
Create/maintain System Documentation
SNow
State: PublishedCategory: Periodic Review
All lifecycle deliverables/artefacts are documented.
Cross Border Transfers
SNow
State: PublishedCategory: Uncategorized
In the event personal data is transferred to another country, the data transfers must be mapped in the RoPA Questionnaire and you must ensure compliance with the obligations regarding cross border data transfers.
Cybersecurity Risks should be identified for the manufacturing system and mitigation activities should be planned including owner, required activities and due date.
SNow
Classification: IdentifyState: PublishedCategory: Vulnerability and Configuration Analysis
Cybersecurity Risks should be identified for the manufacturing system and mitigation activities should be planned including owner, required activities and due date.
DCS-01 Off-Site Equipment Disposal Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible mus
DCS-02 Off-Site Transfer Authorization Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable autho
DCS-03 Secure Area Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.
DCS-04 Secure Media Transportation Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.
DCS-05 Assets Classification
SNow
State: PublishedCategory: Uncategorized
Classify and document the physical, and logical assets (e.g., applications) based on the organizational business risk.
DCS-06 Assets Cataloguing and Tracking
SNow
State: PublishedCategory: Uncategorized
Catalogue and track all relevant physical and logical assets located at all of the CSP's sites within a secured system.
DCS-07 Controlled Access Points
SNow
State: PublishedCategory: Uncategorized
Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.
DCS-08 Equipment Identification
SNow
State: PublishedCategory: Uncategorized
Use equipment identification as a method for connection authentication.
DCS-09 Secure Area Authorization
SNow
State: PublishedCategory: Uncategorized
Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.
DCS-10 Surveillance System
SNow
State: PublishedCategory: Uncategorized
Implement, maintain, and operate datacenter surveillance systems at the external perimeter and at all the ingress and egress points to detect unauthorized ingress and egress attempts.
DCS-11 Unauthorized Access Response Training
SNow
State: PublishedCategory: Uncategorized
Train datacenter personnel to respond to unauthorized ingress or egress attempts.
DCS-12 Cabling Security
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures that ensure a risk-based protection of power and telecommunication cables from a threat of interception, interference or damage at all facilities, offices and rooms.
DCS-13 Environmental Systems
SNow
State: PublishedCategory: Uncategorized
Implement and maintain data center environmental control systems that monitor, maintain and test for continual effectiveness the temperature and humidity conditions within accepted industry standards.
DCS-14 Secure Utilities
SNow
State: PublishedCategory: Uncategorized
Secure, monitor, maintain, and test utilities services for continual effectiveness at planned intervals.
DCS-15 Equipment Location
SNow
State: PublishedCategory: Uncategorized
Keep business-critical equipment away from locations subject to high probability for environmental risk events.
DSP-01 Security and Privacy Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and proced
DSP-02 Secure Disposal
SNow
State: PublishedCategory: Uncategorized
Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.
DSP-03 Data Inventory
SNow
State: PublishedCategory: Uncategorized
Create and maintain a data inventory, at least for any sensitive data and personal data.
DSP-04 Data Classification
SNow
State: PublishedCategory: Uncategorized
Classify data according to its type and sensitivity level.
DSP-05 Data Flow Documentation
SNow
State: PublishedCategory: Uncategorized
Create data flow documentation to identify what data is processed, stored or transmitted where. Review data flow documentation at defined intervals, at least annually, and after any change.
DSP-06 Data Ownership and Stewardship
SNow
State: PublishedCategory: Uncategorized
Document ownership and stewardship of all relevant documented personal and sensitive data. Perform review at least annually.
DSP-07 Data Protection by Design and Default
SNow
State: PublishedCategory: Uncategorized
Develop systems, products, and business practices based upon a principle of security by design and industry best practices.
DSP-08 Data Privacy by Design and Default
SNow
State: PublishedCategory: Uncategorized
Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.
DSP-09 Data Protection Impact Assessment
SNow
State: PublishedCategory: Uncategorized
Conduct a Data Protection Impact Assessment (DPIA) to evaluate the origin, nature, particularity and severity of the risks upon the processing of personal data, according to any applicable laws, regulations and industry best practices.
DSP-10 Sensitive Data Transfer
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.
DSP-11 Personal Data Access, Reversal, Rectification and Deletion
SNow
State: PublishedCategory: Uncategorized
Define and implement, processes, procedures and technical measures to enable data subjects to request access to, modification, or deletion of their personal data, according to any applicable laws and regulations.
DSP-12 Limitation of Purpose in Personal Data Processing
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to ensure that personal data is processed according to any applicable laws and regulations and for the purposes declared to the data subject.
DSP-13 Personal Data Sub-processing
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for the transfer and sub-processing of personal data within the service supply chain, according to any applicable laws and regulations.
DSP-14 Disclosure of Data Sub-processors
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to disclose the details of any personal or sensitive data access by sub-processors to the data owner prior to initiation of that processing.
DSP-15 Limitation of Production Data Use
SNow
State: PublishedCategory: Uncategorized
Obtain authorization from data owners, and manage associated risk before replicating or using production data in non-production environments.
DSP-16 Data Retention and Deletion
SNow
State: PublishedCategory: Uncategorized
Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.
DSP-17 Sensitive Data Protection
SNow
State: PublishedCategory: Uncategorized
Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
DSP-18 Disclosure Notification
SNow
State: PublishedCategory: Uncategorized
The CSP must have in place, and describe to CSCs the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations. The CSP must give special attention to the notification procedure to interested CSCs, unless o
DSP-19 Data Location
SNow
State: PublishedCategory: Uncategorized
Define and implement, processes, procedures and technical measures to specify and document the physical locations of data, including any locations in which data is processed or backed up.
Data Accuracy
SNow
State: PublishedCategory: Uncategorized
Personal data must be accurate and kept up-to-date. Describe the processes you have in place to ensure that personal information is attributed to the correct individual and is accurate, complete, and up-to-date.
Data Breach
SNow
State: PublishedCategory: Uncategorized
Data security breaches must be detected, reported, and managed. Describe how do you detect, report and manage data security breaches.
Data Minimization
SNow
State: PublishedCategory: Uncategorized
Data Minimization requires that personal data shall be adequate, relevant, and limited to what is necessary for the purposes of processing. Define the minimization controls.
Data Protection Impact Assessment Required
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
As required by the EU General Data Protection Regulation (GDPR), a Data Protection Impact Assessment (DPIA) report must be created to identify and minimise the data protection risks.
Data Recovery Capabilities
SNow
Classification: ProtectState: PublishedCategory: Data
The processes and tools used to properly back up critical information with a proven methodology for timely recovery of it.
Data Subject Rights
SNow
State: PublishedCategory: Uncategorized
Personal Data needs to be erased, corrected, retrievable and/or access restricted or blocked upon request. Describe how do you ensure execution of data subject rights.
Database Auditing
SNow
Classification: DetectiveState: PublishedCategory: SAP Application Security
A dedicated third party application (Imperva) monitoring the database layer for non-legitimate activities performed by high privilege accounts (i.e. DB admins). Outsourcing high privilege access authorization to externals requires a detective control at least. (ICFR, GDPR).
Decrypt Network Traffic at Proxy
SNow
Classification: DetectState: PublishedCategory: Network
Decrypt all encrypted network traffic at the boundary proxy prior to analyzing the content. However, the organization may use whitelists of allowed sites that can be accessed through the proxy without decrypting the traffic.
Define Backup & Restore procedures
SNow
State: PublishedCategory: Periodic Review
Documented Backup & Restore procedures exist and are tested on a regular basis.
Define Data Archiving
SNow
State: PublishedCategory: Periodic Review
Process for accessing and retrieving of archived data exists (if required). NOTE: only applicable if data from this system is archived into an archive.
Define Disaster Recovery (if applicable)
SNow
State: PublishedCategory: Periodic Review
Documented Disaster Recovery procedures exist and are tested/exercised on a regular basis.
Define Key Roles
SNow
State: PublishedCategory: Periodic Review
All key roles and responsiblities for the system are defined and assigned and are trained in the relevant CSV procedures. Key roles: - Business Process Owner - System Owner
Define Service Agreements
SNow
State: PublishedCategory: Periodic Review
Adequate Service Agreements are established with internal and external suppliers.
Define Training Requirements
SNow
State: PublishedCategory: Periodic Review
Training Requirements for the users prior to system access are defined
Define and assign the external auditor's roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Define and assign the external auditor's roles and responsibilities.
Define and assign the system development project team roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Define and assign the system development project team roles and responsibilities.
Define and document the nature and scope of all new system development projects.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Define and document the nature and scope of all new system development projects.
Define and prioritize critical business functions.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Define and prioritize critical business functions.
Define applicable operational support processes & procedures
SNow
State: PublishedCategory: Periodic Review
The applicable operational support processes & procedures are defined in the Validation/Qualification Registry and/or the Operational Support Plan
Define each system's disposition requirements for records and logs.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Define each system's disposition requirements for records and logs.
Define each system's preservation requirements for records and logs.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Define each system's preservation requirements for records and logs.
Define personal data that falls under breach notification rules.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Define personal data that falls under breach notification rules.
Define the Information Assurance strategic roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Define the Information Assurance strategic roles and responsibilities.
Define the cryptographic module security functions and the cryptographic module operational modes.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Define the cryptographic module security functions and the cryptographic module operational modes.
Define the frequency to capture and log events.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Define the frequency to capture and log events.
Define the roles and responsibilities for personnel assigned to tasks in the Audit function.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Define the roles and responsibilities for personnel assigned to tasks in the Audit function.
Degauss as a method of sanitizing electronic storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Degauss as a method of sanitizing electronic storage media.
Deliver Training to Fill the Skills Gap
SNow
Classification: ProtectState: PublishedCategory: Users
Deliver training to address the skills gap identified to positively impact workforce members' security behavior.
Deny Communication over Unauthorized Ports
SNow
Classification: ProtectState: PublishedCategory: Network
Deny communication over unauthorized TCP or UDP ports or application traffic to ensure that only authorized protocols are allowed to cross the network boundary in or out of the network at each of the organization's network boundaries.
Deny Communications with Known Malicious IP Addresses
SNow
Classification: ProtectState: PublishedCategory: Network
Deny communications with known malicious or unused Internet IP addresses and limit access only to trusted and necessary IP address ranges at each of the organization's network boundaries,.
Deny access to restricted data or restricted information when an individual is terminated.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Deny access to restricted data or restricted information when an individual is terminated.
Deploy Application Layer Filtering Proxy Server
SNow
Classification: DetectState: PublishedCategory: Network
Ensure that all network traffic to or from the Internet passes through an authenticated application layer proxy that is configured to filter unauthorized connections.
Deploy Automated Operating System Patch Management Tools
SNow
Classification: ProtectState: PublishedCategory: Applications
Deploy automated software update tools in order to ensure that the operating systems are running the most recent security updates provided by the software vendor.
Deploy Automated Software Patch Management Tools
SNow
Classification: ProtectState: PublishedCategory: Applications
Deploy automated software update tools in order to ensure that third-party software on all systems is running the most recent security updates provided by the software vendor.
Deploy NetFlow Collection on Networking Boundary Devices
SNow
Classification: DetectState: PublishedCategory: Network
Enable the collection of NetFlow and logging data on all network boundary devices.
Deploy Network-Based Intrusion Prevention Systems
SNow
Classification: ProtectState: PublishedCategory: Network
Deploy network-based Intrusion Prevention Systems (IPS) to block malicious network traffic at each of the organization's network boundaries.
Deploy Network-based IDS Sensor
SNow
Classification: DetectState: PublishedCategory: Network
Deploy network-based Intrusion Detection Systems (IDS) sensors to look for unusual attack mechanisms and detect compromise of these systems at each of the organization's network boundaries.
Deploy Port Level Access Control
SNow
Classification: ProtectState: PublishedCategory: Devices
Utilize port level access control, following 802.1x standards, to control which devices can authenticate to the network. The authentication system shall be tied into the hardware asset inventory data to ensure only authorized devices can connect to the network.
Deploy SIEM or Log Analytic tool
SNow
Classification: DetectState: PublishedCategory: Network
Deploy Security Information and Event Management (SIEM) or log analytic tool for log correlation and analysis.
Deploy System Configuration Management Tools
SNow
Classification: ProtectState: PublishedCategory: Applications
Deploy system configuration management tools that will automatically enforce and redeploy configuration settings to systems at regularly scheduled intervals.
Deploy Web Application Firewalls (WAFs)
SNow
Classification: ProtectState: PublishedCategory: Network
Protect web applications by deploying web application firewalls (WAFs) that inspect all traffic flowing to the web application for common web application attacks. For applications that are not web-based, specific application firewalls should be deployed if such tools are available for the given appl
Deploy software patches.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Deploy software patches.
Design demilitarized zones with proper isolation rules.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Design demilitarized zones with proper isolation rules.
Design the Information Technology facility with a low profile and consideration given to natural disasters and man-made disasters.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Design the Information Technology facility with a low profile and consideration given to natural disasters and man-made disasters.
Design the security architecture.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Design the security architecture.
Designate Management Personnel to Support Incident Handling
SNow
Classification: ProtectState: PublishedCategory: Users
Designate management personnel, as well as backups, who will support the incident handling process by acting in key decision-making roles.
Designate an alternate facility in the continuity plan.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Designate an alternate facility in the continuity plan.
Destroy cryptographic keys promptly after the retention period.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Destroy cryptographic keys promptly after the retention period.
Destroy electronic storage media following the storage media disposition and destruction procedures.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Destroy electronic storage media following the storage media disposition and destruction procedures.
Detect Wireless Access Points Connected to the Wired Network
SNow
Classification: DetectState: PublishedCategory: Network
Configure network vulnerability scanning tools to detect and alert on unauthorized wireless access points connected to the wired network.
Detect unauthorized access to systems.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Detect unauthorized access to systems.
Determine any errors or material omissions in the audit assertion that affect in scope control implementations.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Determine any errors or material omissions in the audit assertion that affect in scope control implementations.
Determine how long to keep records and logs before disposing them.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Determine how long to keep records and logs before disposing them.
Determine if honeypots should be installed, and if so, where the honeypots should be placed.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Determine if honeypots should be installed, and if so, where the honeypots should be placed.
Determine if the audit assertion's in scope controls are reasonable.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Determine if the audit assertion's in scope controls are reasonable.
Determine if the audit assertion's in scope procedures are accurately documented.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Determine if the audit assertion's in scope procedures are accurately documented.
Determine if the in scope system has been implemented as described in the audit assertion.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Determine if the in scope system has been implemented as described in the audit assertion.
Determine the accurateness of the audit assertion's in scope system description.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Determine the accurateness of the audit assertion's in scope system description.
Determine the appropriate assessment method for each testing process in the test plan.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Determine the appropriate assessment method for each testing process in the test plan.
Determine the effectiveness of in scope controls.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Determine the effectiveness of in scope controls.
Determine the effectiveness of risk control measures.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Determine the effectiveness of risk control measures.
Determine the implementation status of the audit assertion's in scope controls.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Determine the implementation status of the audit assertion's in scope controls.
Develop and implement a content filtering word and phrase library.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Develop and implement a content filtering word and phrase library.
Develop and maintain an archive of maintenance reports in a maintenance log.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Develop and maintain an archive of maintenance reports in a maintenance log.
Develop new products based on Best Practices.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Develop new products based on Best Practices.
Develop new products based on secure coding techniques.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Develop new products based on secure coding techniques.
Develop organizational measures to limit data leakage.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Develop organizational measures to limit data leakage.
Develop remedies and sanctions for privacy policy violations.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Develop remedies and sanctions for privacy policy violations.
Develop systems in accordance with the system design specifications and system design standards.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Develop systems in accordance with the system design specifications and system design standards.
Devise Organization-wide Standards for Reporting Incidents
SNow
Classification: ProtectState: PublishedCategory: Users
Devise organization-wide standards for the time required for system administrators and other workforce members to report anomalous events to the incident handling team, the mechanisms for such reporting, and the kind of information that should be included in the incident notification.
Disable Any Unassociated Accounts
SNow
Classification: ProtectState: PublishedCategory: Users
Disable any account that cannot be associated with a business process or business owner.
Disable CD Autorun.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable CD Autorun.
Disable DHCP Server unless DHCP Server is absolutely necessary.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable DHCP Server unless DHCP Server is absolutely necessary.
Disable Dormant Accounts
SNow
Classification: ProtectState: PublishedCategory: Users
Automatically disable dormant accounts after a set period of inactivity.
Disable Internet Protocol version 6 unless it is absolutely necessary.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable Internet Protocol version 6 unless it is absolutely necessary.
Disable Peer-to-peer Wireless Network Capabilities on Wireless Clients
SNow
Classification: ProtectState: PublishedCategory: Devices
Disable peer-to-peer (adhoc) wireless network capabilities on wireless clients.
Disable Unnecessary or Unauthorized Browser or Email Client Plugins
SNow
Classification: ProtectState: PublishedCategory: Applications
Uninstall or disable any unauthorized browser or email client plugins or add-on applications.
Disable Wireless Access on Devices if Not Required
SNow
Classification: ProtectState: PublishedCategory: Devices
Disable wireless access on devices that do not have a business purpose for wireless access.
Disable Wireless Peripheral Access of Devices
SNow
Classification: ProtectState: PublishedCategory: Devices
Disable wireless peripheral access of devices (such as Bluetooth and NFC), unless such access is required for a business purpose.
Disable Workstation to Workstation Communication
SNow
Classification: ProtectState: PublishedCategory: Network
Disable all workstation to workstation communication to limit an attacker's ability to move laterally and compromise neighboring systems, through technologies such as Private VLANs or microsegmentation.
Disable all unnecessary User IDs.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable all unnecessary User IDs.
Disable all unnecessary applications unless otherwise noted in a policy exception.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable all unnecessary applications unless otherwise noted in a policy exception.
Disable all unnecessary hardware and unnecessary physical interfaces.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable all unnecessary hardware and unnecessary physical interfaces.
Disable all unnecessary services unless otherwise noted in a policy exception.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable all unnecessary services unless otherwise noted in a policy exception.
Disable the use of removable storage media for systems that processes restricted data or restricted information, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Disable the use of removable storage media for systems that processes restricted data or restricted information, as necessary.
Disable unnecessary applications, ports, and protocols on Wireless Access Points.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Disable unnecessary applications, ports, and protocols on Wireless Access Points.
Disallow remote users from copying files to remote devices.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Disallow remote users from copying files to remote devices.
Disassemble and shut down unnecessary systems or unused systems.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Disassemble and shut down unnecessary systems or unused systems.
Disclose any audit irregularities in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Disclose any audit irregularities in the audit report.
Display a logon banner and appropriate logon message before granting access to the system.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Display a logon banner and appropriate logon message before granting access to the system.
Display or print the least amount of personal data necessary.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Display or print the least amount of personal data necessary.
Dispose of data and information in a timely manner.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Dispose of data and information in a timely manner.
Dispose of hardware and software at their life cycle end.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Dispose of hardware and software at their life cycle end.
Disseminate and communicate the Governance, Risk, and Compliance framework to all interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Disseminate and communicate the Governance, Risk, and Compliance framework to all interested personnel and affected parties.
Disseminate the Access Control policy to all affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Disseminate the Access Control policy to all affected parties.
Distribute User IDs and passwords using secure communication protocols.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Distribute User IDs and passwords using secure communication protocols.
Distribute cryptographic keys securely.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Distribute cryptographic keys securely.
Distribute the approved risk assessment report to interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Distribute the approved risk assessment report to interested personnel and affected parties.
Distribute the continuity plan to interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Distribute the continuity plan to interested personnel and affected parties.
Distribute the incident response procedures to all interested personnel and affected parties.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Distribute the incident response procedures to all interested personnel and affected parties.
Distribute the reviews of audit reports to organizational management.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Distribute the reviews of audit reports to organizational management.
Do not allow user access to identifiers and passwords used by applications.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Do not allow user access to identifiers and passwords used by applications.
Do not rely solely on Wired Equivalent Privacy encryption for Wireless Local Area Networks.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Do not rely solely on Wired Equivalent Privacy encryption for Wireless Local Area Networks.
Document Incident Response Procedures
SNow
Classification: ProtectState: PublishedCategory: Data
Ensure that there are written incident response plans that defines roles of personnel as well as phases of incident handling/management.
Document Traffic Configuration Rules
SNow
Classification: IdentifyState: PublishedCategory: Network
All configuration rules that allow traffic to flow through network devices should be documented in a configuration management system with a specific business reason for each rule, a specific individual’s name responsible for that business need, and an expected duration of the need.
Document all change requests in change request forms.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Document all change requests in change request forms.
Document all training in a training record.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Document all training in a training record.
Document and communicate a corrective action plan based on the risk assessment findings.
SNow
Classification: CorrectiveState: PublishedCategory: Audits and risk management
Document and communicate a corrective action plan based on the risk assessment findings.
Document and communicate role descriptions to all applicable personnel.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Document and communicate role descriptions to all applicable personnel.
Document and justify system hardening standard exceptions.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Document and justify system hardening standard exceptions.
Document and use the lessons learned to update the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Document and use the lessons learned to update the continuity plan.
Document approved configuration deviations.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Document approved configuration deviations.
Document organizational objectives.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Document organizational objectives.
Document periodic maintenance in maintenance reports.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Document periodic maintenance in maintenance reports.
Document test plans for auditing in scope controls.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Document test plans for auditing in scope controls.
Document the backup method and backup frequency on a case-by-case basis in the backup procedures.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Document the backup method and backup frequency on a case-by-case basis in the backup procedures.
Document the continuity plan exercise test results and provide them to senior management.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Document the continuity plan exercise test results and provide them to senior management.
Document the event information to be logged in the event information log specification.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Document the event information to be logged in the event information log specification.
Document the third parties compliance with the organization's system hardening framework.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Document the third parties compliance with the organization's system hardening framework.
Document the uninterrupted power requirements for all in scope systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Document the uninterrupted power requirements for all in scope systems.
Document validated testing processes in the testing procedures.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Document validated testing processes in the testing procedures.
Documented operating procedures
SNow
State: PublishedCategory: Uncategorized
Documenting Operating Procedures and working instructions is in place to ensure effective operation of all services and shall be documented and made available to personnel who need them
Each ODC Engagement has a completed ODC Screening Assessment
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Each ODC Engagement has an ODC Manager assigned
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Each Outsorced Delivery Center has an ODC Manual in place
SNow
Classification: PreventiveState: RetiredCategory: Roche Security Standards
Edit the audit assertion for accuracy.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Edit the audit assertion for accuracy.
Employ individuals who have the appropriate staff qualifications, staff clearances, and staff competencies.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Employ individuals who have the appropriate staff qualifications, staff clearances, and staff competencies.
Employ risk assessment methodologies that take into account prior risk assessment findings of the same scope.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Employ risk assessment methodologies that take into account prior risk assessment findings of the same scope.
Employ unique user identifiers.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Employ unique user identifiers.
Enable Command-line Audit Logging
SNow
Classification: DetectState: PublishedCategory: Devices
On high interaction systems, this can be quite noisy. From a forensics standpoint, it will be quite valuable.
Enable DNS Query Logging
SNow
Classification: DetectState: PublishedCategory: Network
This is a great passive way to monitor for malware in an environment. these sensors can log all of these queries without having to pull them off of the endpoint. Looking for new DNS queries and those that look to be computer-generated will be quick wins in terms of hunting out malware infections.
Enable Detailed Logging
SNow
Classification: DetectState: PublishedCategory: Network
Enable system logging to include detailed information such as a event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.
Enable Firewall Filtering Between VLANs
SNow
Classification: ProtectState: PublishedCategory: Network
Enable firewall filtering between VLANs to ensure that only authorized systems are able to communicate with other systems necessary to fulfill their specific responsibilities.
Enable Intrusion Detection Systems and Intrusion Prevention Systems to continuously monitor and send alerts for rogue devices connected to Wireless Local Area Networks.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Enable Intrusion Detection Systems and Intrusion Prevention Systems to continuously monitor and send alerts for rogue devices connected to Wireless Local Area Networks.
Enable Network Address Translation or Port Address Translation for internal networks on all network access and control points.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable Network Address Translation or Port Address Translation for internal networks on all network access and control points.
Enable Operating System Anti-Exploitation Features/ Deploy Anti-Exploit Technologies
SNow
Classification: ProtectState: PublishedCategory: Devices
The DISA hardening guides provide step-by-step instructions on enabling these settings and so much more.
Enable WiFi Protected Access or Wi-Fi Protected Access-2.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable WiFi Protected Access or Wi-Fi Protected Access-2.
Enable access control for objects and users on each system and ensure the system's policy states the objects and users subject to access control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Enable access control for objects and users on each system and ensure the system's policy states the objects and users subject to access control.
Enable access control for objects and users to match restrictions set by the security classification.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Enable access control for objects and users to match restrictions set by the security classification.
Enable and configure auditing operations and logging operations, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable and configure auditing operations and logging operations, as necessary.
Enable and configure logging on all network access controls.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Enable and configure logging on all network access controls.
Enable data-at-rest encryption.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable data-at-rest encryption.
Enable encryption of a protected distributed system if sending restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Enable encryption of a protected distributed system if sending restricted data or restricted information.
Enable logging for all systems that meet a traceability criteria.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Enable logging for all systems that meet a traceability criteria.
Enable logon authentication management techniques.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable logon authentication management techniques.
Enable monitoring and logging operations on all assets that meet the organizational criteria to maintain event logs.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Enable monitoring and logging operations on all assets that meet the organizational criteria to maintain event logs.
Enable network jacks at the patch panel, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Enable network jacks at the patch panel, as necessary.
Enable or disable all BIOS wireless devices, as appropriate.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable or disable all BIOS wireless devices, as appropriate.
Enable or disable all wireless interfaces, as appropriate.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable or disable all wireless interfaces, as appropriate.
Enable the appropriate tunneling protocol for Internet Protocol version 6.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable the appropriate tunneling protocol for Internet Protocol version 6.
Enable the firewall and configure it to meet organizational standards.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable the firewall and configure it to meet organizational standards.
Enable two-factor authentication for identifying and authenticating Wireless Local Area Network users.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Enable two-factor authentication for identifying and authenticating Wireless Local Area Network users.
Encrypt All Sensitive Information in Transit
SNow
Classification: ProtectState: PublishedCategory: Data
Encrypt all sensitive information in transit.
Encrypt Data on USB Storage Devices
SNow
Classification: ProtectState: PublishedCategory: Data
Provide the training to employees so they are aware of the risks of data on USB drives. Then provide them with the tools to secure your organization’s critical data.
Encrypt Sensitive Information at Rest
SNow
Classification: ProtectState: PublishedCategory: Data
Encrypt all sensitive information at rest using a tool that requires a secondary authentication mechanism not integrated into the operating system, in order to access the information.
Encrypt Transmittal of Username and Authentication Credentials
SNow
Classification: ProtectState: PublishedCategory: Users
Ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels.
Encrypt backup data.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Encrypt backup data.
Encrypt files and move them to a secure file server when a user account is disabled.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Encrypt files and move them to a secure file server when a user account is disabled.
Encrypt information stored on mobile devices.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Encrypt information stored on mobile devices.
Encrypt non-console administrative access.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Encrypt non-console administrative access.
Encrypt or Hash all Authentication Credentials
SNow
Classification: ProtectState: PublishedCategory: Users
Encrypt or hash with a salt all authentication credentials when stored.
Encrypt the Hard Drive of All Mobile Devices.
SNow
Classification: ProtectState: PublishedCategory: Data
Utilize approved whole disk encryption software to encrypt the hard drive of all mobile devices.
Encrypt, truncate, or tokenize data fields as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Encrypt, truncate, or tokenize data fields as necessary.
Enforce Access Control to Data through Automated Tools
SNow
Classification: ProtectState: PublishedCategory: Data
Use an automated tool, such as host-based Data Loss Prevention, to enforce access controls to data even when data is copied off a system.
Enforce Detail Logging for Access or Changes to Sensitive Data
SNow
Classification: DetectState: PublishedCategory: Data
Enforce detailed audit logging for access to sensitive data or changes to sensitive data (utilizing tools such as File Integrity Monitoring or Security Information and Event Monitoring).
Enforce a continuous Quality Control system.
SNow
Classification: DetectiveState: PublishedCategory: Leadership and high level objectives
Enforce a continuous Quality Control system.
Enforce access restrictions for change control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Enforce access restrictions for change control.
Enforce privileged accounts and non-privileged accounts for system access and separate user functionality from system management functionality.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Enforce privileged accounts and non-privileged accounts for system access and separate user functionality from system management functionality.
Ensure All Accounts Have An Expiration Date
SNow
Classification: ProtectState: PublishedCategory: Users
Ensure that all accounts have an expiration date that is monitored and enforced.
Ensure Anti-Malware Software and Signatures are Updated
SNow
Classification: ProtectState: PublishedCategory: Devices
The AV is only as good as it’s signatures. While pure signature-based detection is no longer viable, even anomaly-based engines need to be updated on a regular basis. Ensure that the updates are rolled out automatically and use tools to verify that the signatures are actually up-to-date
Ensure Backups Have At least One Non-Continuously Addressable Destination
SNow
Classification: ProtectState: PublishedCategory: Data
Ensure that all backups have at least one backup destination that is not continuously addressable through operating system calls.
Ensure Compliance with Applicable Local Laws
SNow
Classification: MandatedState: PublishedCategory: Governance, Risk and Compliance
Projects must ensure compliance with applicable laws and regulations. Local privacy, legal and compliance roles must be adequately informed and involved in the planned rollout of solutions to local markets/countries.
Ensure Explicit Error Checking is Performed for All In-house Developed Software
SNow
Classification: ProtectState: PublishedCategory: Applications
For in-house developed software, ensure that explicit error checking is performed and documented for all input, including for size, data type, and acceptable ranges or formats.
Ensure Only Approved Ports, Protocols and Services Are Running
SNow
Classification: ProtectState: PublishedCategory: Devices
Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.
Ensure Protection of Backups
SNow
Classification: ProtectState: PublishedCategory: Data
Ensure that backups are properly protected via physical security or encryption when they are stored, as well as when they are moved across the network. This includes remote backups and cloud services.
Ensure Regular Automated Back Ups
SNow
Classification: ProtectState: PublishedCategory: Data
Ensure that all system data is automatically backed up on regular basis.
Ensure Results from Penetration Test are Documented Using Open, Machine-readable Standards
SNow
Classification: DetectState: PublishedCategory: Applications/Network
Wherever possible, ensure that Red Teams results are documented using open, machine-readable standards (e.g., SCAP). Devise a scoring method for determining the results of Red Team exercises so that results can be compared over time.
Ensure Software Development Personnel are Trained in Secure Coding
SNow
Classification: ProtectState: PublishedCategory: Users
Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities.
Ensure Software is Supported by Vendor
SNow
Classification: IdentifyState: PublishedCategory: Applications
Ensure that only software applications or operating systems currently supported by the software's vendor are added to the organization's authorized software inventory. Unsupported software should be tagged as unsupported in the inventory system.
Ensure Use of Only Fully Supported Browsers and Email Clients
SNow
Classification: ProtectState: PublishedCategory: Applications
Ensure that only fully supported web browsers and email clients are allowed to execute in the organization, ideally only using the latest version of the browsers and email clients provided by the vendor.
Ensure accounts and Electronically Stored Information are segregated from Operating System access.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Ensure accounts and Electronically Stored Information are segregated from Operating System access.
Ensure adequate storage for logs
SNow
Classification: DetectState: PublishedCategory: Network
Ensure that all systems that store logs have adequate storage space for the logs generated.
Ensure end users accept and sign the customer agreement covering access rights and user privileges before data or system access is enabled.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Ensure end users accept and sign the customer agreement covering access rights and user privileges before data or system access is enabled.
Ensure the Use of Dedicated Administrative Accounts
SNow
Classification: ProtectState: PublishedCategory: Users
Ensure that all users with administrative account access use a dedicated or secondary account for elevated activities. This account should only be used for administrative activities and not internet browsing, email, or similar activities.
Ensure vendor has an ODC Impact Assessment in complete state for the engagement
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Enter the visitor's name, visitor's organization, and acceptable access areas into the visitor log.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Enter the visitor's name, visitor's organization, and acceptable access areas into the visitor log.
Equipment Siting and Protection
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Equipment Siting and Protection
Escalate the report when the software configuration is updated absent authorization.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Escalate the report when the software configuration is updated absent authorization.
Escort uncleared personnel who need to work in or access secure areas.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Escort uncleared personnel who need to work in or access secure areas.
Escort visitors within the facility, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Escort visitors within the facility, as necessary.
Establish Process for Revoking Access
SNow
Classification: ProtectState: PublishedCategory: Users
Establish and follow an automated process for revoking system access by disabling accounts immediately upon termination or change of responsibilities of an employee or contractor . Disabling these accounts, instead of deleting accounts, allows preservation of audit trails.
Establish Secure Coding Practices
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish secure coding practices appropriate to the programming language and development environment being used.
Establish Secure Configurations
SNow
Classification: ProtectState: PublishedCategory: Applications
Maintain documented, standard security configuration standards for all authorized operating systems and software.
Establish a Penetration Testing Program
SNow
Classification: ProtectState: PublishedCategory: Data
Establish a program for penetration tests that includes a full scope of blended attacks, such as wireless, client-based, and web application attacks.
Establish a Process to Accept and Address Reports of Software Vulnerabilities
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish a process to accept and address reports of software vulnerabilities, including providing a means for external entities to contact your security group.
Establish a Root Certification Authority to support the Public Key Infrastructure.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish a Root Certification Authority to support the Public Key Infrastructure.
Establish a risk acceptance level that is appropriate to the organization's risk appetite.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Establish a risk acceptance level that is appropriate to the organization's risk appetite.
Establish access rights based on least privilege.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish access rights based on least privilege.
Establish and implement training plans.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and implement training plans.
Establish and maintain Automated Data Processing error handling reporting.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain Automated Data Processing error handling reporting.
Establish and maintain Automated Data Processing validation checks and editing checks.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain Automated Data Processing validation checks and editing checks.
Establish and maintain Information Technology asset removal procedures.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain Information Technology asset removal procedures.
Establish and maintain Information Technology staff security clearance level criteria.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain Information Technology staff security clearance level criteria.
Establish and maintain Public Key certificate application procedures.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain Public Key certificate application procedures.
Establish and maintain Recovery Time Objectives for all in scope systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain Recovery Time Objectives for all in scope systems.
Establish and maintain Service Level Agreements for all alternate facilities.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain Service Level Agreements for all alternate facilities.
Establish and maintain Service Level Agreements with the organization's supply chain.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Establish and maintain Service Level Agreements with the organization's supply chain.
Establish and maintain Voice over Internet Protocol design specification and Configuration Management criteria.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain Voice over Internet Protocol design specification and Configuration Management criteria.
Establish and maintain Voice over Internet Protocol operating procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain Voice over Internet Protocol operating procedures.
Establish and maintain a Code of Conduct as a part of the Terms and Conditions of employment.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain a Code of Conduct as a part of the Terms and Conditions of employment.
Establish and maintain a Compliance Exception standard for compliance exceptions.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a Compliance Exception standard for compliance exceptions.
Establish and maintain a Configuration Management Plan.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain a Configuration Management Plan.
Establish and maintain a Configuration Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a Configuration Management program.
Establish and maintain a Customer Information Management program.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain a Customer Information Management program.
Establish and maintain a Governance, Risk, and Compliance awareness and training program.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a Governance, Risk, and Compliance awareness and training program.
Establish and maintain a Governance, Risk, and Compliance framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a Governance, Risk, and Compliance framework.
Establish and maintain a Heating Ventilation and Air Conditioning system.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a Heating Ventilation and Air Conditioning system.
Establish and maintain a Quality Management framework.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a Quality Management framework.
Establish and maintain a Quality Management program.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a Quality Management program.
Establish and maintain a Risk Scoping and Measurement Definitions Document.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Establish and maintain a Risk Scoping and Measurement Definitions Document.
Establish and maintain a Service Level Agreement framework.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Establish and maintain a Service Level Agreement framework.
Establish and maintain a Software Change Management metrics program.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a Software Change Management metrics program.
Establish and maintain a Standard Operating Procedures Manual.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a Standard Operating Procedures Manual.
Establish and maintain a System Security Plan.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a System Security Plan.
Establish and maintain a Wireless Local Area Network Configuration Management standard and associated practices.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a Wireless Local Area Network Configuration Management standard and associated practices.
Establish and maintain a capacity management standard.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a capacity management standard.
Establish and maintain a compliance oversight committee.
SNow
Classification: DetectiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a compliance oversight committee.
Establish and maintain a configuration change log.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Establish and maintain a configuration change log.
Establish and maintain a continuous monitoring for Configuration Management program.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a continuous monitoring for Configuration Management program.
Establish and maintain a critical Information Technology resource list.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Establish and maintain a critical Information Technology resource list.
Establish and maintain a critical personnel list.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Establish and maintain a critical personnel list.
Establish and maintain a critical third party list.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain a critical third party list.
Establish and maintain a current configuration baseline based on the least functionality principle.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a current configuration baseline based on the least functionality principle.
Establish and maintain a customer service business function.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a customer service business function.
Establish and maintain a data classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a data classification scheme.
Establish and maintain a data conversion plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a data conversion plan.
Establish and maintain a data processing continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a data processing continuity plan.
Establish and maintain a data processing run manual.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a data processing run manual.
Establish and maintain a data retention program.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Establish and maintain a data retention program.
Establish and maintain a database management standard.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a database management standard.
Establish and maintain a documented list of protocols, ports, applications, and services for essential operations.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a documented list of protocols, ports, applications, and services for essential operations.
Establish and maintain a facility physical security program.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a facility physical security program.
Establish and maintain a file requirements definition document.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a file requirements definition document.
Establish and maintain a fire prevention and fire suppression standard.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a fire prevention and fire suppression standard.
Establish and maintain a guideline for working in a secure area.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a guideline for working in a secure area.
Establish and maintain a hardware asset inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a hardware asset inventory.
Establish and maintain a high-level Strategic Information Technology Plan.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a high-level Strategic Information Technology Plan.
Establish and maintain a job schedule exceptions list.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a job schedule exceptions list.
Establish and maintain a job scheduling methodology.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a job scheduling methodology.
Establish and maintain a lock and access mechanism inventory (keys, lock combinations, or key cards) for all physical access control systems.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a lock and access mechanism inventory (keys, lock combinations, or key cards) for all physical access control systems.
Establish and maintain a locking screen saver policy.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a locking screen saver policy.
Establish and maintain a metrics policy.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a metrics policy.
Establish and maintain a network access and control point configuration standard that includes Configuration Management and rulesets.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a network access and control point configuration standard that includes Configuration Management and rulesets.
Establish and maintain a network security policy.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a network security policy.
Establish and maintain a patch management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a patch management program.
Establish and maintain a performance management standard.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a performance management standard.
Establish and maintain a personnel health and safety policy.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain a personnel health and safety policy.
Establish and maintain a personnel security program.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain a personnel security program.
Establish and maintain a physical clean desk policy.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a physical clean desk policy.
Establish and maintain a physical, electrical, and logical interface specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a physical, electrical, and logical interface specification.
Establish and maintain a policies and controls metrics program.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a policies and controls metrics program.
Establish and maintain a positive information control environment.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a positive information control environment.
Establish and maintain a privacy policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a privacy policy.
Establish and maintain a processing requirements definition document.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a processing requirements definition document.
Establish and maintain a product and services acquisition program.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Establish and maintain a product and services acquisition program.
Establish and maintain a product and services acquisition strategy.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Establish and maintain a product and services acquisition strategy.
Establish and maintain a program specification guideline document.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a program specification guideline document.
Establish and maintain a project control program.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a project control program.
Establish and maintain a project program documentation standard.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a project program documentation standard.
Establish and maintain a project team plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a project team plan.
Establish and maintain a project test plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a project test plan.
Establish and maintain a rapport with business and technical communities throughout the organization to promote the value and importance of Information Security.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a rapport with business and technical communities throughout the organization to promote the value and importance of Information Security.
Establish and maintain a record classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain a record classification scheme.
Establish and maintain a records lifecycle management program.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain a records lifecycle management program.
Establish and maintain a remote access and teleworking program.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a remote access and teleworking program.
Establish and maintain a risk assessment program to manage internal threats and external threats.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Establish and maintain a risk assessment program to manage internal threats and external threats.
Establish and maintain a security awareness program.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain a security awareness program.
Establish and maintain a security controls definition document.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a security controls definition document.
Establish and maintain a security test program.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a security test program.
Establish and maintain a shared resources management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a shared resources management program.
Establish and maintain a social media governance program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a social media governance program.
Establish and maintain a software accountability policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a software accountability policy.
Establish and maintain a software product acquisition methodology.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Establish and maintain a software product acquisition methodology.
Establish and maintain a software release policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a software release policy.
Establish and maintain a source data collection design specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a source data collection design specification.
Establish and maintain a storage media inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain a storage media inventory.
Establish and maintain a system continuity framework.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain a system continuity framework.
Establish and maintain a system continuity plan and associated system continuity procedures.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain a system continuity plan and associated system continuity procedures.
Establish and maintain a system continuity plan philosophy.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain a system continuity plan philosophy.
Establish and maintain a system design project management framework.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a system design project management framework.
Establish and maintain a system design specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a system design specification.
Establish and maintain a system hardening standard and system hardening procedures.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain a system hardening standard and system hardening procedures.
Establish and maintain a system implementation standard.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a system implementation standard.
Establish and maintain a system redeployment or disposal program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain a system redeployment or disposal program.
Establish and maintain a system requirements specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a system requirements specification.
Establish and maintain a system use agreement for each information system.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a system use agreement for each information system.
Establish and maintain a system use training plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a system use training plan.
Establish and maintain a technical measurement metrics policy.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a technical measurement metrics policy.
Establish and maintain a threat and risk classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Establish and maintain a threat and risk classification scheme.
Establish and maintain a transparent storage media strategy.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain a transparent storage media strategy.
Establish and maintain a travel program for all personnel.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain a travel program for all personnel.
Establish and maintain a user-machine interaction specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain a user-machine interaction specification.
Establish and maintain a virtual environment and shared resources security program.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a virtual environment and shared resources security program.
Establish and maintain a visitor access permissions policy.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a visitor access permissions policy.
Establish and maintain a visitor log.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain a visitor log.
Establish and maintain a vulnerability analysis program.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain a vulnerability analysis program.
Establish and maintain a wireless networking policy.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain a wireless networking policy.
Establish and maintain access controls for all records.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain access controls for all records.
Establish and maintain access policies.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain access policies.
Establish and maintain access procedures.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain access procedures.
Establish and maintain access rights to source code based upon least privilege.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain access rights to source code based upon least privilege.
Establish and maintain an Information Architecture model.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain an Information Architecture model.
Establish and maintain an Information Security metrics program.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain an Information Security metrics program.
Establish and maintain an Information Technology financial management framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain an Information Technology financial management framework.
Establish and maintain an Information Technology inventory with asset discovery audit trails.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain an Information Technology inventory with asset discovery audit trails.
Establish and maintain an Intellectual Property Right program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain an Intellectual Property Right program.
Establish and maintain an access classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an access classification scheme.
Establish and maintain an access control program.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an access control program.
Establish and maintain an access rights management plan.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an access rights management plan.
Establish and maintain an account lockout policy.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain an account lockout policy.
Establish and maintain an accurate Configuration Management Database with accessible reporting capabilities.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain an accurate Configuration Management Database with accessible reporting capabilities.
Establish and maintain an application security policy.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an application security policy.
Establish and maintain an approach for compliance monitoring.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain an approach for compliance monitoring.
Establish and maintain an asset inventory database.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain an asset inventory database.
Establish and maintain an authority for access authorization list.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an authority for access authorization list.
Establish and maintain an e-mail policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain an e-mail policy.
Establish and maintain an encryption management and cryptographic controls policy.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an encryption management and cryptographic controls policy.
Establish and maintain an incident management and vulnerability management metrics program.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Establish and maintain an incident management and vulnerability management metrics program.
Establish and maintain an information classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain an information classification scheme.
Establish and maintain an information classification standard to use when establishing information impact levels.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain an information classification standard to use when establishing information impact levels.
Establish and maintain an input requirements definition document.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain an input requirements definition document.
Establish and maintain an instant messaging and chat system usage policy.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain an instant messaging and chat system usage policy.
Establish and maintain an online availability plan that is commensurate with the electronic storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain an online availability plan that is commensurate with the electronic storage media.
Establish and maintain an organizational data dictionary, including data syntax rules.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain an organizational data dictionary, including data syntax rules.
Establish and maintain an output requirements definition document.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain an output requirements definition document.
Establish and maintain an overall Quality Management standard.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain an overall Quality Management standard.
Establish and maintain an unauthorized software list.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain an unauthorized software list.
Establish and maintain application asset management procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain application asset management procedures.
Establish and maintain appropriate system labeling.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain appropriate system labeling.
Establish and maintain asset return procedures.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain asset return procedures.
Establish and maintain backup procedures for in scope systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain backup procedures for in scope systems.
Establish and maintain compromised system reaccreditation procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain compromised system reaccreditation procedures.
Establish and maintain configuration control and Configuration Status Accounting for each system.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain configuration control and Configuration Status Accounting for each system.
Establish and maintain data and information confidentiality policies.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain data and information confidentiality policies.
Establish and maintain data handling policies.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain data handling policies.
Establish and maintain data handling procedures.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain data handling procedures.
Establish and maintain data processing integrity controls.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain data processing integrity controls.
Establish and maintain document handling procedures for paper documents.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain document handling procedures for paper documents.
Establish and maintain document retention procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain document retention procedures.
Establish and maintain document security requirements for the output of records.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain document security requirements for the output of records.
Establish and maintain documentation justifying the use of risky protocols, such as the File Transfer Protocol, and risky ports.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain documentation justifying the use of risky protocols, such as the File Transfer Protocol, and risky ports.
Establish and maintain documentation that justifies using protocols beyond HyperText Transfer Protocol, Secure Socket Layer, Secure Shell, and Virtual Private Network.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain documentation that justifies using protocols beyond HyperText Transfer Protocol, Secure Socket Layer, Secure Shell, and Virtual Private Network.
Establish and maintain documentation to control the network configuration.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain documentation to control the network configuration.
Establish and maintain emergency change procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain emergency change procedures.
Establish and maintain end user computing device security guidelines.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain end user computing device security guidelines.
Establish and maintain end user support communications.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain end user support communications.
Establish and maintain event logging procedures.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Establish and maintain event logging procedures.
Establish and maintain facilities, assets, and services acceptance procedures.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Establish and maintain facilities, assets, and services acceptance procedures.
Establish and maintain facility maintenance procedures.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain facility maintenance procedures.
Establish and maintain full documentation of all policies, standards, and procedures that support the organization's compliance framework.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain full documentation of all policies, standards, and procedures that support the organization's compliance framework.
Establish and maintain future system capacity forecasting methods.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain future system capacity forecasting methods.
Establish and maintain guidelines and procedures for personal data retention or Personally Identifiable Information retention.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain guidelines and procedures for personal data retention or Personally Identifiable Information retention.
Establish and maintain help desk query clearance monitoring procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain help desk query clearance monitoring procedures.
Establish and maintain help desk query escalation procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain help desk query escalation procedures.
Establish and maintain help desk query trend analysis procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain help desk query trend analysis procedures.
Establish and maintain high level operational roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain high level operational roles and responsibilities.
Establish and maintain identification card or badge architectural designs.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain identification card or badge architectural designs.
Establish and maintain identification issuance procedures for identification cards or badges.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain identification issuance procedures for identification cards or badges.
Establish and maintain identification mechanism termination procedures.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain identification mechanism termination procedures.
Establish and maintain identification procedures.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain identification procedures.
Establish and maintain incident response procedures.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Establish and maintain incident response procedures.
Establish and maintain information flow control configuration standards.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain information flow control configuration standards.
Establish and maintain information flow control policies inside the system and between interconnected systems.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain information flow control policies inside the system and between interconnected systems.
Establish and maintain information flow procedures.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain information flow procedures.
Establish and maintain information preservation procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain information preservation procedures.
Establish and maintain ingress address filters.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain ingress address filters.
Establish and maintain integrated project plans.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain integrated project plans.
Establish and maintain mobile device security guidelines.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain mobile device security guidelines.
Establish and maintain nondisclosure agreements.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain nondisclosure agreements.
Establish and maintain off-site physical controls for all distributed Information Technology assets.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain off-site physical controls for all distributed Information Technology assets.
Establish and maintain on-site logical controls for all distributed Information Technology assets.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain on-site logical controls for all distributed Information Technology assets.
Establish and maintain on-site physical controls for all distributed Information Technology assets.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain on-site physical controls for all distributed Information Technology assets.
Establish and maintain onboarding procedures for new hires.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain onboarding procedures for new hires.
Establish and maintain online storage controls.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain online storage controls.
Establish and maintain organizational facility continuity plans.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain organizational facility continuity plans.
Establish and maintain output review and error handling checks with end users.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Establish and maintain output review and error handling checks with end users.
Establish and maintain outsourced development procedures.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain outsourced development procedures.
Establish and maintain personal data access procedures.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain personal data access procedures.
Establish and maintain personal data collection limitation boundaries.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain personal data collection limitation boundaries.
Establish and maintain personnel screening procedures.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain personnel screening procedures.
Establish and maintain personnel status change and termination procedures.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain personnel status change and termination procedures.
Establish and maintain policies and procedures to specify actions that permit users to access the Information System absent Identification and Authentication.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain policies and procedures to specify actions that permit users to access the Information System absent Identification and Authentication.
Establish and maintain policies, standards, and procedures used to manage compliance documents.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain policies, standards, and procedures used to manage compliance documents.
Establish and maintain procedures for configuring the appropriate network parameter modifications.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain procedures for configuring the appropriate network parameter modifications.
Establish and maintain procedures for establishing, maintaining, and terminating third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Establish and maintain procedures for establishing, maintaining, and terminating third party contracts.
Establish and maintain procedures to revoke Public Key certificates.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain procedures to revoke Public Key certificates.
Establish and maintain procedures to standardize Operating System software installation.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain procedures to standardize Operating System software installation.
Establish and maintain promoting the system to a production environment procedures.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain promoting the system to a production environment procedures.
Establish and maintain proper container security.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Establish and maintain proper container security.
Establish and maintain rate limiting filters.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain rate limiting filters.
Establish and maintain record structures to support information confidentiality.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain record structures to support information confidentiality.
Establish and maintain records disposition procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain records disposition procedures.
Establish and maintain records management policies used to manage organizational records.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain records management policies used to manage organizational records.
Establish and maintain records management procedures used to manage organizational records.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain records management procedures used to manage organizational records.
Establish and maintain relationships with key stakeholders, business functions, and leadership outside the Information Technology staff.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain relationships with key stakeholders, business functions, and leadership outside the Information Technology staff.
Establish and maintain requirements for Personal Identity Verification authentication certificates.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain requirements for Personal Identity Verification authentication certificates.
Establish and maintain risk assessment procedures.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Establish and maintain risk assessment procedures.
Establish and maintain risk profiling procedures for internal risk assessments.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Establish and maintain risk profiling procedures for internal risk assessments.
Establish and maintain security classifications for organizational assets.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain security classifications for organizational assets.
Establish and maintain security clearance procedures.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain security clearance procedures.
Establish and maintain security controls appropriate to the record types and electronic storage media in use.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain security controls appropriate to the record types and electronic storage media in use.
Establish and maintain session security coding standards.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain session security coding standards.
Establish and maintain software asset management procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain software asset management procedures.
Establish and maintain software distribution procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain software distribution procedures.
Establish and maintain software license management procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain software license management procedures.
Establish and maintain storage media access control procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain storage media access control procedures.
Establish and maintain storage media and record security label procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain storage media and record security label procedures.
Establish and maintain storage media disposition and destruction procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Establish and maintain storage media disposition and destruction procedures.
Establish and maintain sustainable infrastructure planning.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain sustainable infrastructure planning.
Establish and maintain system acceptance criteria.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain system acceptance criteria.
Establish and maintain system capacity monitoring procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Establish and maintain system capacity monitoring procedures.
Establish and maintain system continuity roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Establish and maintain system continuity roles and responsibilities.
Establish and maintain system conversion procedures.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain system conversion procedures.
Establish and maintain system security documentation.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain system security documentation.
Establish and maintain system testing policies.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain system testing policies.
Establish and maintain system testing procedures.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain system testing procedures.
Establish and maintain systems design principles, systems design guidelines, and System Development Life Cycle documentation.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain systems design principles, systems design guidelines, and System Development Life Cycle documentation.
Establish and maintain tactical Information Technology plans and Information Technology projects in support of the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain tactical Information Technology plans and Information Technology projects in support of the Strategic Information Technology Plan.
Establish and maintain tactical Information Technology plans derived from the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain tactical Information Technology plans derived from the Strategic Information Technology Plan.
Establish and maintain the Information Technology staff structure in line with the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish and maintain the Information Technology staff structure in line with the Strategic Information Technology Plan.
Establish and maintain the interactive logon settings.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish and maintain the interactive logon settings.
Establish and maintain the overall system development project management roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Establish and maintain the overall system development project management roles and responsibilities.
Establish and maintain the scope of the organizational compliance framework and Information Assurance controls.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Establish and maintain the scope of the organizational compliance framework and Information Assurance controls.
Establish and maintain third party Software Maintenance Agreements.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Establish and maintain third party Software Maintenance Agreements.
Establish and maintain third party connection agreements in support of information flow control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain third party connection agreements in support of information flow control.
Establish and maintain third party transaction authentication procedures.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Establish and maintain third party transaction authentication procedures.
Establish and maintain transparency and openness while protecting the privacy of personal data.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Establish and maintain transparency and openness while protecting the privacy of personal data.
Establish and maintain whitelists and blacklists of software.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish and maintain whitelists and blacklists of software.
Establish idle session termination and logout capabilities.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Establish idle session termination and logout capabilities.
Establish job categorization criteria, job recruitment criteria, and promotion criteria.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Establish job categorization criteria, job recruitment criteria, and promotion criteria.
Establish lockout procedures or mechanisms to be triggered after a predetermined number of consecutive logon attempts.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish lockout procedures or mechanisms to be triggered after a predetermined number of consecutive logon attempts.
Establish session authenticity through Transport Layer Security.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish session authenticity through Transport Layer Security.
Establish session lock capabilities.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish session lock capabilities.
Establish test environments separate from the production environment to support integration testing before product acquisition.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Establish test environments separate from the production environment to support integration testing before product acquisition.
Establish the criticality of the network and systems.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish the criticality of the network and systems.
Establish the third party's service continuity.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Establish the third party's service continuity.
Establish trusted paths to transmit restricted data or restricted information over public networks or wireless networks.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Establish trusted paths to transmit restricted data or restricted information over public networks or wireless networks.
Evaluate Information Technology personnel job performance.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Evaluate Information Technology personnel job performance.
Evaluate and determine whether or not the newly developed system meets security requirements.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Evaluate and determine whether or not the newly developed system meets security requirements.
Evaluate and determine whether or not the newly developed system meets users' system design requirements.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Evaluate and determine whether or not the newly developed system meets users' system design requirements.
Evaluate any refusal by the organization to provide missing audit documentation.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Evaluate any refusal by the organization to provide missing audit documentation.
Evaluate the Information Technology staffing requirements regularly.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Evaluate the Information Technology staffing requirements regularly.
Execute Problem Management
SNow
State: PublishedCategory: Periodic Review
Problems are monitored and resolved following effective procedures.
Execute fail-safe procedures when an emergency occurs.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Execute fail-safe procedures when an emergency occurs.
Firewall rules filtering the manufacturing system network traffic should be documented according to the requirements defined within the DIA OT CS Firewall Policy Guideline.
SNow
Classification: IdentifyState: PublishedCategory: Technical security
Firewall rules filtering the manufacturing system network traffic should be documented according to the requirements defined within the PL ID 24974826 MCRP Firewall Policy Guideline.
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
Firewall rules filtering the manufacturing system network traffic should be documented according to the requirements defined within the PL ID 24974826 MCRP Firewall Policy Guideline.
Follow security design requirements when developing systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Follow security design requirements when developing systems.
Follow the resource workload schedule.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Follow the resource workload schedule.
Follow the system development process when upgrading a system.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Follow the system development process when upgrading a system.
Follow-up on Previous Corrective Actions
SNow
State: PublishedCategory: Periodic Review
Corrective actions from a previous Periodic Review, a Validation Report or performed internal audits and external inspections are followed up and closed
Forecast system workloads.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Forecast system workloads.
Formalize client and third party relationships with contracts or nondisclosure agreements as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Formalize client and third party relationships with contracts or nondisclosure agreements as necessary.
Formally approve the initiation of each project phase.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Formally approve the initiation of each project phase.
GRC-01 Governance Program Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.
GRC-02 Risk Management Program
SNow
State: PublishedCategory: Uncategorized
Establish a formal, documented, and leadership-sponsored Enterprise Risk Management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks.
GRC-03 Organizational Policy Reviews
SNow
State: PublishedCategory: Uncategorized
Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.
GRC-04 Policy Exception Process
SNow
State: PublishedCategory: Uncategorized
Establish and follow an approved exception process as mandated by the governance program whenever a deviation from an established policy occurs.
GRC-05 Information Security Program
SNow
State: PublishedCategory: Uncategorized
Develop and implement an Information Security Program, which includes programs for all the relevant domains of the CCM.
GRC-06 Governance Responsibility Model
SNow
State: PublishedCategory: Uncategorized
Define and document roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs.
GRC-07 Information System Regulatory Mapping
SNow
State: PublishedCategory: Uncategorized
Identify and document all relevant standards, regulations, legal/contractual, and statutory requirements, which are applicable to your organization.
GRC-08 Special Interest Groups
SNow
State: PublishedCategory: Uncategorized
Establish and maintain contact with cloud-related special interest groups and other relevant entities in line with business context.
Generate an alert when an audit log failure occurs.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Generate an alert when an audit log failure occurs.
Generate strong cryptographic keys.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Generate strong cryptographic keys.
HIPAA Compliance
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
In the US a Roche HIPAA Privacy Officer must review the project deliverables and confirm if HIPAA requirements are met.
HRS-01 Background Screening Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for background verification of all new employees (including but not limited to remote employees, contractors, and third parties) according to local laws, regulations, ethics, and contractual constraints a
HRS-02 Acceptable Use of Technology Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets. Review and update the policies and procedures at least annually.
HRS-03 Clean Desk Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures that require unattended workspaces to not have openly visible confidential data. Review and update the policies and procedures at least annually.
HRS-04 Remote and Home Working Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
HRS-05 Asset returns
SNow
State: PublishedCategory: Uncategorized
Establish and document procedures for the return of organization-owned assets by terminated employees.
HRS-06 Employment Termination
SNow
State: PublishedCategory: Uncategorized
Establish, document, and communicate to all personnel the procedures outlining the roles and responsibilities concerning changes in employment.
HRS-07 Employment Agreement Process
SNow
State: PublishedCategory: Uncategorized
Employees sign the employee agreement prior to being granted access to organizational information systems, resources and assets.
HRS-08 Employment Agreement Content
SNow
State: PublishedCategory: Uncategorized
The organization includes within the employment agreements provisions and/or terms for adherence to established information governance and security policies.
HRS-09 Personnel Roles and Responsibilities
SNow
State: PublishedCategory: Uncategorized
Document and communicate roles and responsibilities of employees, as they relate to information assets and security.
HRS-10 Non-Disclosure Agreements
SNow
State: PublishedCategory: Uncategorized
Identify, document, and review, at planned intervals, requirements for non-disclosure/confidentiality agreements reflecting the organization's needs for the protection of data and operational details.
HRS-11 Security Awareness Training
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain a security awareness training program for all employees of the organization and provide regular training updates.
HRS-12 Personal and Sensitive Data Awareness and Training
SNow
State: PublishedCategory: Uncategorized
Provide all employees with access to sensitive organizational and personal data with appropriate security awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization.
HRS-13 Compliance User Responsibility
SNow
State: PublishedCategory: Uncategorized
Make employees aware of their roles and responsibilities for maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations.
House system components in areas where the physical damage potential is minimized.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
House system components in areas where the physical damage potential is minimized.
IAM-01 Identity and Access Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.
IAM-02 Strong Password Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, implement, apply, evaluate and maintain strong password policies and procedures. Review and update the policies and procedures at least annually.
IAM-03 Identity Inventory
SNow
State: PublishedCategory: Uncategorized
Manage, store, and review the information of system identities, and level of access.
IAM-04 Separation of Duties
SNow
State: PublishedCategory: Uncategorized
Employ the separation of duties principle when implementing information system access.
IAM-05 Least Privilege
SNow
State: PublishedCategory: Uncategorized
Employ the least privilege principle when implementing information system access.
IAM-06 User Access Provisioning
SNow
State: PublishedCategory: Uncategorized
Define and implement a user access provisioning process which authorizes, records, and communicates access changes to data and assets.
IAM-07 User Access Changes and Revocation
SNow
State: PublishedCategory: Uncategorized
De-provision or respectively modify access of movers / leavers or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.
IAM-08 User Access Review
SNow
State: PublishedCategory: Uncategorized
Review and revalidate user access for least privilege and separation of duties with a frequency that is commensurate with organizational risk tolerance.
IAM-09 Segregation of Privileged Access Roles
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for the segregation of privileged access roles such that administrative access to data, encryption and key management capabilities and logging capabilities are distinct and separated.
IAM-10 Management of Privileged Access Roles
SNow
State: PublishedCategory: Uncategorized
Define and implement an access process to ensure privileged access roles and rights are granted for a time limited period, and implement procedures to prevent the culmination of segregated privileged access.
IAM-11 CSCs Approval for Agreed Privileged Access Roles
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes and procedures for customers to participate, where applicable, in the granting of access for agreed, high risk (as defined by the organizational risk assessment) privileged access roles.
IAM-12 Safeguard Logs Integrity
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it is controlled through a procedure that ensures the segregation of duties and
IAM-13 Uniquely Identifiable Users
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures that ensure users are identifiable through unique IDs or which can associate individuals to the usage of user IDs.
IAM-14 Strong Authentication
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for authenticating access to systems, application and data assets, including multifactor authentication for at least privileged user and sensitive data access. Adopt digital certificates or alternatives which achieve an equi
IAM-15 Passwords Management
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for the secure management of passwords.
IAM-16 Authorization Mechanisms
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.
IPY-01 Interoperability and Portability Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for interoperability and portability including requirements for: a. Communications between application interfaces b. Information processing interoperability c. Application development portability d. Infor
IPY-02 Application Interface Availability
SNow
State: PublishedCategory: Uncategorized
Provide application interface(s) to CSCs so that they programmatically retrieve their data to enable interoperability and portability.
IPY-03 Secure Interoperability and Portability Management
SNow
State: PublishedCategory: Uncategorized
Implement cryptographically secure and standardized network protocols for the management, import and export of data.
IPY-04 Data Portability Contractual Obligations
SNow
State: PublishedCategory: Uncategorized
Agreements must include provisions specifying CSCs access to data upon contract termination and will include: a. Data format b. Length of time the data will be stored c. Scope of the data retained and made available to the CSCs d. Data deletion policy
IT General Controls
SNow
Classification: DetectState: PublishedCategory: Audits and risk management
IT Security Checklist is fully assessed
SNow
State: PublishedCategory: Periodic Review
The IT Security Checklist attached to this control is completed
IVS-01 Infrastructure and Virtualization Security Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for infrastructure and virtualization security. Review and update the policies and procedures at least annually.
IVS-02 Capacity and Resource Planning
SNow
State: PublishedCategory: Uncategorized
Plan and monitor the availability, quality, and adequate capacity of resources in order to deliver the required system performance as determined by the business.
IVS-03 Network Security
SNow
State: PublishedCategory: Uncategorized
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating
IVS-04 OS Hardening and Base Controls
SNow
State: PublishedCategory: Uncategorized
Harden host and guest OS, hypervisor or infrastructure control plane according to their respective best practices, and supported by technical controls, as part of a security baseline.
IVS-05 Production and Non-Production Environments
SNow
State: PublishedCategory: Uncategorized
Separate production and non-production environments.
IVS-06 Segmentation and Segregation
SNow
State: PublishedCategory: Uncategorized
Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.
IVS-07 Migration to Cloud Environments
SNow
State: PublishedCategory: Uncategorized
Use secure and encrypted communication channels when migrating servers, services, applications, or data to cloud environments. Such channels must include only up-to-date and approved protocols.
IVS-08 Network Architecture Documentation
SNow
State: PublishedCategory: Uncategorized
Identify and document high-risk environments.
IVS-09 Network Defense
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.
Identify Security and Data Privacy Job Roles
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
Security relevant roles are identified and got a security specific training. The system documentation must cover the security-related functions of the system (e. g. access control, authorization management, logging, encryption). Documented Security Functions (e.g. SAP Security Admin) to ensure that
Identify accreditation tasks.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Identify accreditation tasks.
Identify and allocate departmental costs.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Identify and allocate departmental costs.
Identify and authenticate approved devices before establishing a connection to restricted data.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Identify and authenticate approved devices before establishing a connection to restricted data.
Identify and consider alternatives to meeting the security requirements when acquiring Information Technology assets.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Identify and consider alternatives to meeting the security requirements when acquiring Information Technology assets.
Identify and define all key Information Technology roles.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Identify and define all key Information Technology roles.
Identify and document physical access controls for all physical entry points.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Identify and document physical access controls for all physical entry points.
Identify and document the system's Configurable Items.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Identify and document the system's Configurable Items.
Identify discrepancies between the asset register database and the Information Technology inventory, as necessary.
SNow
Classification: CorrectiveState: PublishedCategory: Leadership and high level objectives
Identify discrepancies between the asset register database and the Information Technology inventory, as necessary.
Identify processes, Information Systems, and third parties that transmit, store, or process Personally Identifiable Information.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Identify processes, Information Systems, and third parties that transmit, store, or process Personally Identifiable Information.
Identify roles, tasks, information, systems, and assets that fall under the organization's mandated Authority Documents.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Identify roles, tasks, information, systems, and assets that fall under the organization's mandated Authority Documents.
If applicable, use of "secure" (encrypted version like https or SMBv3 for example) network protocols. Alternatives may include the use of edge devices or similar devices
SNow
Classification: ProtectState: PublishedCategory: Operational management
If applicable, use of "secure" (encrypted version like https or SMBv3 for example) network protocols. Alternatives may include the use of edge devices or similar devices
Implement Application Firewalls
SNow
Classification: ProtectState: PublishedCategory: Devices
Place application firewalls in front of any critical servers to verify and validate the traffic going to the server. Any unauthorized traffic should be blocked and logged.
Implement Application Whitelisting of Libraries
SNow
Classification: ProtectState: PublishedCategory: Applications
The organization's application whitelisting software must ensure that only authorized software libraries (such as *.dll, *.ocx, *.so, etc) are allowed to load into a system process.
Implement Application Whitelisting of Scripts
SNow
Classification: ProtectState: PublishedCategory: Applications
The organization's application whitelisting software must ensure that only authorized, digitally signed scripts (such as *.ps1, *.py, macros, etc) are allowed to run on a system.
Implement Automated Configuration Monitoring Systems
SNow
Classification: DetectState: PublishedCategory: Applications
Utilize a Security Content Automation Protocol (SCAP) compliant configuration monitoring system to verify all security configuration elements, catalog approved exceptions, and alert when unauthorized changes occur.
Implement DMARC and Enable Receiver-Side Verification
SNow
Classification: ProtectState: PublishedCategory: Network
To lower the chance of spoofed or modified emails from valid domains, implement Domain-based Message Authentication, Reporting and Conformance (DMARC) policy and verification, starting by implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail(DKIM) standards.
Implement a Security Awareness Program
SNow
Classification: ProtectState: PublishedCategory: Users
Create a security awareness program for all workforce members to complete on a regular basis to ensure they understand and exhibit the necessary behaviors and skills to help ensure the security of the organization. The organization's security awareness program should be communicated in a continuous
Implement a Security Awareness and Training Program
SNow
Classification: IdentifyState: PublishedCategory: Users
For all functional roles in the organization (prioritizing those mission-critical to the business and its security), identify the specific knowledge, skills, and abilities needed to support defense of the enterprise; develop and execute an integrated plan to assess, identify gaps, and remediate thro
Implement a centralized identification and access rights management process.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Implement a centralized identification and access rights management process.
Implement a corrective action plan in response to the audit report.
SNow
Classification: CorrectiveState: PublishedCategory: Audits and risk management
Implement a corrective action plan in response to the audit report.
Implement a sanctions process for personnel who fail to comply to the organizational compliance program.
SNow
Classification: CorrectiveState: PublishedCategory: Human Resources management
Implement a sanctions process for personnel who fail to comply to the organizational compliance program.
Implement and comply with the Governance, Risk, and Compliance framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Implement and comply with the Governance, Risk, and Compliance framework.
Implement and maintain a duplicate originals of record indexes.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Implement and maintain a duplicate originals of record indexes.
Implement and maintain backups and duplicate copies of organizational records.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Implement and maintain backups and duplicate copies of organizational records.
Implement and maintain high availability storage, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Implement and maintain high availability storage, as necessary.
Implement approved changes.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Implement approved changes.
Implement automated audit tools.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Implement automated audit tools.
Implement cryptographic operations and support functions on identification cards or badges.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Implement cryptographic operations and support functions on identification cards or badges.
Implement fault-tolerant architecture and segregation of duties on systems that provide secure name/address resolution services.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Implement fault-tolerant architecture and segregation of duties on systems that provide secure name/address resolution services.
Implement file integrity monitoring.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Implement file integrity monitoring.
Implement information flow control policies when making decisions about information sharing or collaboration.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Implement information flow control policies when making decisions about information sharing or collaboration.
Implement mobile device security guidelines.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Implement mobile device security guidelines.
Implement non-repudiation for transactions.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Implement non-repudiation for transactions.
Implement only one application or primary function per network component or server.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Implement only one application or primary function per network component or server.
Implement personnel supervisory practices.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Implement personnel supervisory practices.
Implement procedures to file privacy rights violation complaints.
SNow
Classification: CorrectiveState: PublishedCategory: Privacy protection for information and data
Implement procedures to file privacy rights violation complaints.
Implement safeguards to protect memory from unauthorized code execution.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Implement safeguards to protect memory from unauthorized code execution.
Implement security controls into the system during the development process.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Implement security controls into the system during the development process.
Implement security controls when developing systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Implement security controls when developing systems.
Implement segregation of duties in roles and responsibilities.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Implement segregation of duties in roles and responsibilities.
Implement the documented cryptographic module security functions.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Implement the documented cryptographic module security functions.
Implement two-factor authentication techniques.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Implement two-factor authentication techniques.
In case the manufacturing system is managed by 3rd parties or vendor, the service provider should be assessed against cybersecurity requirements according to respective vendor risk assessment process.
SNow
Classification: IdentifyState: PublishedCategory: Third Party and supply chain oversight
In case the manufacturing system is managed by 3rd parties or vendor, the service provider should be assessed against cybersecurity requirements according to respective vendor risk assessment process.
In case the manufacturing system is managed by 3rd parties the SLA (Service Level Agreement) should be formally defined (e.g. support for incident or failure investigation and remediation).
SNow
Classification: RespondState: PublishedCategory: Third Party and supply chain oversight
In case the manufacturing system is managed by 3rd parties the SLA (Service Level Agreement) should be formally defined (e.g. support for incident or failure investigation and remediation).
In case the manufacturing system utilizes communication from RCN, the untrusted communication should be routed through dedicated industrial DMZ.
SNow
Classification: ProtectState: PublishedCategory: Technical Security
In case the manufacturing system utilizes communication from RCN, the untrusted communication should be routed through dedicated industrial DMZ.
In-depth Technical Security Verification (Penetration Test)
SNow
Classification: PreventiveState: PublishedCategory: Vulnerability and Configuration Analysis
A trusted and approved 3rd party cyber-security expert shall execute a penetration test to simulate an attack and identify vulnerabilities. The system or solution must successfully pass without any major or critical findings.
Incident Response and Management
SNow
Classification: ProtectState: PublishedCategory: Data
Protect the organization's information, as well as its reputation, by developing and implementing an incident response infrastructure (e.g., plans, defined roles, training, communications, management oversight) for quickly discovering an attack and then effectively containing the damage, eradicating
Include that explicit management authorization must be given for the use of all technologies and their documentation in the Acceptable Use Policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include that explicit management authorization must be given for the use of all technologies and their documentation in the Acceptable Use Policy.
Include Bring Your Own Device security guidelines in the Acceptable Use Policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include Bring Your Own Device security guidelines in the Acceptable Use Policy.
Include Change Control clauses as appropriate in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include Change Control clauses as appropriate in third party contracts.
Include Internet Service Provider continuity procedures in the continuity plan.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Include Internet Service Provider continuity procedures in the continuity plan.
Include Tests for Presence of Unprotected System Information and Artifacts
SNow
Classification: DetectState: PublishedCategory: Network
Include tests for the presence of unprotected system information and artifacts that would be useful to attackers, including network diagrams, configuration files, older penetration test reports, e-mails or documents containing passwords or other information critical to system operation.
Include Wide Area Network continuity procedures in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include Wide Area Network continuity procedures in the continuity plan.
Include a bug tracking system in the Quality Management program.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Include a bug tracking system in the Quality Management program.
Include a description of each module and asset in the system design specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Include a description of each module and asset in the system design specification.
Include a description of the data or information to be covered in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include a description of the data or information to be covered in third party contracts.
Include a reporting structure in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include a reporting structure in third party contracts.
Include a software installation policy in the Acceptable Use Policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include a software installation policy in the Acceptable Use Policy.
Include a standard to collect and interpret event logs in the event logging procedures.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Include a standard to collect and interpret event logs in the event logging procedures.
Include a statement that access to the report is restricted based on least privilege in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include a statement that access to the report is restricted based on least privilege in the audit report.
Include access control mechanisms in the Acceptable Use Policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include access control mechanisms in the Acceptable Use Policy.
Include access to issued Public Key certificates in the Public Key certificate procedures.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Include access to issued Public Key certificates in the Public Key certificate procedures.
Include access to work papers in external auditor outsourcing contracts.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include access to work papers in external auditor outsourcing contracts.
Include after-action analysis procedures in the Incident Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include after-action analysis procedures in the Incident Management program.
Include agreement to the audit scope and audit terms in the audit program.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include agreement to the audit scope and audit terms in the audit program.
Include all electronic storage media containing restricted data or restricted information in the storage media inventory.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Include all electronic storage media containing restricted data or restricted information in the storage media inventory.
Include any in scope material events that might affect the assertion in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include any in scope material events that might affect the assertion in the audit assertion.
Include any in scope uncorrected errors or non-compliance issues in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include any in scope uncorrected errors or non-compliance issues in the audit assertion.
Include any of the organization's use of compensating controls that were not audited in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include any of the organization's use of compensating controls that were not audited in the audit report.
Include any out of scope components of in scope systems in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include any out of scope components of in scope systems in the audit report.
Include archives and record management standards in the system requirements specification.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Include archives and record management standards in the system requirements specification.
Include asset tags in the Acceptable Use Policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include asset tags in the Acceptable Use Policy.
Include asset use policies in the Acceptable Use Policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include asset use policies in the Acceptable Use Policy.
Include assigned roles and responsibilities in the network access and control point configuration standard.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Include assigned roles and responsibilities in the network access and control point configuration standard.
Include assigning and approving operations in operational control procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include assigning and approving operations in operational control procedures.
Include audit subject matter in the audit program.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include audit subject matter in the audit program.
Include business continuity procedures in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include business continuity procedures in the Incident Response program.
Include business requirements of delivered services in the Service Level Agreement.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include business requirements of delivered services in the Service Level Agreement.
Include business security requirements in the access classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Include business security requirements in the access classification scheme.
Include compliance with the organization's access policy as a requirement in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include compliance with the organization's access policy as a requirement in third party contracts.
Include compliance with the organization's privacy policy in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include compliance with the organization's privacy policy in third party contracts.
Include continuity wrap-up procedures and continuity normalization procedures during continuity planning.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include continuity wrap-up procedures and continuity normalization procedures during continuity planning.
Include continuous security warning monitoring procedures in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include continuous security warning monitoring procedures in the internal control framework.
Include continuous user account management procedures in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include continuous user account management procedures in the internal control framework.
Include damaged site continuity procedures that cover continuing operations in a partially functional primary facility in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include damaged site continuity procedures that cover continuing operations in a partially functional primary facility in the continuity plan.
Include data elements that contain an individual's payment card information as personal data that falls under the breach notification rules.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Include data elements that contain an individual's payment card information as personal data that falls under the breach notification rules.
Include data loss event notifications in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include data loss event notifications in the Incident Response program.
Include each Information System's system boundaries in the Information Technology inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Include each Information System's system boundaries in the Information Technology inventory.
Include emergency communications procedures in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include emergency communications procedures in the continuity plan.
Include emergency processing priorities in the Incident Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include emergency processing priorities in the Incident Management program.
Include explanations, compensating controls, or risk acceptance in the compliance exceptions Exceptions document.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Include explanations, compensating controls, or risk acceptance in the compliance exceptions Exceptions document.
Include explicit restrictions in the social media acceptable usage policy.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include explicit restrictions in the social media acceptable usage policy.
Include how access to in scope systems, personnel and in scope records are provided to the auditor in the audit terms.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include how access to in scope systems, personnel and in scope records are provided to the auditor in the audit terms.
Include how in scope material events are monitored and logged in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include how in scope material events are monitored and logged in the audit assertion.
Include how the audit scope matches in scope controls in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include how the audit scope matches in scope controls in the audit assertion.
Include how the in scope system is designed and implemented in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include how the in scope system is designed and implemented in the audit assertion.
Include if in scope control deviations allow in scope controls to be performed acceptably in the work papers.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Include if in scope control deviations allow in scope controls to be performed acceptably in the work papers.
Include in scope change controls in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include in scope change controls in the audit assertion.
Include incident escalation procedures in the Incident Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include incident escalation procedures in the Incident Management program.
Include incident management procedures and incident reporting procedures in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include incident management procedures and incident reporting procedures in third party contracts.
Include incident monitoring procedures in the Incident Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include incident monitoring procedures in the Incident Management program.
Include incident record closure procedures in the Incident Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include incident record closure procedures in the Incident Management program.
Include incident reporting procedures in the Incident Management program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include incident reporting procedures in the Incident Management program.
Include incident response team services in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include incident response team services in the Incident Response program.
Include incident response team structures in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include incident response team structures in the Incident Response program.
Include information about the organization being audited and the auditor performing the audit in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include information about the organization being audited and the auditor performing the audit in the audit report.
Include items that pertain to third parties in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include items that pertain to third parties in the audit report.
Include items that were excluded from the audit report in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include items that were excluded from the audit report in the audit report.
Include limiting access to confidential data or restricted information to a need to know basis in the access classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Include limiting access to confidential data or restricted information to a need to know basis in the access classification scheme.
Include material changes in information processes, Information Systems, and assets that could affect audits in the audit terms.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include material changes in information processes, Information Systems, and assets that could affect audits in the audit terms.
Include materiality levels in the audit terms.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include materiality levels in the audit terms.
Include network equipment in the Information Technology inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Include network equipment in the Information Technology inventory.
Include participation by each affected user department in the project implementation phase.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Include participation by each affected user department in the project implementation phase.
Include personnel contact information in the event of an incident in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include personnel contact information in the event of an incident in the Incident Response program.
Include personnel security procedures in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include personnel security procedures in the internal control framework.
Include portable computing devices that store restricted data or restricted information in the Information Technology inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Include portable computing devices that store restricted data or restricted information in the Information Technology inventory.
Include priority-of-service provisions in the telecommunications Service Level Agreements.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include priority-of-service provisions in the telecommunications Service Level Agreements.
Include procedures for continuous quality improvement in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include procedures for continuous quality improvement in the internal control framework.
Include program documentation standards in the Quality Management program.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Include program documentation standards in the Quality Management program.
Include record integrity techniques in the Records Management procedures.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Include record integrity techniques in the Records Management procedures.
Include required service levels in system acquisition contracts.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Include required service levels in system acquisition contracts.
Include restoration procedures in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include restoration procedures in the continuity plan.
Include risk management procedures in the supply chain management policy.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include risk management procedures in the supply chain management policy.
Include risk prioritized recovery procedures for each business unit in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include risk prioritized recovery procedures for each business unit in the continuity plan.
Include security incident response procedures in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include security incident response procedures in the internal control framework.
Include security information sharing procedures in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include security information sharing procedures in the internal control framework.
Include security requirements in system acquisition contracts.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Include security requirements in system acquisition contracts.
Include security requirements in the system design specification.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Include security requirements in the system design specification.
Include security threats and hazards to the system in the threat and risk classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include security threats and hazards to the system in the threat and risk classification scheme.
Include security vulnerabilities based upon threats to the system in the threat and risk classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include security vulnerabilities based upon threats to the system in the threat and risk classification scheme.
Include software in the Information Technology inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Include software in the Information Technology inventory.
Include startup processes in operational control procedures.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include startup processes in operational control procedures.
Include system continuity procedures in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include system continuity procedures in the continuity plan.
Include technical preparation considerations for backup operations in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include technical preparation considerations for backup operations in the continuity plan.
Include temporary and emergency access authorization procedures in the Incident Management program.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Include temporary and emergency access authorization procedures in the Incident Management program.
Include text about access, use, disclosure, and transfer of data or information in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include text about access, use, disclosure, and transfer of data or information in third party contracts.
Include text that signatories must meet organizational compliance requirements in third party contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Include text that signatories must meet organizational compliance requirements in third party contracts.
Include that the audit findings are not a predictive analysis of future compliance in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include that the audit findings are not a predictive analysis of future compliance in the audit report.
Include that the organization is the responsible party for designing and implementing the in scope controls it identified in the audit scope in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include that the organization is the responsible party for designing and implementing the in scope controls it identified in the audit scope in the audit report.
Include that the organization is the responsible party for specifying in scope controls not defined by law or contractual obligation in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include that the organization is the responsible party for specifying in scope controls not defined by law or contractual obligation in the audit report.
Include that the organization is the responsible party for the content of its audit assertion and in scope system description in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include that the organization is the responsible party for the content of its audit assertion and in scope system description in the audit report.
Include that this is the audit opinion in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include that this is the audit opinion in the audit report.
Include the General Support Systems and security support structure in the Information Technology inventory.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Include the General Support Systems and security support structure in the Information Technology inventory.
Include the attestation standards the auditor follows in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the attestation standards the auditor follows in the audit report.
Include the audit opinion regarding the accurateness of the in scope system description in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the audit opinion regarding the accurateness of the in scope system description in the audit report.
Include the causes of identified in scope control deficiencies in the work papers.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the causes of identified in scope control deficiencies in the work papers.
Include the consequences of non-compliance in the Acceptable Use Policy.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Include the consequences of non-compliance in the Acceptable Use Policy.
Include the date of the audit in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the date of the audit in the audit report.
Include the end users and affected parties of the in scope system in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the end users and affected parties of the in scope system in the audit assertion.
Include the in scope controls and compliance documents in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the in scope controls and compliance documents in the audit assertion.
Include the in scope risk assessment processes in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the in scope risk assessment processes in the audit assertion.
Include the in scope services offered or in scope transactions processed in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the in scope services offered or in scope transactions processed in the audit assertion.
Include the incident response team member's roles and responsibilities in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include the incident response team member's roles and responsibilities in the Incident Response program.
Include the incident response training program in the Incident Response program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include the incident response training program in the Incident Response program.
Include the nature and causes of identified in scope control deviations in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the nature and causes of identified in scope control deviations in the audit report.
Include the organization's audit assertion of the in scope system in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the organization's audit assertion of the in scope system in the audit report.
Include the organization's description of the in scope system in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the organization's description of the in scope system in the audit report.
Include the organization's privacy practices in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the organization's privacy practices in the audit report.
Include the pass or fail test status of all in scope controls in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the pass or fail test status of all in scope controls in the audit report.
Include the process of using evidential matter to test in scope controls in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the process of using evidential matter to test in scope controls in the audit report.
Include the process of using evidential matter to test in scope controls in the test plan.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the process of using evidential matter to test in scope controls in the test plan.
Include the protection of personnel in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include the protection of personnel in the continuity plan.
Include the results of the risk assessment in the risk assessment report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the results of the risk assessment in the risk assessment report.
Include the risks to the organization's key personnel and assets in the threat and risk classification scheme.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the risks to the organization's key personnel and assets in the threat and risk classification scheme.
Include the roles and responsibilities involved in risk assessments in the risk assessment program.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the roles and responsibilities involved in risk assessments in the risk assessment program.
Include the scope and work performed in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the scope and work performed in the audit report.
Include the scope and work to be performed in external auditor outsourcing contracts.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the scope and work to be performed in external auditor outsourcing contracts.
Include the threats and risks associated with the system development project in the project feasibility study.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Include the threats and risks associated with the system development project in the project feasibility study.
Include the word independent in the title of audit reports.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include the word independent in the title of audit reports.
Include third party acknowledgement of their data protection responsibilities in third party contracts.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Include third party acknowledgement of their data protection responsibilities in third party contracts.
Include third party requirements for personnel security in third party contracts.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Include third party requirements for personnel security in third party contracts.
Include threat assessment, vulnerability management, and risk assessment in the internal control framework.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Include threat assessment, vulnerability management, and risk assessment in the internal control framework.
Include website continuity procedures in the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Include website continuity procedures in the continuity plan.
Include whether the use of compensating controls are necessary in the audit report.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include whether the use of compensating controls are necessary in the audit report.
Include why specific criteria are ignored by in scope controls in the audit assertion.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Include why specific criteria are ignored by in scope controls in the audit assertion.
Incorporate realistic exercises that are tested into the incident response training program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Incorporate realistic exercises that are tested into the incident response training program.
Incorporate simulated events into the continuity plan training.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Incorporate simulated events into the continuity plan training.
Incorporate simulated events into the incident response training program.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Incorporate simulated events into the incident response training program.
Indicate the active use of collaborative computing devices to users physically present at the device.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Indicate the active use of collaborative computing devices to users physically present at the device.
Information Compliance Requirements
SNow
Classification: MandatedState: PublishedCategory: Governance, Risk and Compliance
All IT systems must comply with the Information Compliance requirements: Classify information in your system according to the GRIC. The system must delete information at the end of the retention period. Ensure information is findable and retrievable in your system. Ensure continuous ownership of all
Information security in project management
SNow
State: PublishedCategory: Uncategorized
Information Security is integrated into Project Management
Initiate the System Development Life Cycle development phase or System Development Life Cycle build phase.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Initiate the System Development Life Cycle development phase or System Development Life Cycle build phase.
Initiate the System Development Life Cycle implementation phase.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Initiate the System Development Life Cycle implementation phase.
Initiate the System Development Life Cycle planning phase.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Initiate the System Development Life Cycle planning phase.
Inspect items brought into the facility.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Inspect items brought into the facility.
Install a generator sized to support the facility.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Install a generator sized to support the facility.
Install all available critical security updates and important security updates in a timely way.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Install all available critical security updates and important security updates in a timely way.
Install an Uninterruptible Power Supply sized to support all critical systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Install an Uninterruptible Power Supply sized to support all critical systems.
Install and configure application layer firewalls for all key web-facing applications.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Install and configure application layer firewalls for all key web-facing applications.
Install and configure firewalls to be enabled on all mobile devices, if possible.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Install and configure firewalls to be enabled on all mobile devices, if possible.
Install and maintain Emergency Power Supply shutdown devices or Emergency Power Supply shutdown switches.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain Emergency Power Supply shutdown devices or Emergency Power Supply shutdown switches.
Install and maintain a moisture control system as a part of the climate control system.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain a moisture control system as a part of the climate control system.
Install and maintain an Intrusion Detection System and/or Intrusion Prevention System.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Install and maintain an Intrusion Detection System and/or Intrusion Prevention System.
Install and maintain an environment control monitoring system.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Install and maintain an environment control monitoring system.
Install and maintain emergency lighting for use in a power failure.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain emergency lighting for use in a power failure.
Install and maintain fire protection equipment.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain fire protection equipment.
Install and maintain fire suppression systems.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain fire suppression systems.
Install and maintain network jacks and outlet boxes.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain network jacks and outlet boxes.
Install and maintain redundant power supplies for the Information Technology facility.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and maintain redundant power supplies for the Information Technology facility.
Install and protect network cabling.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Install and protect network cabling.
Install antivirus software, anti-spam software, and spyware monitoring, detection and removal utilities on all systems.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Install antivirus software, anti-spam software, and spyware monitoring, detection and removal utilities on all systems.
Integrate Software and Hardware Asset Inventories
SNow
Classification: IdentifyState: PublishedCategory: Applications
The software inventory system should be tied into the hardware asset inventory so all devices and associated software are tracked from a single location.
Integrate the corrective action plan based on the risk assessment findings with other risk management activities.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Integrate the corrective action plan based on the risk assessment findings with other risk management activities.
Integration with Centralized Security Monitoring
SNow
Classification: DetectiveState: PublishedCategory: Logging, Monitoring, Threat Detection, and Analytics
For high-risk solutions or when processing personal data, logging and incident management processes must be implemented to reliably capture, identify, contain and report security & privacy-related incidents.In order to identify fraudulent access or abusive use of Roche systems and/or data (including
Interpret and apply security requirements based upon the information classification of the system.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Interpret and apply security requirements based upon the information classification of the system.
Inventory and Control of Hardware Assets
SNow
Classification: IdentifyState: PublishedCategory: Devices
Actively manage (inventory, track, and correct) all hardware devices on the network so that only authorized devices are given access, and unauthorized and unmanaged devices are found and prevented from gaining access.
Inventory and Control of Software Assets
SNow
Classification: IdentifyState: PublishedCategory: Applications
Actively manage (inventory, track, and correct) all software on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
Inventory of information and other associated assets
SNow
State: PublishedCategory: Uncategorized
All Services including supporting components must be registered in the CMDB
Investigate and take action regarding help desk queries.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Investigate and take action regarding help desk queries.
Investigate the nature and causes of identified in scope control deviations.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Investigate the nature and causes of identified in scope control deviations.
Involve the Board of Directors in Information Governance.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Involve the Board of Directors in Information Governance.
Isolate compromised systems from the network.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Isolate compromised systems from the network.
Isolate rogue devices after they have been detected.
SNow
Classification: CorrectiveState: PublishedCategory: Technical security
Isolate rogue devices after they have been detected.
Issue authentication mechanisms that support the Public Key Infrastructure.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Issue authentication mechanisms that support the Public Key Infrastructure.
Issue devices with secure configurations to individuals traveling to locations deemed to be of risk.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Issue devices with secure configurations to individuals traveling to locations deemed to be of risk.
Issue visitor identification badges to all non-employees.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Issue visitor identification badges to all non-employees.
Justify the system's cost and benefit.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Justify the system's cost and benefit.
LOG-01 Logging and Monitoring Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.
LOG-02 Audit Logs Protection
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
LOG-03 Security Monitoring and Alerting
SNow
State: PublishedCategory: Uncategorized
Identify and monitor security-related events within applications and the underlying infrastructure. Define and implement a system to generate alerts to responsible stakeholders based on such events and corresponding metrics.
LOG-04 Audit Logs Access and Accountability
SNow
State: PublishedCategory: Uncategorized
Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.
LOG-05 Audit Logs Monitoring and Response
SNow
State: PublishedCategory: Uncategorized
Monitor security audit logs to detect activity outside of typical or expected patterns. Establish and follow a defined process to review and take appropriate and timely actions on detected anomalies.
LOG-06 Clock Synchronization
SNow
State: PublishedCategory: Uncategorized
Use a reliable time source across all relevant information processing systems.
LOG-07 Logging Scope
SNow
State: PublishedCategory: Uncategorized
Establish, document and implement which information meta/data system events should be logged. Review and update the scope at least annually or whenever there is a change in the threat environment.
LOG-08 Log Records
SNow
State: PublishedCategory: Uncategorized
Generate audit records containing relevant security information.
LOG-09 Log Protection
SNow
State: PublishedCategory: Uncategorized
The information system protects audit records from unauthorized access, modification, and deletion.
LOG-10 Encryption Monitoring and Reporting
SNow
State: PublishedCategory: Uncategorized
Establish and maintain a monitoring and internal reporting capability over the operations of cryptographic, encryption and key management policies, processes, procedures, and controls.
LOG-11 Transaction/Activity Logging
SNow
State: PublishedCategory: Uncategorized
Log and monitor key lifecycle management events to enable auditing and reporting on usage of cryptographic keys.
LOG-12 Access Control Logs
SNow
State: PublishedCategory: Uncategorized
Monitor and log physical access using an auditable access control system.
LOG-13 Failures and Anomalies Reporting
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for the reporting of anomalies and failures of the monitoring system and provide immediate notification to the accountable party.
Label printed output for specific record categories as directed by the organization's information classification standard.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Label printed output for specific record categories as directed by the organization's information classification standard.
Legitimate Interest
SNow
State: PublishedCategory: Uncategorized
Review the Legitimate Interest Assessment conducted in the PIA. If your processing activity is covered, ensure compliance with such LIA. If your processing activity is not convered, a new LIA must be conducted.
Legitimate Interest Assessment (LIA)
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
The Legitimate Interest Assessment (LIA) documents the key aspects to be considered when balancing the benefit to the Data Controller (e.g. Roche) against the potential impact/risk to the Data Subject (i.e. individual). This is required to support the decision that the "legitimate interest" of the
Leverage the Advanced Encryption Standard (AES) to Encrypt Wireless Data
SNow
Classification: ProtectState: PublishedCategory: Network
Leverage the Advanced Encryption Standard (AES) to encrypt wireless data in transit.
Limit Access to Script Tools
SNow
Classification: ProtectState: PublishedCategory: Users
Limit access to scripting tools (such as Microsoft PowerShell and Python) to only administrative or development users with the need to access those capabilities.
Limit Superuser accounts to designated System Administrators.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Limit Superuser accounts to designated System Administrators.
Limit Use of Scripting Languages in Web Browsers and Email Clients
SNow
Classification: ProtectState: PublishedCategory: Applications
Ensure that only authorized scripting languages are able to run in all web browsers and email clients.
Limit Wireless Access on Client Devices
SNow
Classification: ProtectState: PublishedCategory: Devices
Configure wireless access on client machines that do have an essential wireless business purpose, to allow access only to authorized wireless networks and to restrict access to other wireless networks.
Limit access to audit trails to a need to know basis.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Limit access to audit trails to a need to know basis.
Limit access to logs to a need to know basis.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Limit access to logs to a need to know basis.
Limit concurrent sessions according to account type.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Limit concurrent sessions according to account type.
Limitation and Control of Network Ports, Protocols, and Services
SNow
Classification: IdentifyState: PublishedCategory: Devices
Manage (track/control/correct) the ongoing operational use of ports, protocols, and services on networked devices in order to minimize windows of vulnerability available to attackers.
Local Worker´s Council Notice
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
For new software systems or services, ensure that local Worker's Councils (employees' representative bodies) are informed or involved as applicable.
Lock Antivirus configurations to prevent them from being disabled or changed by end users.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Lock Antivirus configurations to prevent them from being disabled or changed by end users.
Lock Workstation Sessions After Inactivity
SNow
Classification: ProtectState: PublishedCategory: Users
Automatically lock workstation sessions after a standard period of inactivity.
Lock closeable storage containers.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Lock closeable storage containers.
Lock personal firewall configurations to prevent them from being disabled or changed by end users.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Lock personal firewall configurations to prevent them from being disabled or changed by end users.
Log all URL requests
SNow
Classification: DetectState: PublishedCategory: Network
Log all URL requests from each of the organization's systems, whether onsite or a mobile device, in order to identify potentially malicious activity and assist incident handlers with identifying potentially compromised systems.
Log and Alert on Changes to Administrative Group Membership
SNow
Classification: DetectState: PublishedCategory: Users
Configure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges.
Log and Alert on Unsuccessful Administrative Account Login
SNow
Classification: DetectState: PublishedCategory: Users
Configure systems to issue a log entry and alert on unsuccessful logins to an administrative account.
Log and react to all malicious code activity.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Log and react to all malicious code activity.
Log help desk queries.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Log help desk queries.
Log incidents in the Incident Management audit log.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Log incidents in the Incident Management audit log.
Log the entrance of a staff member to a facility or designated rooms within the facility.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Log the entrance of a staff member to a facility or designated rooms within the facility.
Maintain Asset Inventory Information
SNow
Classification: IdentifyState: PublishedCategory: Devices
Ensure that the hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network.
Maintain Contact Information For Reporting Security Incidents
SNow
Classification: ProtectState: PublishedCategory: Users
Assemble and maintain information on third-party contact information to be used to report a security incident, such as Law Enforcement, relevant government departments, vendors, and ISAC partners.
Maintain Detailed Asset Inventory
SNow
Classification: IdentifyState: PublishedCategory: Devices
Maintain an accurate and up-to-date inventory of all technology assets with the potential to store or process information. This inventory shall include all hardware assets, whether connected to the organization's network or not.
Maintain Inventory of Administrative Accounts
SNow
Classification: DetectState: PublishedCategory: Users
Use automated tools to inventory all administrative accounts, including domain and local accounts, to ensure that only authorized individuals have elevated privileges.
Maintain Inventory of Authorized Software
SNow
Classification: IdentifyState: PublishedCategory: Applications
Maintain an up-to-date list of all authorized software that is required in the enterprise for any business purpose on any business system.
Maintain Secure Images
SNow
Classification: ProtectState: PublishedCategory: Applications
Maintain secure images or templates for all systems in the enterprise based on the organization's approved configuration standards. Any new system deployment or existing system that becomes compromised should be imaged using one of those images or templates.
Maintain Standard Security Configurations for Network Devices
SNow
Classification: IdentifyState: PublishedCategory: Network
Maintain standard, documented security configuration standards for all authorized network devices.
Maintain an Inventory of Accounts
SNow
Classification: IdentifyState: PublishedCategory: Users
Maintain an inventory of all accounts organized by authentication system.
Maintain an Inventory of Authentication Systems
SNow
Classification: IdentifyState: PublishedCategory: Users
Maintain an inventory of each of the organization's authentication systems, including those located onsite or at a remote service provider.
Maintain an Inventory of Authorized Wireless Access Points
SNow
Classification: IdentifyState: PublishedCategory: Network
Maintain an inventory of authorized wireless access points connected to the wired network.
Maintain an Inventory of Network Boundaries
SNow
Classification: IdentifyState: PublishedCategory: Network
Maintain an up-to-date inventory of all of the organization's network boundaries.
Maintain an Inventory of Sensitive Information
SNow
Classification: IdentifyState: PublishedCategory: Data
Maintain an inventory of all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider.
Maintain and Enforce Network-Based URL Filters
SNow
Classification: ProtectState: PublishedCategory: Network
Enforce network-based URL filters that limit a system's ability to connect to websites not approved by the organization. This filtering shall be enforced for each of the organization's systems, whether they are physically at an organization's facilities or not.
Maintain and review facility access lists of personnel who have been granted authorized entry to (and within) facilities that contain restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Maintain and review facility access lists of personnel who have been granted authorized entry to (and within) facilities that contain restricted data or restricted information.
Maintain media sanitization equipment in operational condition.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Maintain media sanitization equipment in operational condition.
Maintain personal data in a form that does not permit the identification of data subjects for longer than the processing purpose.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Maintain personal data in a form that does not permit the identification of data subjects for longer than the processing purpose.
Maintain up-to-date network diagrams.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Maintain up-to-date network diagrams.
Maintenance, Monitoring and Analysis of Audit Logs
SNow
Classification: DetectState: PublishedCategory: Network
Collect, manage, and analyze audit logs of events that could help detect, understand, or recover from an attack.
Malware Defenses
SNow
Classification: ProtectState: PublishedCategory: Devices
Install AV and run updates regularly. This has been ingrained in IT professionals for decades. The only key aspects is to make sure the AV solution meets the needs of your organization in terms of capabilities.
Manage All Devices Remotely Logging into Internal Network
SNow
Classification: ProtectState: PublishedCategory: Devices
Scan all enterprise devices remotely logging into the organization's network prior to accessing the network to ensure that each of the organization's security policies has been enforced in the same manner as local network devices.
Manage Network Devices Using Multi-Factor Authentication and Encrypted Sessions
SNow
Classification: ProtectState: PublishedCategory: Network
Manage all network devices using multi-factor authentication and encrypted sessions.
Manage Network Infrastructure Through a Dedicated Network
SNow
Classification: ProtectState: PublishedCategory: Network
Manage the network infrastructure across network connections that are separated from the business use of that network, relying on separate VLANs or, preferably, on entirely different physical connectivity for management sessions for network devices.
Manage System's External Removable Media's Read/write Configurations
SNow
Classification: ProtectState: PublishedCategory: Data
Configure systems not to write data to external removable media, if there is no business need for supporting such devices.
Manage USB Devices
SNow
Classification: ProtectState: PublishedCategory: Data
If USB storage devices are required, enterprise software should be used that can configure systems to allow the use of specific devices. An inventory of such devices should be maintained.
Manage access to loading docks, unloading docks, and mail rooms.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Manage access to loading docks, unloading docks, and mail rooms.
Manage all internal network connections and external network connections.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Manage all internal network connections and external network connections.
Manage and maintain user accounts according to organizationally documented policies and procedures.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Manage and maintain user accounts according to organizationally documented policies and procedures.
Manage change requests.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Manage change requests.
Manage changes.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Manage changes.
Manage outdated, compromised, or revoked encryption keys.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Manage outdated, compromised, or revoked encryption keys.
Manage the disposition status for all records.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Manage the disposition status for all records.
Manage the use of encryption and cryptographic controls to protect information.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Manage the use of encryption and cryptographic controls to protect information.
Manage third party audits.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Manage third party audits.
Manage visitor identification inside the facility.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Manage visitor identification inside the facility.
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines.
SNow
Classification: IdentifyState: PublishedCategory: System hardening through configuration management
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines. In case the manufacturing system, network or any related change is not in line with Roche Manufacturing Cybersecurity requirements, a formal Exception approval need t
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines. Any exception needs to be processed according to PL ID 24636342 MC Change and Exceptions Management.
SNow
Classification: CorrectiveState: PublishedCategory: System hardening through configuration management
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines. In case the manufacturing system, network or any related change is not in line with Roche Manufacturing Cybersecurity requirements, a formal Exception approval need t
Measure policy compliance when reviewing the internal control framework.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Measure policy compliance when reviewing the internal control framework.
Mirror the organization's business strategy during Information Technology planning in the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Mirror the organization's business strategy during Information Technology planning in the Strategic Information Technology Plan.
Monitor Attempts to Access Deactivated Accounts
SNow
Classification: DetectState: PublishedCategory: Users
Monitor attempts to access deactivated accounts through audit logging.
Monitor and Block Unauthorized Network Traffic
SNow
Classification: DetectState: PublishedCategory: Data
Deploy an automated tool on network perimeters that monitors for unauthorized transfer of sensitive information and blocks such transfers while alerting information security professionals.
Monitor and Detect Any Unauthorized Use of Encryption
SNow
Classification: DetectState: PublishedCategory: Data
Monitor all traffic leaving the organization and detect any unauthorized use of encryption.
Monitor and evaluate all remote access usage.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Monitor and evaluate all remote access usage.
Monitor and evaluate system performance.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor and evaluate system performance.
Monitor and evaluate the implementation and effectiveness of Information Technology Plans.
SNow
Classification: DetectiveState: PublishedCategory: Leadership and high level objectives
Monitor and evaluate the implementation and effectiveness of Information Technology Plans.
Monitor and evaluate user account activity.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor and evaluate user account activity.
Monitor and measure the effectiveness of security awareness.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Monitor and measure the effectiveness of security awareness.
Monitor and report on the efficacy of all Service Level Agreements using a Service Level Agreement Monitoring Chart or equivalent.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Monitor and report on the efficacy of all Service Level Agreements using a Service Level Agreement Monitoring Chart or equivalent.
Monitor compliance with the Quality Control system.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Monitor compliance with the Quality Control system.
Monitor continuously for threats.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Monitor continuously for threats.
Monitor devices continuously for conformance with production specifications.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor devices continuously for conformance with production specifications.
Monitor entry through all physical entry points.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Monitor entry through all physical entry points.
Monitor for and react to when suspicious activities are detected.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Monitor for and react to when suspicious activities are detected.
Monitor for and report when a software configuration is updated.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor for and report when a software configuration is updated.
Monitor for firmware updates absent authorization.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor for firmware updates absent authorization.
Monitor for new vulnerabilities.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Monitor for new vulnerabilities.
Monitor for software configurations updates absent authorization.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Monitor for software configurations updates absent authorization.
Monitor for sufficicient system capacity.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Monitor for sufficicient system capacity.
Monitor for unauthorized physical access at physical entry points.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Monitor for unauthorized physical access at physical entry points.
Monitor for when documents are being updated absent authorization.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Monitor for when documents are being updated absent authorization.
Monitor personnel and third parties for compliance to the organizational compliance framework.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor personnel and third parties for compliance to the organizational compliance framework.
Monitor physical entry point alarms.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Monitor physical entry point alarms.
Monitor restricted areas with motion detectors or Closed-Circuit Television systems.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Monitor restricted areas with motion detectors or Closed-Circuit Television systems.
Monitor systems for Denial of Service attacks.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor systems for Denial of Service attacks.
Monitor systems for access to restricted data or restricted information.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor systems for access to restricted data or restricted information.
Monitor systems for blended attacks and multiple component incidents.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor systems for blended attacks and multiple component incidents.
Monitor systems for inappropriate usage and other security violations.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor systems for inappropriate usage and other security violations.
Monitor systems for unauthorized mobile code.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Monitor systems for unauthorized mobile code.
Monitor the activities to correct control deficiencies identified in an audit.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor the activities to correct control deficiencies identified in an audit.
Monitor the usage and capacity of critical IT assets.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Monitor the usage and capacity of critical IT assets.
Monitor third parties when they deliver services.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Monitor third parties when they deliver services.
Monitoring
Mapping
Category: Mapping
Notify affected parties to keep passwords confidential.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Notify affected parties to keep passwords confidential.
Notify all interested personnel and affected parties when personnel status changes or an individual is terminated.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Notify all interested personnel and affected parties when personnel status changes or an individual is terminated.
Notify designated personnel when a formal personnel sanctions process is initiated.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Notify designated personnel when a formal personnel sanctions process is initiated.
Notify individuals of their right to challenge personal data.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Notify individuals of their right to challenge personal data.
Notify organizational unit leaders prior to when the system is redeployed or the system is disposed.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Notify organizational unit leaders prior to when the system is redeployed or the system is disposed.
Notify the interested personnel and affected parties after the failure of an automated security test.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Notify the interested personnel and affected parties after the failure of an automated security test.
Notify the interested personnel and affected parties before the storage unit will reach maximum capacity.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Notify the interested personnel and affected parties before the storage unit will reach maximum capacity.
ODC has formally documented Business Continuity and Disaster Recovery Plans
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Obtain management authorization for restricted storage media transit or distribution from a secure area.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Obtain management authorization for restricted storage media transit or distribution from a secure area.
Obtain system documentation before acquiring products and services.
SNow
Classification: PreventiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Obtain system documentation before acquiring products and services.
Only Allow Access to Authorized Cloud Storage or Email Providers
SNow
Classification: ProtectState: PublishedCategory: Data
Only allow access to authorized cloud storage or email providers.
Only Use Up-to-date And Trusted Third-Party Components
SNow
Classification: ProtectState: PublishedCategory: Applications
Only use up-to-date and trusted third-party components for the software developed by the organization.
Only traffic with clear business purpose should be allowed for the manufacturing system.
SNow
Classification: ProtectState: PublishedCategory: System hardening through configuration management
Only traffic with clear business purpose should be allowed for the manufacturing system.
Operationalize key monitoring and logging concepts to ensure the audit trails capture sufficient information.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Operationalize key monitoring and logging concepts to ensure the audit trails capture sufficient information.
Outline explicit mitigation actions for facility accessibility issues that might take place when an area-wide disruption occurs or an area-wide disaster occurs.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Outline explicit mitigation actions for facility accessibility issues that might take place when an area-wide disruption occurs or an area-wide disaster occurs.
Outline explicit mitigation actions for potential off-site electronic media storage facilities accessibility issues for when area-wide disruptions occur or area-wide disasters occur.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Outline explicit mitigation actions for potential off-site electronic media storage facilities accessibility issues for when area-wide disruptions occur or area-wide disasters occur.
PCI DSS Compliance (Credit Card Data Processing)
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Processes which involve the storing, processing or transmission of credit card data shall assess the applicability of the Payment Card Industry Data Security Standard (PCI DSS) and comply with it as required.
Password Settings
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
Password settings must adhere to the Roche Password Management Standard.
Patch Management for Security and Compliance
SNow
Classification: PreventiveState: PublishedCategory: Vulnerability and Configuration Analysis
Ensure that a professional security patch management process is established (or supported) to maintain up-to-date, vendor-supported software and the installation of security patches and software updates to address security vulnerabilities.
Perform Audit Trail Review
SNow
State: PublishedCategory: Periodic Review
An Audit Trail review process exists and is executed, if needed based on a documented assessment.
Perform Authenticated Vulnerability Scanning
SNow
Classification: DetectState: PublishedCategory: Applications
Perform authenticated vulnerability scanning with agents running locally on each system or with remote scanners that are configured with elevated rights on the system being tested.
Perform Change Management
SNow
State: PublishedCategory: Periodic Review
Changes are implemented following effective procedures.
Perform Complete System Backups
SNow
Classification: ProtectState: PublishedCategory: Data
Ensure that each of the organization's key systems are backed up as a complete system, through processes such as imaging, to enable the quick recovery of an entire system.
Perform Periodic Red Team Exercises
SNow
Classification: DetectState: PublishedCategory: Users
Perform periodic Red Team exercises to test organizational readiness to identify and stop attacks or to respond quickly and effectively.
Perform Quality Management on all newly developed or modified software.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Perform Quality Management on all newly developed or modified software.
Perform Quality Management on all newly developed or modified systems.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Perform Quality Management on all newly developed or modified systems.
Perform Regular Automated Port Scans
SNow
Classification: DetectState: PublishedCategory: Devices
Perform automated port scans on a regular basis against all systems and alert if unauthorized ports are detected on a system.
Perform System Performance Monitoring
SNow
State: PublishedCategory: Periodic Review
The performance and availability of the CS application, server(s), network, security, and other supporting infrastructure is monitored as part of day-to-day operations.
Perform System Risk Assessment (SRA)
SNow
State: PublishedCategory: Periodic Review
SRA kept up-to-date in regards to intended use of the system and resulting controls are implemented as needed.
Perform User Access Review
SNow
State: PublishedCategory: Periodic Review
User access of End-users and IT technical personnel, including privileged users, is reviewed on a regular basis.
Perform a Skills Gap Analysis
SNow
Classification: IdentifyState: PublishedCategory: Users
Perform a skills gap analysis to understand the skills and behaviors workforce members are not adhering to, using this information to build a baseline education roadmap.
Perform a final acceptance test prior to implementing a new system.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Perform a final acceptance test prior to implementing a new system.
Perform a gap analysis to review in scope controls for identified risks and implement new controls, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Perform a gap analysis to review in scope controls for identified risks and implement new controls, as necessary.
Perform a patch test prior to deploying a patch.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Perform a patch test prior to deploying a patch.
Perform a risk assessment for each system development project.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Perform a risk assessment for each system development project.
Perform a risk assessment prior to activating third party access to the organization's critical systems.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Perform a risk assessment prior to activating third party access to the organization's critical systems.
Perform a risk assessment prior to engaging a third party.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Perform a risk assessment prior to engaging a third party.
Perform application-layer penetration testing on all systems, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Perform application-layer penetration testing on all systems, as necessary.
Perform backup procedures for in scope systems.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Perform backup procedures for in scope systems.
Perform content filtering scans on network traffic.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Perform content filtering scans on network traffic.
Perform internal vulnerability scans on the organization's systems.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Perform internal vulnerability scans on the organization's systems.
Perform maintenance in a timely manner.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Perform maintenance in a timely manner.
Perform network-layer penetration testing on all systems, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Perform network-layer penetration testing on all systems, as necessary.
Perform personnel screening procedures, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Perform personnel screening procedures, as necessary.
Perform risk assessments prior to approving change requests.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Perform risk assessments prior to approving change requests.
Perform security clearance procedures, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Perform security clearance procedures, as necessary.
Perform vulnerability scanning on a regular basis.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Perform vulnerability scanning on a regular basis.
Permission Management
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
Roles must first be defined based on which system, application, or data the entity/user is allowed or not allowed to access. An access-control mechanism must then be used to grant, change or revoke the right to use a particular service or access certain assets.
Physical Entry
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Physical Entry
Physical Security Monitoring
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Physical Security Monitoring
Physical and environmental protection
SNow
Classification: IT Impact ZoneState: PublishedCategory: Physical and environmental protection
Physical and environmental protection
Physical security perimeters
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Physical security perimeters
Physically or Logically Segregate High Risk Applications
SNow
Classification: ProtectState: PublishedCategory: Applications
Physically or logically segregated systems should be used to isolate and run software that is required for business operations but incur higher risk for the organization.
Physically secure all electronic storage media that store restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Physically secure all electronic storage media that store restricted data or restricted information.
Place Information Technology operations in a position to support the business model.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Place Information Technology operations in a position to support the business model.
Place Intrusion Detection Systems and intrusion response systems in network locations where they will be the most effective.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Place Intrusion Detection Systems and intrusion response systems in network locations where they will be the most effective.
Place firewalls between all security domains and between any Demilitarized Zone and internal network zones.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Place firewalls between all security domains and between any Demilitarized Zone and internal network zones.
Place firewalls between all security domains and between any secure subnet and internal network zones.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Place firewalls between all security domains and between any secure subnet and internal network zones.
Place perimeter firewalls between wireless networks and applications or databases that contain restricted data or restricted information and completely deny or strictly control wireless traffic to these applications and databases.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Place perimeter firewalls between wireless networks and applications or databases that contain restricted data or restricted information and completely deny or strictly control wireless traffic to these applications and databases.
Plan and conduct maintenance so that it does not interfere with scheduled operations.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Plan and conduct maintenance so that it does not interfere with scheduled operations.
Plan and document the Certification and Accreditation process.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Plan and document the Certification and Accreditation process.
Plan for and approve all network changes.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Plan for and approve all network changes.
Platform Operational Governance
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
A platform operational governance framework document shall be created, approved with clear roles & responsibilities (governing body) for all enterprise wide platforms/systems. The framework shall include terms of use, application on-boarding process, development/deployment best practices, legal/priv
Policies for information security
SNow
State: PublishedCategory: Uncategorized
All Services should adhere to Roche Information Security Policies / Standard / Processes
Position computer monitors in such a way that unauthorized personnel are prevented from viewing them.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Position computer monitors in such a way that unauthorized personnel are prevented from viewing them.
Post all required information on organizational websites and ensure all hyperlinks are working.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Post all required information on organizational websites and ensure all hyperlinks are working.
Post the privacy policy in an easily seen location.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Post the privacy policy in an easily seen location.
Prepare an annual Information Technology budget.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Prepare an annual Information Technology budget.
Prepare for incident response notifications.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Prepare for incident response notifications.
Prepare the alternate facility for an emergency offsite relocation.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Prepare the alternate facility for an emergency offsite relocation.
Prevent Loss of Data using Backup and Restore
SNow
Classification: PreventiveState: PublishedCategory: Vulnerability and Configuration Analysis
Prevent data loss in systems containing business critical, C4, or Sensitive personal data by scheduling and executing data backups and restore testing procedures to address availability and compliance requirements of the system and data. It must also be ensured that backup data is adequately secured
Prevent the unauthorized substitution of cryptographic keys.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Prevent the unauthorized substitution of cryptographic keys.
Prioritize and select controls based on the risk assessment findings.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Prioritize and select controls based on the risk assessment findings.
Prioritize deploying patches according to vulnerability risk metrics.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Prioritize deploying patches according to vulnerability risk metrics.
Privacy Notice
SNow
State: PublishedCategory: Uncategorized
Data subjects need to be informed about the processing of their personal data and regarding their data subject rights. Explain how the privacy notice will be provided to the data subject and add the link to the privacy notice if available.
Privacy Registry Entries
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Maintain up-to-date information related to the solution or service in the Roche Privacy Register as required by the applicable data privacy laws and regulations
Privileged Access Management
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
Protecting credentials with privileged access to IT systems, services, applications and data is critical to the overall security of Roche IT solutions and information assets. This control enables the enforcement, management, and auditing of these credentials through a set of policies, services, and
Prohibit data elements containing payment card security codes (Card Authentication Value 2, Card Validation Code Value 2, Card Verification Value 2, Card Identification Number) from being stored.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Prohibit data elements containing payment card security codes (Card Authentication Value 2, Card Validation Code Value 2, Card Verification Value 2, Card Identification Number) from being stored.
Prohibit personal data from being sent by e-mail or instant messaging.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Prohibit personal data from being sent by e-mail or instant messaging.
Prohibit restricted data or restricted information from being copied or moved absent approval of system boundaries for information flow control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Prohibit restricted data or restricted information from being copied or moved absent approval of system boundaries for information flow control.
Prohibit systems from connecting directly to external networks.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Prohibit systems from connecting directly to external networks.
Prohibit the unauthorized remote activation of collaborative computing devices.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Prohibit the unauthorized remote activation of collaborative computing devices.
Prohibit the use of binary code or machine-executable code from sources with limited or no warranty absent the source code.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Prohibit the use of binary code or machine-executable code from sources with limited or no warranty absent the source code.
Protect Data at Rest
SNow
Classification: PreventiveState: PublishedCategory: Encryption
Data should be adequately protected when stored. Beyond appropriate access control, an additional control is to store the data in encrypted form (Encryption at Rest) to protect against unauthorized access and/or modification. There are several options for encrypting data at rest and choosing the rig
Protect Data at rest
SNow
State: RetiredCategory: Uncategorized
Protect Data in Transit
SNow
Classification: PreventiveState: PublishedCategory: Encryption
Protects data if communications are intercepted while data moves between two endpoints (e.g. clients, systems, service). This protection is achieved by encrypting the data before transmission, authenticating the endpoints, and decrypting and verifying the data on arrival.
Protect Data in transit
SNow
State: RetiredCategory: Uncategorized
Protect Dedicated Assessment Accounts
SNow
Classification: ProtectState: PublishedCategory: Users
Use a dedicated account for authenticated vulnerability scans, which should not be used for any other administrative activities and should be tied to specific machines at specific IP addresses.
Protect Information through Access Control Lists
SNow
Classification: ProtectState: PublishedCategory: Data
Protect all information stored on systems with file system, network share, claims, application, or database specific access control lists. These controls will enforce the principle that only authorized individuals should have access to the information based on their need to access the information as
Protect data from modification, loss, and unauthorized disclosure while transmitting between separate parts of the system.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Protect data from modification, loss, and unauthorized disclosure while transmitting between separate parts of the system.
Protect each person's right to privacy and civil liberties during intrusion management operations.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Protect each person's right to privacy and civil liberties during intrusion management operations.
Protect logs from unauthorized activity.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Protect logs from unauthorized activity.
Protect physical assets from water damage.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Protect physical assets from water damage.
Protect policies, standards, and procedures from unauthorized modification or disclosure.
SNow
Classification: PreventiveState: PublishedCategory: Deprecated
Protect policies, standards, and procedures from unauthorized modification or disclosure.
Protect power equipment and power cabling from damage or destruction.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Protect power equipment and power cabling from damage or destruction.
Protect remote access accounts with encryption.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Protect remote access accounts with encryption.
Protect the event logs from failure.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Protect the event logs from failure.
Protect the system against replay attacks.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Protect the system against replay attacks.
Protecting against physical and environmental threats
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Protecting against physical and environmental threats
Protection from Denial of Service Attacks
SNow
Classification: PreventiveState: PublishedCategory: Network and Infrastructure
Protection from a Denial-of-Service attack (DoS, DDoS) is intended to keep a network service available despite criminal attacks attempting to interrupt or damage the Roche Network service's availability by overwhelming it with malicious traffic.
Provide a physical disconnect of collaborative computing devices in a way that supports ease of use.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Provide a physical disconnect of collaborative computing devices in a way that supports ease of use.
Provide auditors access to all in scope records, in scope assets, personnel and in scope procedures.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Provide auditors access to all in scope records, in scope assets, personnel and in scope procedures.
Provide encryption for different types of electronic storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Provide encryption for different types of electronic storage media.
Provide transaction authorization.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Provide transaction authorization.
Provide transactional walkthrough procedures for external auditors.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Provide transactional walkthrough procedures for external auditors.
Publish Information Regarding Reporting Computer Anomalies and Incidents
SNow
Classification: ProtectState: PublishedCategory: Users
Publish information for all workforce members, regarding reporting computer anomalies and incidents to the incident handling team. Such information should be included in routine employee awareness activities.
Publish revoked Public Key certificates in the Certificate Revocation List.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Publish revoked Public Key certificates in the Certificate Revocation List.
Purpose of the processing activity
SNow
State: PublishedCategory: Uncategorized
Personal data must be collected for specified, explicit, and legitimate purposes: ensure the personal data is collected for a specific purpose and clearly define the purposes for which the personal data will be processed within the solution.
Reassess the system design after the product has been tested.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Reassess the system design after the product has been tested.
Recommend mitigation techniques based on penetration test results.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Recommend mitigation techniques based on penetration test results.
Reconfigure restored systems to meet the Recovery Point Objectives.
SNow
Classification: CorrectiveState: PublishedCategory: Systems continuity
Reconfigure restored systems to meet the Recovery Point Objectives.
Reconfigure the encryption keys from their default setting or previous setting.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Reconfigure the encryption keys from their default setting or previous setting.
Record Configuration Management items in the Configuration Management database.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Record Configuration Management items in the Configuration Management database.
Record the manufacturer's serial number for applicable assets in the asset inventory.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Record the manufacturer's serial number for applicable assets in the asset inventory.
Record the owner for applicable assets in the asset inventory.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Record the owner for applicable assets in the asset inventory.
Record the physical location for applicable assets in the asset inventory.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Record the physical location for applicable assets in the asset inventory.
Records management
SNow
Classification: IT Impact ZoneState: PublishedCategory: Records management
Records management
Recover encrypted data for lost cryptographic keys, compromised cryptographic keys, or damaged cryptographic keys.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Recover encrypted data for lost cryptographic keys, compromised cryptographic keys, or damaged cryptographic keys.
Redesign business activities to support the system implementation.
SNow
Classification: CorrectiveState: PublishedCategory: Systems design, build, and implementation
Redesign business activities to support the system implementation.
Refrain from sharing a single point of failure between the alternate telecommunications service providers and the primary telecommunications service providers.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Refrain from sharing a single point of failure between the alternate telecommunications service providers and the primary telecommunications service providers.
Regularly Review Logs
SNow
Classification: DetectState: PublishedCategory: Network
On a regular basis, review logs to identify anomalies or abnormal events.
Regularly Tune SIEM
SNow
Classification: DetectState: PublishedCategory: Network
On a regular basis, tune your SIEM system to better identify actionable events and decrease event noise.
Remote access to the manufacturing system or its component for 3rd party vendors should be under service terms and conditions, with liability for incidents due to weak cyber security practices.
SNow
Classification: IdentifyState: PublishedCategory: Governance, Risk and Compliance
Remote access to the manufacturing system or its component for 3rd party vendors should be under service terms and conditions, with liability for incidents due to weak cyber security practices.
Remote access to the manufacturing system or its component from public zone (outside of Roche network) should be done via VPN with at least two-factor authentication and with utilization of jump stations.
SNow
Classification: ProtectState: PublishedCategory: Technical Security
Remote access to the manufacturing system or its component from public zone (outside of Roche network) should be done via VPN with at least two-factor authentication and with utilization of jump stations.
Remote access to the manufacturing system or its component should be performed only via solution compliant with requirements defined within the DIA OT CS Remote Access best practices use cases and requirements for supporting and security services for
SNow
Classification: ProtectState: PublishedCategory: Technical security
Remote access to the manufacturing system or its component should be performed only via solution compliant with requirements defined within the PL ID 22984490 Use cases and requirements for supporting and security services for manufacturing systems.
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
Remote access to the manufacturing system or its component should be performed only via solution compliant with requirements defined within the PL ID 22984490 Use cases and requirements for supporting and security services for manufacturing systems.
Remote sessions should be recorded or activities should be logged.
SNow
Classification: DetectState: PublishedCategory: Logging, Monitoring, Threat Detection, and Analytics
Remote sessions should be recorded or activities should be logged.
Remove Sensitive Data or Systems Not Regularly Accessed by Organization
SNow
Classification: ProtectState: PublishedCategory: Data
Remove sensitive data or systems not regularly accessed by the organization from the network. These systems shall only be used as stand alone systems (disconnected from the network) by the business unit needing to occasionally use the system or completely virtualized and powered off until needed.
Remove all compilers and assemblers from the system.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Remove all compilers and assemblers from the system.
Remove all unauthorized Wireless Local Area Networks and Wireless Access Points.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Remove all unauthorized Wireless Local Area Networks and Wireless Access Points.
Remove all unnecessary functionality.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Remove all unnecessary functionality.
Remove and/or destroy records according to the records' retention event and retention period schedule.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Remove and/or destroy records according to the records' retention event and retention period schedule.
Remove inactive user accounts and temporary user accounts at least every 90 days.
SNow
Classification: CorrectiveState: PublishedCategory: Technical security
Remove inactive user accounts and temporary user accounts at least every 90 days.
Remove test information before releasing the system into a production environment.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Remove test information before releasing the system into a production environment.
Remove unnecessary default user accounts.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Remove unnecessary default user accounts.
Report compliance monitoring statistics to the Board of Directors and other key stakeholders, as necessary.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Report compliance monitoring statistics to the Board of Directors and other key stakeholders, as necessary.
Report data loss events to breach notification organizations.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Report data loss events to breach notification organizations.
Report on the mean time from patch availability to patch installation.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Report on the mean time from patch availability to patch installation.
Require All Remote Login to Use Multi-factor Authentication
SNow
Classification: ProtectState: PublishedCategory: Users
Require all remote login access to the organization's network to encrypt data in transit and use multi-factor authentication.
Require Multi-factor Authentication
SNow
Classification: ProtectState: PublishedCategory: Users
Require multi-factor authentication for all user accounts, on all systems, whether managed onsite or by a third-party provider.
Require interested personnel and affected parties to re-sign Acceptable Use Policies, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Require interested personnel and affected parties to re-sign Acceptable Use Policies, as necessary.
Require interested personnel and affected parties to sign Acceptable Use Policies.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Require interested personnel and affected parties to sign Acceptable Use Policies.
Require key custodians to sign the key custodian's roles and responsibilities.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Require key custodians to sign the key custodian's roles and responsibilities.
Require personnel to acknowledge, through writing their signature, that they have read and understand the organization's security policies.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Require personnel to acknowledge, through writing their signature, that they have read and understand the organization's security policies.
Require proper authentication for user identifiers.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Require proper authentication for user identifiers.
Require telecommunications service providers to have adequate continuity plans.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Require telecommunications service providers to have adequate continuity plans.
Require the Information System developer to create a Security Testing and Evaluation plan, implement the test, and provide the test results for all newly acquired Information Technology assets.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Require the Information System developer to create a Security Testing and Evaluation plan, implement the test, and provide the test results for all newly acquired Information Technology assets.
Require the Information System developer to have a Configuration Management plan for all newly acquired information technology assets.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Require the Information System developer to have a Configuration Management plan for all newly acquired information technology assets.
Require the audit report to be complete.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Require the audit report to be complete.
Require the return of all assets upon notification an individual is terminated.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Require the return of all assets upon notification an individual is terminated.
Require third parties to maintain a compliance framework equivalent to that of the organization's compliance requirements.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Require third parties to maintain a compliance framework equivalent to that of the organization's compliance requirements.
Respective information about the manufacturing system and relevant system stakeholders should be up to date in the OT Asset Inventory (CMDB) in order to enable communication during Incident Response service provision.
SNow
Classification: RespondState: PublishedCategory: Logging, Monitoring, Threat Detection, and Analytics
Respective information about the manufacturing system and relevant system stakeholders should be up to date in the OT Asset Inventory (CMDB) in order to enable communication during Incident Response service provision.
Respond to all alerts from security systems in a timely manner.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Respond to all alerts from security systems in a timely manner.
Respond to and triage when a security incident is detected.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Respond to and triage when a security incident is detected.
Respond to maintenance requests inside the organizationally established timeframe.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Respond to maintenance requests inside the organizationally established timeframe.
Restart systems when an integrity violation is detected, as necessary.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Restart systems when an integrity violation is detected, as necessary.
Restrict access to cryptographic keys.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Restrict access to cryptographic keys.
Restrict access to time server configuration to personnel with a business need.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Restrict access to time server configuration to personnel with a business need.
Restrict inbound Internet traffic inside the Demilitarized Zone.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Restrict inbound Internet traffic inside the Demilitarized Zone.
Restrict outbound network traffic from systems that contain restricted data or restricted information.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Restrict outbound network traffic from systems that contain restricted data or restricted information.
Restrict production data from being used in the test environment.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Restrict production data from being used in the test environment.
Restrict system architects from being assigned as Administrators.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Restrict system architects from being assigned as Administrators.
Restrict the development team from having access to the production environment.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Restrict the development team from having access to the production environment.
Retain all records in the visitor log as prescribed by law.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Retain all records in the visitor log as prescribed by law.
Retain copies of external auditor outsourcing contracts and engagement letters.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Retain copies of external auditor outsourcing contracts and engagement letters.
Retain penetration test remediation action records according to internal policy.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Retain penetration test remediation action records according to internal policy.
Retain records in accordance with applicable regulations.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Retain records in accordance with applicable regulations.
Retain video events according to Records Management procedures.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Retain video events according to Records Management procedures.
Retrain all personnel annually or as appropriate.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Retrain all personnel annually or as appropriate.
Retrieve visitor identification badges prior to the exit of a visitor from the facility.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Retrieve visitor identification badges prior to the exit of a visitor from the facility.
Review accounts and access rights when notified of personnel status changes.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Review accounts and access rights when notified of personnel status changes.
Review all Service Level Agreements.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Review all Service Level Agreements.
Review all access privileges at least annually.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Review all access privileges at least annually.
Review all contracts.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Review all contracts.
Review all third party's continuity plan exercise test results.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Review all third party's continuity plan exercise test results.
Review and agree with the risk assessment findings.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review and agree with the risk assessment findings.
Review and approve all custom code test results before code is released.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Review and approve all custom code test results before code is released.
Review and approve logical access to all assets based upon organizational policies.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Review and approve logical access to all assets based upon organizational policies.
Review and prioritize the importance of each business unit.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Review and prioritize the importance of each business unit.
Review and restrict network addresses and network protocols.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Review and restrict network addresses and network protocols.
Review and terminate accounts or terminate access rights when notified than an individual is terminated.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Review and terminate accounts or terminate access rights when notified than an individual is terminated.
Review and test custom code to identify potential coding vulnerabilities.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Review and test custom code to identify potential coding vulnerabilities.
Review and test source code.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Review and test source code.
Review and update staff position risk designations, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Review and update staff position risk designations, as necessary.
Review and update the Governance, Risk, and Compliance framework, as necessary.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Review and update the Governance, Risk, and Compliance framework, as necessary.
Review and update the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Review and update the continuity plan.
Review and update the incident response procedures after a security incident has been closed.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Review and update the incident response procedures after a security incident has been closed.
Review and update the list of auditable events in the event logging procedures.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Review and update the list of auditable events in the event logging procedures.
Review each system's operational readiness.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Review each system's operational readiness.
Review event logs, Intrusion Detection System reports, security incident tracking reports, and other security logs regularly.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Review event logs, Intrusion Detection System reports, security incident tracking reports, and other security logs regularly.
Review external auditor outsourcing contracts and engagement letters.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review external auditor outsourcing contracts and engagement letters.
Review facility access lists.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Review facility access lists.
Review management's response to issues raised in past audit reports.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review management's response to issues raised in past audit reports.
Review organizational personnel successes.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Review organizational personnel successes.
Review past audit reports for specific process steps and calculations that were stated to support the audit report's conclusions.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review past audit reports for specific process steps and calculations that were stated to support the audit report's conclusions.
Review past audit reports.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review past audit reports.
Review physical access logs, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Review physical access logs, as necessary.
Review the Access Control policies, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Review the Access Control policies, as necessary.
Review the Access Control procedures, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Review the Access Control procedures, as necessary.
Review the adequacy of the external auditor's work papers and audit reports.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review the adequacy of the external auditor's work papers and audit reports.
Review the adequacy of the internal auditor's audit reports.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review the adequacy of the internal auditor's audit reports.
Review the adequacy of the internal auditor's work papers.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review the adequacy of the internal auditor's work papers.
Review the alternate facility preparation procedures.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Review the alternate facility preparation procedures.
Review the audit assertion furnished by the organization for accuracy.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review the audit assertion furnished by the organization for accuracy.
Review the audit program scope as it relates to the organization's profile.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review the audit program scope as it relates to the organization's profile.
Review the audit scope when the Risk Profile is updated.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review the audit scope when the Risk Profile is updated.
Review the compliance exceptions Exceptions document annually.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Review the compliance exceptions Exceptions document annually.
Review the conclusions of the external auditor's work papers and audit reports.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review the conclusions of the external auditor's work papers and audit reports.
Review the configuration change log.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Review the configuration change log.
Review the current published guidance and awareness and training programs.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Review the current published guidance and awareness and training programs.
Review the external auditor's qualifications.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review the external auditor's qualifications.
Review the external auditors involvement in assessing Information Technology controls.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review the external auditors involvement in assessing Information Technology controls.
Review the firewall rules quarterly or when there are network changes.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Review the firewall rules quarterly or when there are network changes.
Review the internal control framework, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Review the internal control framework, as necessary.
Review the issues of non-compliance from past audit reports.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Review the issues of non-compliance from past audit reports.
Review the risk assessment procedures, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Review the risk assessment procedures, as necessary.
Review the security of the off-site electronic media storage facilities, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Review the security of the off-site electronic media storage facilities, as necessary.
Review user accounts and shared accounts.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Review user accounts and shared accounts.
Review visitor logs, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Review visitor logs, as necessary.
Revoke asset access when an individual is terminated.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Revoke asset access when an individual is terminated.
Roche Digital Channel Registry Entry
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
It must be ensured that all Roche digital channels (e.g., web and mobile applications, social media accounts ) are included in Roche Digital Registry.
Run Automated Vulnerability Scanning Tools
SNow
Classification: DetectState: PublishedCategory: Applications
Utilize an up-to-date SCAP-compliant vulnerability scanning tool to automatically scan all systems on the network on a weekly or more frequent basis to identify all potential vulnerabilities on the organization's systems.
SAP Authorization Concept Verification
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
An external and Roche-independent security assessment for the authorization concept is required to prove that access restrictions work as intended and privilege escalation is not possible. Mitigate all potential findings.
SAP source outage
SNow
State: PublishedCategory: Uncategorized
SAP-specific Access Controls for Externals (Contractors & Business Partners)
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
Access to confidential, sensitive and business critical data is excluded (without additional mitigating controls) via dedicated restricted roles for external business partners. The access concept has been assessed independently and profen to be reliable. External, i.e. non-Roche-employees have separ
SAP-specific Application Firewall
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
Connections to system via RFC will be restricted using UCON functionality. Application Firewall UCON and/or Dedicated Server Firewall to reduce the attack surface for potential attackers.
SAP-specific High Privileged Access Management
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
High privilege access to the system and its data is governed by the Roche Standard solutions SAP Fire Fighter / SAP Emergency Users. Dedicated solutions to protect access to high privilege accounts like admins. To prevent full system compromise through breached high privilege accounts.
SAP-specific Malware Protection
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
Dedicated Anti-Virus may be required. If many different file formats are uploaded from a multitude of non-managed devices.
SAP-specific Roles for Externals (Contractors and External Business Partners)
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
To protect Roche's assets and to comply with legal requirements like data privacy laws, an authorization concept with data-access restrictions reflecting the contractual & location-based attributes of a user is to be established.  In cases where an access restriction is not possible (e.g. due to th
SAP-specific Secure Code Development
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
Three different controls are available based on the need, SAP Code Inspector for SL2, Self-developped enhanced solution eSCR for SL3 or third party solution (Onapsis) for SL4. Self-developped SAP code or code developped by a third party vendor poses a multitude of potential risks like backdoors, har
SAP-specific Security Compliance Checks
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
According to Roche’s internal regulation, GxP relevant systems are periodically reviewed by an independent auditor. Perform the Roche SAP security standard compliance check and mitigate all portential non compliance of medium and high criticality before go live and regular compliance checks need to
SAP-specific Security Monitoring
SNow
Classification: DetectiveState: PublishedCategory: SAP Application Security
A dedicated third party application (Onapsis) monitoring the SAP application layer for ongoing attacks. Data breach notifications within the specified time range cannot rely on a monthly manual review of the audit logs. (GDPR)
SAP-specific Standardized Permission Management
SNow
Classification: PreventiveState: PublishedCategory: SAP Application Security
Usage of Globally developed BASIS roles restricting Access to the Application Layer (no access to business transactions). Standardized and harmonized high privilege authorization roles. Balanced approach between access restriction and globalized standard roles for administrator accounts, for instanc
SEF-01 Security Incident Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics. Review and update the policies and procedures at least annually.
SEF-02 Service Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the timely management of security incidents. Review and update the policies and procedures at least annually.
SEF-03 Incident Response Plans
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.'
SEF-04 Incident Response Testing
SNow
State: PublishedCategory: Uncategorized
Test and update as necessary incident response plans at planned intervals or upon significant organizational or environmental changes for effectiveness.
SEF-05 Incident Response Metrics
SNow
State: PublishedCategory: Uncategorized
Establish and monitor information security incident metrics.
SEF-06 Event Triage Processes
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures supporting business processes to triage security-related events.
SEF-07 Security Breach Notification
SNow
State: PublishedCategory: Uncategorized
Define and implement, processes, procedures and technical measures for security breach notifications. Report security breaches and assumed security breaches including any relevant supply chain breaches, as per applicable SLAs, laws and regulations.
SEF-08 Points of Contact Maintenance
SNow
State: PublishedCategory: Uncategorized
Maintain points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities.
SOC Report Review
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Service provider holds a System and Organization Controls (SOC) report and the report is reviewed on a yearly basis by Roche Information Security.
SRA (risk assessment artifact capturing risk profile)
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
STA-01 SSRM Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the application of the Shared Security Responsibility Model (SSRM) within the organization. Review and update the policies and procedures at least annually.
STA-02 SSRM Supply Chain
SNow
State: PublishedCategory: Uncategorized
Apply, document, implement and manage the SSRM throughout the supply chain for the cloud service offering.
STA-03 SSRM Guidance
SNow
State: PublishedCategory: Uncategorized
Provide SSRM Guidance to the CSC detailing information about the SSRM applicability throughout the supply chain.
STA-04 SSRM Control Ownership
SNow
State: PublishedCategory: Uncategorized
Delineate the shared ownership and applicability of all CSA CCM controls according to the SSRM for the cloud service offering.
STA-05 SSRM Documentation Review
SNow
State: PublishedCategory: Uncategorized
Review and validate SSRM documentation for all cloud services offerings the organization uses.
STA-06 SSRM Control Implementation
SNow
State: PublishedCategory: Uncategorized
Implement, operate, and audit or assess the portions of the SSRM which the organization is responsible for.
STA-07 Supply Chain Inventory
SNow
State: PublishedCategory: Uncategorized
Develop and maintain an inventory of all supply chain relationships.
STA-08 Supply Chain Risk Management
SNow
State: PublishedCategory: Uncategorized
CSPs periodically review risk factors associated with all organizations within their supply chain.
STA-09 Primary Service and Contractual Agreement
SNow
State: PublishedCategory: Uncategorized
Service agreements between CSPs and CSCs (tenants) must incorporate at least the following mutually-agreed upon provisions and/or terms: • Scope, characteristics and location of business relationship and services offered • Information security requirements (including SSRM) • Change management proces
STA-10 Supply Chain Agreement Review
SNow
State: PublishedCategory: Uncategorized
Review supply chain agreements between CSPs and CSCs at least annually.
STA-11 Internal Compliance Testing
SNow
State: PublishedCategory: Uncategorized
Define and implement a process for conducting internal assessments to confirm conformance and effectiveness of standards, policies, procedures, and service level agreement activities at least annually.
STA-12 Supply Chain Service Agreement Compliance
SNow
State: PublishedCategory: Uncategorized
Implement policies requiring all CSPs throughout the supply chain to comply with information security, confidentiality, access control, privacy, audit, personnel policy and service level requirements and standards.
STA-13 Supply Chain Governance Review
SNow
State: PublishedCategory: Uncategorized
Periodically review the organization's supply chain partners' IT governance policies and procedures.
STA-14 Supply Chain Data Security Assessment
SNow
State: PublishedCategory: Uncategorized
Define and implement a process for conducting security assessments periodically for all organizations within the supply chain.
Sandbox All Email Attachments
SNow
Classification: ProtectState: PublishedCategory: Network
Use sandboxing to analyze and block inbound email attachments with malicious behavior.
Sanitize all electronic storage media before disposing a system or redeploying a system.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Sanitize all electronic storage media before disposing a system or redeploying a system.
Scan devices for malicious code when an individual returns from locations deemed to be of risk.
SNow
Classification: DetectiveState: PublishedCategory: Human Resources management
Scan devices for malicious code when an individual returns from locations deemed to be of risk.
Scan for Unauthorized Connections across Trusted Network Boundaries
SNow
Classification: DetectState: PublishedCategory: Network
Perform regular scans from outside each trusted network boundary to detect any unauthorized connections which are accessible across the boundary.
Scan for rogue devices and other network devices and deny access until approval has been received.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Scan for rogue devices and other network devices and deny access until approval has been received.
Scan the network for Wireless Access Points.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Scan the network for Wireless Access Points.
Scan wireless networks for rogue devices.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Scan wireless networks for rogue devices.
Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers
SNow
Classification: ProtectState: PublishedCategory: Applications
Establish, implement, and actively manage (track, report on, correct) the security configuration of mobile devices, laptops, servers, and workstations using a rigorous configuration management and change control process in order to prevent attackers from exploiting vulnerable services and settings.
Secure Configuration for Network Devices, such as Firewalls, Routers and Switches
SNow
Classification: IdentifyState: PublishedCategory: Network
Establish, implement, and actively manage (track, report on, correct) the security configuration of network infrastructure devices using a rigorous configuration management and change control process in order to prevent attackers from exploiting vulnerable services and settings.
Secure Disposal or Re-use of Equipment
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Secure Disposal or Re-use of Equipment
Secure Login (Multi-Factor Authentication)
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
Ensures that a computer user is granted access to resources only after successfully presenting two or more pieces of evidence (multiple factors) during authentication. This is in addition to user name and password (first factor). Multi-factor authentication can also be achieved by using Single Sign-
Secure Remote Access for Externals
SNow
State: RetiredCategory: Identity and Access
Secure Software Development
SNow
Classification: PreventiveState: PublishedCategory: Application Security
Secure software development practice includes secure code development conforming to standards/guidelines, code reviews, security testing and fixing issues early and often. Security flaws are consistently the primary cause of commonly exploited software vulnerabilities leading to data breaches. Check
Secure access to each system component Operating System.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Secure access to each system component Operating System.
Secure non issued access mechanisms.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Secure non issued access mechanisms.
Secure physical entry points with physical access controls or security guards.
SNow
Classification: DetectiveState: PublishedCategory: Physical and environmental protection
Secure physical entry points with physical access controls or security guards.
Securely Store Master Images
SNow
Classification: ProtectState: PublishedCategory: Applications
Store the master images and templates on securely configured servers, validated with integrity monitoring tools, to ensure that only authorized changes to the images are possible.
Security Awareness Training
SNow
Classification: PreventiveState: PublishedCategory: Users
Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.
Security Controls
SNow
Classification: ProtectState: PublishedCategory: Roche Security Standards
Security Design Document
SNow
State: PublishedCategory: Uncategorized
The security design document aims to be audit/inspection ready, being able to demonstrate that key security controls are properly integrated into the system design. The security concept document contains all security relevant information needed to demonstrate the system design is secure and all risk
Security Logging and Incident Management
SNow
Classification: DetectiveState: PublishedCategory: Logging, Monitoring, Threat Detection, and Analytics
For high-risk solutions or when processing personal data, logging and incident management processes must be implemented to reliably capture, identify, contain and report security & privacy-related incidents.In order to identify fraudulent access or abusive use of Roche systems and/or data (including
Security Scorecard Rating is reviewed on a yearly basis
SNow
Classification: DetectiveState: PublishedCategory: Uncategorized
On a yearly basis the SSC rating is reviewed, in case the rating is below the agreed threshold (B Rating) a new Vendor Security Assessment needs to be executed.
Security concept review with Security Expert
SNow
State: PublishedCategory: Uncategorized
The Security Expert Review (SER) is a specialized control that solution teams can leverage to enhance their information security posture. It involves an in-depth assessment of key security controls' effectiveness in mitigating identified risks within the specific context of a system.
Security of Assets Off-Premises
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Security of Assets Off-Premises
Segment the Network Based on Sensitivity
SNow
Classification: ProtectState: PublishedCategory: Network
Segment the network based on the label or classification level of the information stored on the servers, locate all sensitive information on separated Virtual Local Area Networks (VLANs).
Segregate applications and databases that contain restricted data or restricted information from the Demilitarized Zone by placing them in an internal network zone.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Segregate applications and databases that contain restricted data or restricted information from the Demilitarized Zone by placing them in an internal network zone.
Segregate servers that contain restricted data or restricted information from direct public access.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Segregate servers that contain restricted data or restricted information from direct public access.
Select suppliers based on their qualifications.
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Select suppliers based on their qualifications.
Separate Production and Non-Production Systems
SNow
Classification: ProtectState: PublishedCategory: Data
Maintain separate environments for production and nonproduction systems. Developers should not have unmonitored access to production environments.
Separate duplicate originals and backup media from the original electronic storage media.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Separate duplicate originals and backup media from the original electronic storage media.
Separate processing domains to segregate user privileges and enhance information flow control.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Separate processing domains to segregate user privileges and enhance information flow control.
Separate the Wireless Access Points and wireless bridges from the wired network via a firewall.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Separate the Wireless Access Points and wireless bridges from the wired network via a firewall.
Separate the alternate facility from the primary facility through geographic separation.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Separate the alternate facility from the primary facility through geographic separation.
Separate the alternate telecommunications service providers from the primary telecommunications service providers through geographic separation, so as to not be susceptible to the same hazards.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Separate the alternate telecommunications service providers from the primary telecommunications service providers through geographic separation, so as to not be susceptible to the same hazards.
Separate the design and development environment from the production environment.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Separate the design and development environment from the production environment.
Separate the off-site electronic media storage facilities from the primary facility through geographic separation.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Separate the off-site electronic media storage facilities from the primary facility through geographic separation.
Set access control for objects and users to "deny all" unless explicitly authorized.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Set access control for objects and users to "deny all" unless explicitly authorized.
Share incident information with interested personnel and affected parties.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Share incident information with interested personnel and affected parties.
Share relevant security information with Special Interest Groups, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Share relevant security information with Special Interest Groups, as necessary.
Shielding by Network Segmentation and Filtering
SNow
Classification: PreventiveState: PublishedCategory: Network and Infrastructure
Systems with different levels of security (e.g. lab equipment, internet-facing applications, IoT devices) should be placed into different security zones (e.g segmented networks) to protect the resources appropriately and minimize the impact of individual system compromise.
Shut down systems when an integrity violation is detected, as necessary.
SNow
Classification: CorrectiveState: PublishedCategory: Operational management
Shut down systems when an integrity violation is detected, as necessary.
SolMan compliance
SNow
Classification: ProtectState: PublishedCategory: Systems design, build, and implementation
Solution Specific Security & Privacy Awareness Training
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Protecting business data is critical to the overall security of Roche IT solutions and information assets. Not handling the Business data, the Business IT solution or even platform with appropriate care, could lead to unauthorized access and/or data breach within the given environment. An appropri
Specify appropriate tools for the system development project.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Specify appropriate tools for the system development project.
Specify who will receive the privacy policy.
SNow
Classification: PreventiveState: PublishedCategory: Privacy protection for information and data
Specify who will receive the privacy policy.
Storage Duration
SNow
State: PublishedCategory: Uncategorized
A storage duration must be defined for each type of data and justified by the legal requirements and/or processing needs. Define the data retention period and erasure mechanism at the end of the storage duration.
Storage Media
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Storage Media
Store backup media at an off-site electronic media storage facility.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Store backup media at an off-site electronic media storage facility.
Store cryptographic keys in encrypted format.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Store cryptographic keys in encrypted format.
Store cryptographic keys securely.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Store cryptographic keys securely.
Store key-encrypting keys and data-encrypting keys in different locations.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Store key-encrypting keys and data-encrypting keys in different locations.
Store source code documentation in escrow by an independent third party.
SNow
Classification: DetectiveState: PublishedCategory: Acquisition or sale of facilities, technology, and services
Store source code documentation in escrow by an independent third party.
Subscribe to URL-Categorization service
SNow
Classification: ProtectState: PublishedCategory: Network
Subscribe to URL categorization services to ensure that they are up-to-date with the most recent website category definitions available. Uncategorized sites shall be blocked by default.
Supervise and monitor outsourced development projects.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Supervise and monitor outsourced development projects.
Supply each in scope asset with audit reduction tool and report generation capabilities to support after-the-fact investigations without altering the event logs.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Supply each in scope asset with audit reduction tool and report generation capabilities to support after-the-fact investigations without altering the event logs.
Supporting Utilities
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Supporting Utilities
Synchronize and secure all router configuration files and firewall configuration files.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Synchronize and secure all router configuration files and firewall configuration files.
Synchronize system clocks to an accurate and universal time source on all devices that have logging enabled.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Synchronize system clocks to an accurate and universal time source on all devices that have logging enabled.
System Inventory
SNow
Classification: IdentifyState: PublishedCategory: Uncategorized
System Risk Assessment (artifact capturing risk profile)
SNow
Classification: IdentifyState: RetiredCategory: Uncategorized
System Risk Assessment Verification
SNow
Classification: PreventiveState: PublishedCategory: Governance, Risk and Compliance
Control to check whether a System Risk Assessment is in place for Business Applications Contact: Martin Aeschlimann, Dionysia Patsou Last Update: 13-May-2025
System hardening through configuration management
SNow
Classification: IT Impact ZoneState: PublishedCategory: System hardening through configuration management
System hardening through configuration management
Systems design, build, and implementation
SNow
Classification: IT Impact ZoneState: PublishedCategory: Systems design, build, and implementation
Systems design, build, and implementation
TVM-01 Threat and Vulnerability Management Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to identify, report and prioritize the remediation of vulnerabilities, in order to protect systems against vulnerability exploitation. Review and update the policies and procedures at least annually.
TVM-02 Malware Protection Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect against malware on managed assets. Review and update the policies and procedures at least annually.
TVM-03 Vulnerability Remediation Schedule
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to enable both scheduled and emergency responses to vulnerability identifications, based on the identified risk.
TVM-04 Detection Updates
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to update detection tools, threat signatures, and indicators of compromise on a weekly, or more frequent basis.
TVM-05 External Library Vulnerabilities
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to identify updates for applications which use third party or open source libraries according to the organization's vulnerability management policy.
TVM-06 Penetration Testing
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for the periodic performance of penetration testing by independent third parties.
TVM-07 Vulnerability Identification
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures for the detection of vulnerabilities on organizationally managed assets at least monthly.
TVM-08 Vulnerability Prioritization
SNow
State: PublishedCategory: Uncategorized
Use a risk-based model for effective prioritization of vulnerability remediation using an industry recognized framework.
TVM-09 Vulnerability Management Reporting
SNow
State: PublishedCategory: Uncategorized
Define and implement a process for tracking and reporting vulnerability identification and remediation activities that includes stakeholder notification.
TVM-10 Vulnerability Management Metrics
SNow
State: PublishedCategory: Uncategorized
Establish, monitor and report metrics for vulnerability identification and remediation at defined intervals.
Tailor training to be taught at each person's level of responsibility.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Tailor training to be taught at each person's level of responsibility.
Tailor training to meet published guidance on the subject being taught.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Tailor training to meet published guidance on the subject being taught.
Take appropriate action if missing audit documentation compromises the audit.
SNow
Classification: PreventiveState: PublishedCategory: Audits and risk management
Take appropriate action if missing audit documentation compromises the audit.
Take appropriate action to correct deficiencies identified in the audit report.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Take appropriate action to correct deficiencies identified in the audit report.
Test Data on Backup Media
SNow
Classification: ProtectState: PublishedCategory: Data
Test data integrity on backup media on a regular basis by performing a data restoration process to ensure that the backup is properly working.
Test all firewall configuration change requests.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Test all firewall configuration change requests.
Test all software changes before implementation in the production environment.
SNow
Classification: DetectiveState: PublishedCategory: Systems design, build, and implementation
Test all software changes before implementation in the production environment.
Test all untrusted files or unverified files and removable storage media for viruses and malicious code.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Test all untrusted files or unverified files and removable storage media for viruses and malicious code.
Test and approve all network connections through the firewall.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Test and approve all network connections through the firewall.
Test backup media for media integrity and information integrity, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Test backup media for media integrity and information integrity, as necessary.
Test compliance controls for proper functionality.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test compliance controls for proper functionality.
Test each restored system for media integrity and information integrity.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Test each restored system for media integrity and information integrity.
Test network access controls for proper Configuration Management settings.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Test network access controls for proper Configuration Management settings.
Test systems for malicious code prior to when the system will be redeployed.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Test systems for malicious code prior to when the system will be redeployed.
Test the continuity plan at the alternate facility.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Test the continuity plan at the alternate facility.
Test the continuity plan under conditions that simulate a disaster or disruption.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Test the continuity plan under conditions that simulate a disaster or disruption.
Test the continuity plan, as necessary.
SNow
Classification: DetectiveState: PublishedCategory: Systems continuity
Test the continuity plan, as necessary.
Test the incident response procedures.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Test the incident response procedures.
Test the system for Cross-Site Request Forgery.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for Cross-Site Request Forgery.
Test the system for broken access controls.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for broken access controls.
Test the system for broken authentication and session management.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for broken authentication and session management.
Test the system for buffer overflows.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for buffer overflows.
Test the system for cross-site scripting attacks.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for cross-site scripting attacks.
Test the system for injection flaws.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for injection flaws.
Test the system for insecure communications.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for insecure communications.
Test the system for insecure configuration management.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for insecure configuration management.
Test the system for insecure cryptographic storage.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for insecure cryptographic storage.
Test the system for proper error handling.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Test the system for proper error handling.
Test the system's operational functionality after implementing approved changes.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Test the system's operational functionality after implementing approved changes.
The manufacturing system accessible remotely should have appropriate flag in OT Asset Inventory (ServiceNow CMDB) in order to share awareness regarding specific cyber risk resulting from utilization of such technology.
SNow
Classification: IdentifyState: PublishedCategory: Records Management
The manufacturing system accessible remotely should have appropriate flag in OT Asset Inventory (ServiceNow CMDB) in order to share awareness regarding specific cyber risk resulting from utilization of such technology.
The manufacturing system and data should be covered by backup and recovery service/solution according to the requirements defined within the PL ID 22984490 Use cases and Requirement for supporting and security requirements for manufacturing systems.
SNow
Classification: CorrectiveState: PublishedCategory: Systems Continuity
The manufacturing system and data should be covered by backup and recovery service/solution according to the requirements defined within the PL ID 22984490 Use cases and Requirement for supporting and security requirements for manufacturing systems.
The manufacturing system and data should be covered by backup and recovery service/solution.
SNow
Classification: RespondState: PublishedCategory: Systems continuity
The manufacturing system and data should be covered by backup and recovery service/solution.
The manufacturing system and it's components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
The manufacturing system and it's components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
The manufacturing system and its components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
SNow
Classification: ProtectState: PublishedCategory: Operational management
The manufacturing system and its components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
The manufacturing system and/or network should be covered by the OT Security Monitoring (industrial Intrusion Detection System - IIDS) service according to OT Monitoring Scope requirements defined within the DIA OT CS Security & Operations SOP.
SNow
Classification: DetectState: PublishedCategory: Monitoring and measurement
The manufacturing system and/or network should be covered by the OT Security Monitoring (industrial Intrusion Detection System) service according to OT Monitoring Scope requirements defined within the PL ID 24220009 iIDS Monitoring Scoping Model.
SNow
Classification: IdentifyState: PublishedCategory: Logging, Monitoring, Threat Detection, and Analytics
The manufacturing system and/or network should be covered by the OT Security Monitoring (industrial Intrusion Detection System - IIDS) service according to OT Monitoring Scope requirements defined within the PL ID 24220009 iIDS Monitoring Scoping Model.
The manufacturing system architecture should be in line with DIA OT CS Network Segmentation Concept.
SNow
Classification: ProtectState: PublishedCategory: Network
The manufacturing system architecture should be in line with DIA OT CS Network Segmentation Concept.
The manufacturing system architecture should be in line with Network Segmentation requirements defined in: PL ID 22235185 Roche MCRP - Network Segmentation Concept.
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
The manufacturing system architecture should be in line with Network Segmentation requirements defined in: PL ID 22235185 Roche MCRP - Network Segmentation Concept.
The manufacturing system configuration should be hardened, including restriction of use of unnecessary functions, closing non-used open ports/protocols and disabling unnecessary services.
SNow
Classification: ProtectState: PublishedCategory: System hardening through configuration management
The manufacturing system configuration should be hardened, including restriction of use of unnecessary functions, closing non-used open ports/protocols and disabling unnecessary services.
The manufacturing system network communication should be in line with the requirements defined in: DIA OT CS Firewall Policy Guideline.
SNow
Classification: IdentifyState: PublishedCategory: Technical security
The manufacturing system network communication should be in line with the requirements defined in: PL ID 24974826 MCRP Firewall Policy Guideline.
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
The manufacturing system network communication should be in line with the requirements defined in: PL ID 24974826 MCRP Firewall Policy Guideline.
The manufacturing system network traffic exchanged with systems in different VLANs should be routed through firewall.
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
The manufacturing system network traffic exchanged with systems in different VLANs should be routed through firewall.
The manufacturing system should be logically separated from non-control system networks and other control system networks.
SNow
Classification: ProtectState: PublishedCategory: Technical Security
The manufacturing system should be logically separated from non-control system networks and other control system networks.
The manufacturing system should be reflected in the OT Asset Inventory (ServiceNow CMDB) including all its components (includes internal programming devices or engineering stations) and respective attributes.
SNow
Classification: IdentifyState: PublishedCategory: Records management
The manufacturing system should be reflected in the OT Asset Inventory (ServiceNow CMDB) including all its components (includes internal programming devices or engineering stations) and respective attributes. Data in the OT Asset Inventory (ServiceNow CMDB) should be stored and maintained according
The manufacturing system should be reflected in the OT Asset Inventory (ServiceNow CMDB) including its all components and respective attributes according to the PL ID 25035550 PT OT Asset Inventory Management for Manufacturing Cybersecurity.
SNow
Classification: RespondState: PublishedCategory: Records management
The manufacturing system should be reflected in the OT Asset Inventory (ServiceNow CMDB) including its all components and respective attributes. Data in the OT Asset Inventory (ServiceNow CMDB) should be stored and maintained according to the: PL ID 25035550 PT OT Asset Inventory Management for Manu
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: PL ID 24640623 Manufacturing Cybersecurity Vulnerability Identification in Manufacturing.
SNow
Classification: IdentifyState: PublishedCategory: Vulnerability and Configuration Analysis
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: PL ID 24640623 Manufacturing Cybersecurity Vulnerability Identification in Manufacturing.
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: Vulnerability Management SOP.
SNow
Classification: DetectState: PublishedCategory: Vulnerability and Configuration Analysis
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: Vulnerability Management SOP 24090-03.
The manufacturing system should be supported by Vendor (not obsolete) including a notification process for vulnerabilities affecting the supported system.
SNow
Classification: IdentifyState: PublishedCategory: Vulnerability and Configuration Analysis
The manufacturing system should be supported by Vendor (not obsolete) including a notification process for vulnerabilities affecting the supported system.
The manufacturing system should be supported by Vendor (not obsolete).
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
The manufacturing system should be supported by Vendor (not obsolete).
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.).
SNow
Classification: ProtectState: PublishedCategory: Identity and Access
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.). Privileged user accounts should be limited and the user should be trained in regard to of the elevated permissions and associated risks to their account.
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.). Privileged user accounts should be limited and the user should be trained in regard to of the elevated permissions and associat
SNow
State: RetiredCategory: Operational management
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.). Privileged user accounts should be limited and the user should be trained in regard to of the elevated permissions and associated risks to their account.
The manufacturing system should have a Disaster Recovery Plan prepared unless it is not classified as BCM relevant.
SNow
Classification: RespondState: PublishedCategory: Systems continuity
The manufacturing system should have a Disaster Recovery Plan prepared unless it is not classified as BCM relevant.
The manufacturing system should have a Disaster Recovery Plan prepared unless it is not classified as critical.
SNow
Classification: CorrectiveState: PublishedCategory: Systems Continuity
The manufacturing system should have a Disaster Recovery Plan prepared unless it is not classified as critical.
The manufacturing system should have an anti-malware software installed. There should be defined process for anti-malware software solution maintenance (update).
SNow
Classification: ProtectState: PublishedCategory: Technical Security
The manufacturing system should have an anti-malware software installed. There should be defined process for anti-malware software solution maintenance (update).
The manufacturing system should have defined ownership (e.g. System Owner, System Manager) to address required cybersecurity measures.
SNow
Classification: RespondState: PublishedCategory: Operational management
The manufacturing system should have defined ownership (e.g. System Owner, System Manager) to address required cybersecurity measures.
The manufacturing system should have technical capabilities to receive patches / updates in a secured manner according to requirements defined within the: DIA OT CS Patchmanagement SOP.
SNow
Classification: ProtectState: PublishedCategory: Technical security
The manufacturing system should have technical capabilities to receive patches / updates in a secured manner according to requirements defined within the: DIA OT CS Patchmanagement SOP.
The manufacturing system should have technicall capabilities to receive patches / updates in a secured manner according to regirements defined within the: PL ID 22235185 Roche MCRP - Network Segmentation Concept.
SNow
Classification: CorrectiveState: PublishedCategory: Vulnerability and Configuration Analysis
The manufacturing system should have technicall capabilities to receive patches / updates in a secured manner according to regirements defined within the: PL ID 22235185 Roche MCRP - Network Segmentation Concept.
The manufacturing system should not utilize dual-homed devices (e.g. servers) to communicate with systems (or system components) located in other segments / security zones.
SNow
Classification: ProtectState: PublishedCategory: System hardening through configuration management
The manufacturing system should not utilize dual-homed devices (e.g. servers) to communicate with systems (or system components) located in other segments / security zones.
The manufacturing system should provide the capability for an authorized user or role to define and modify the mapping of permissions to roles for all users.
SNow
Classification: ProtectState: PublishedCategory: Identity and Access
The manufacturing system should provide the capability for an authorized user or role to define and modify the mapping of permissions to roles for all users.
The manufacturing system should support session timeout feature covering also remote sessions.
SNow
Classification: ProtectState: PublishedCategory: Technical security
The manufacturing system should support session timeout feature covering also remote sessions.
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring according to the global password policy.
SNow
Classification: ProtectState: PublishedCategory: Identity and Access
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring according to the global password policy.
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring.
SNow
Classification: PreventiveState: PublishedCategory: Identity and Access
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring.
The manufacturing system should utilize a supported and most up to date (not obsolete) operating system.
SNow
Classification: ProtectState: PublishedCategory: Technical Security
The manufacturing system should utilize a supported and most up to date (not obsolete) operating system.
The manufacturing system should utilize approved (whitelisted) application only.
SNow
Classification: ProtectState: PublishedCategory: Technical Security
The manufacturing system should utilize approved (whitelisted) application only.
The manufacturing system update and patching process should be defined, including roles and responsibilities.
SNow
Classification: ProtectState: PublishedCategory: Technical security
The manufacturing system update and patching process should be defined, including roles and responsibilities.
There should be an evidence that the exisiting disaster recovery procedures and/or backups are available and restorable depending on the system and available test infrastructure
SNow
Classification: RespondState: PublishedCategory: Systems continuity
There should be an evidence that the exisiting disaster recovery procedures and/or backups are available and restorable depending on the system and available test infrastructure
There should be defined decommission process for the manufacturing system, covering data removal and/or data storage disposal.
SNow
Classification: PreventiveState: PublishedCategory: Deprecated
There should be defined decommission process for the manufacturing system, covering data removal and/or data storage disposal.
There should be defined process for the manufacturing system backup and recovery including Recovery Point Objective (RPO), Recovery Time Objective (RTO) requirements.
SNow
Classification: CorrectiveState: PublishedCategory: Systems Continuity
There should be defined process for the manufacturing system backup and recovery including Recovery Point Objective (RPO), Recovery Time Objective (RTO) requirements.
There should be defined processes for the manufacturing system backup and recovery including Recovery Point Objective (RPO), Recovery Time Objective (RTO) requirements.
SNow
Classification: RespondState: PublishedCategory: Systems continuity
There should be defined processes for the manufacturing system backup and recovery including Recovery Point Objective (RPO), Recovery Time Objective (RTO) requirements.
There should be file sharing location for file exchange between various security zones.
SNow
Classification: ProtectState: PublishedCategory: Technical Security
There should be file sharing location for file exchange between various security zones.
Third Party Management
SNow
State: PublishedCategory: Uncategorized
Third Parties are identified and governed by a contract. For data processors, a data processing agreement is executed between the parties and the reference is provided in the RoPA questionnaire.
Third Party and supply chain oversight
SNow
Classification: IT Impact ZoneState: PublishedCategory: Third Party and supply chain oversight
Third Party and supply chain oversight
Threat Detection
Mapping
Category: Mapping
Track Software Inventory Information
SNow
Classification: IdentifyState: PublishedCategory: Applications
The software inventory system should track the name, version, publisher, and install date for all software, including operating systems authorized by the organization.
Track restricted storage media while it is in transit.
SNow
Classification: DetectiveState: PublishedCategory: Records management
Track restricted storage media while it is in transit.
Train Workforce Members on Identifying and Reporting Incidents
SNow
Classification: ProtectState: PublishedCategory: Users
Train employees to be able to identify the most common indicators of an incident and be able to report such an incident.
Train Workforce on Causes of Unintentional Data Exposure
SNow
Classification: ProtectState: PublishedCategory: Users
Train workforce members to be aware of causes for unintentional data exposures, such as losing their mobile devices or emailing the wrong person due to autocomplete in email.
Train Workforce on Identifying Social Engineering Attacks
SNow
Classification: ProtectState: PublishedCategory: Users
Train the workforce on how to identify different forms of social engineering attacks, such as phishing, phone scams and impersonation calls.
Train Workforce on Secure Authentication
SNow
Classification: ProtectState: PublishedCategory: Users
Train workforce members on the importance of enabling and utilizing secure authentication.
Train Workforce on Sensitive Data Handling
SNow
Classification: ProtectState: PublishedCategory: Users
Train workforce on how to identify and properly store, transfer, archive and destroy sensitive information.
Train all new hires, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Train all new hires, as necessary.
Train all personnel and third parties on how to recognize and report security incidents.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Train all personnel and third parties on how to recognize and report security incidents.
Train all personnel and third parties, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Train all personnel and third parties, as necessary.
Train personnel on the continuity plan.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Train personnel on the continuity plan.
Train the affected users during development projects, implementation projects, or modification projects.
SNow
Classification: PreventiveState: PublishedCategory: Systems design, build, and implementation
Train the affected users during development projects, implementation projects, or modification projects.
Transport backup media in lockable electronic media storage containers.
SNow
Classification: PreventiveState: PublishedCategory: Systems continuity
Transport backup media in lockable electronic media storage containers.
Transport restricted media using a delivery method that can be tracked.
SNow
Classification: PreventiveState: PublishedCategory: Records management
Transport restricted media using a delivery method that can be tracked.
UEM-01 Endpoint Devices Policy and Procedures
SNow
State: PublishedCategory: Uncategorized
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for all endpoints. Review and update the policies and procedures at least annually.
UEM-02 Application and Service Approval
SNow
State: PublishedCategory: Uncategorized
Define, document, apply and evaluate a list of approved services, applications and sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data.
UEM-03 Compatibility
SNow
State: PublishedCategory: Uncategorized
Define and implement a process for the validation of the endpoint device's compatibility with operating systems and applications.
UEM-04 Endpoint Inventory
SNow
State: PublishedCategory: Uncategorized
Maintain an inventory of all endpoints used to store and access company data.
UEM-05 Endpoint Management
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-06 Automatic Lock Screen
SNow
State: PublishedCategory: Uncategorized
Configure all relevant interactive-use endpoints to require an automatic lock screen.
UEM-07 Operating Systems
SNow
State: PublishedCategory: Uncategorized
Manage changes to endpoint operating systems, patch levels, and/or applications through the company's change management processes.
UEM-08 Storage Encryption
SNow
State: PublishedCategory: Uncategorized
Protect information from unauthorized disclosure on managed endpoint devices with storage encryption.
UEM-09 Anti-Malware Detection and Prevention
SNow
State: PublishedCategory: Uncategorized
Configure managed endpoints with anti-malware detection and prevention technology and services.
UEM-10 Software Firewall
SNow
State: PublishedCategory: Uncategorized
Configure managed endpoints with properly configured software firewalls.
UEM-11 Data Loss Prevention
SNow
State: PublishedCategory: Uncategorized
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
UEM-12 Remote Locate
SNow
State: PublishedCategory: Uncategorized
Enable remote geo-location capabilities for all managed mobile endpoints.
UEM-13 Remote Wipe
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical measures to enable the deletion of company data remotely on managed endpoint devices.
UEM-14 Third-Party Endpoint Security Posture
SNow
State: PublishedCategory: Uncategorized
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.
US DOJ DSP Check
SNow
Classification: RespondState: PublishedCategory: Privacy protection for information and data
DoJ DSP Assessment by Roche US Legal
US DoJ Compliance
SNow
Classification: ProtectState: PublishedCategory: Governance, Risk and Compliance
Control for compliance governance of systems in scope of Department of Justice's (DOJ) Data Security Program
Unencrypted/unsecure network traffic should not transit into other network zones/segments
SNow
State: RetiredCategory: Operational management
Alternative solutions for data transfer should be evaluated or implemented (data gateway, secure storage media solutions...)
Update Awareness Content Frequently
SNow
Classification: ProtectState: PublishedCategory: Users
Ensure that the organization's security awareness program is updated frequently (at least annually) to address new technologies, threats, standards and business requirements.
Update associated documentation after the system configuration has been changed.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Update associated documentation after the system configuration has been changed.
Update firmware to the most recent version once upgrade notification has been received.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Update firmware to the most recent version once upgrade notification has been received.
Update the incident response procedures using the lessons learned.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Update the incident response procedures using the lessons learned.
Update the intrusion detection capabilities and the incident response capabilities regularly.
SNow
Classification: PreventiveState: PublishedCategory: Monitoring and measurement
Update the intrusion detection capabilities and the incident response capabilities regularly.
Update the risk assessment upon changes to the risk profile.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Update the risk assessment upon changes to the risk profile.
Update the risk assessment upon discovery of a new threat.
SNow
Classification: DetectiveState: PublishedCategory: Audits and risk management
Update the risk assessment upon discovery of a new threat.
Update the system's backup procedures after an approved change has occurred.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Update the system's backup procedures after an approved change has occurred.
Update the vulnerability scanners' vulnerability list.
SNow
Classification: CorrectiveState: PublishedCategory: Monitoring and measurement
Update the vulnerability scanners' vulnerability list.
Use Automated Tools to Verify Standard Device Configurations and Detect Changes
SNow
Classification: DetectState: PublishedCategory: Network
Compare all network device configuration against approved security configurations defined for each network device in use and alert when any deviations are discovered.
Use DHCP Logging to Update Asset Inventory
SNow
Classification: IdentifyState: PublishedCategory: Devices
Use Dynamic Host Configuration Protocol (DHCP) logging on all DHCP servers or IP address management tools to update the organization's hardware asset inventory.
Use Dedicated Machines For All Network Administrative Tasks
SNow
Classification: ProtectState: PublishedCategory: Network
Ensure network engineers use a dedicated machine for all administrative tasks or tasks requiring elevated access. This machine shall be segmented from the organization's primary network and not be allowed Internet access. This machine shall not be used for reading e-mail, composing documents, or sur
Use Multifactor Authentication For All Administrative Access
SNow
Classification: ProtectState: PublishedCategory: Users
Use multi-factor authentication and encrypted channels for all administrative account access.
Use Only Standardized and Extensively Reviewed Encryption Algorithms
SNow
Classification: ProtectState: PublishedCategory: Applications
Use only standardized and extensively reviewed encryption algorithms.
Use Standard Hardening Configuration Templates for Databases
SNow
Classification: ProtectState: PublishedCategory: Data
For applications that rely on a database, use standard hardening configuration templates. All systems that are part of critical business processes should also be tested.
Use Superuser accounts only in emergencies.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Use Superuser accounts only in emergencies.
Use Unique Passwords
SNow
Classification: ProtectState: PublishedCategory: Users
Where multi-factor authentication is not supported (such as local administrator, root, or service accounts), accounts will use passwords that are unique to that system.
Use Vulnerability Scanning and Penetration Testing Tools in Concert
SNow
Classification: DetectState: PublishedCategory: Applications/Network
Use vulnerability scanning and penetration testing tools in concert. The results of vulnerability scanning assessments should be used as a starting point to guide and focus penetration testing efforts.
Use Wireless Authentication Protocols that Require Mutual, Multi-Factor Authentication
SNow
Classification: ProtectState: PublishedCategory: Network
Ensure that wireless networks use authentication protocols such as Extensible Authentication Protocol-Transport Layer Security (EAP/TLS), that requires mutual, multi-factor authentication.
Use a Passive Asset Discovery Tool
SNow
Classification: IdentifyState: PublishedCategory: Devices
Utilize a passive discovery tool to identify devices connected to the organization's network and automatically update the organization's hardware asset inventory.
Use a Wireless Intrusion Detection System
SNow
Classification: DetectState: PublishedCategory: Network
Use a wireless intrusion detection system (WIDS) to detect and alert on unauthorized wireless access points connected to the network.
Use automated mechanisms in the training environment, where appropriate.
SNow
Classification: PreventiveState: PublishedCategory: Human Resources management
Use automated mechanisms in the training environment, where appropriate.
Use automated mechanisms to compare new vulnerability test results with past vulnerability test results.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Use automated mechanisms to compare new vulnerability test results with past vulnerability test results.
Use automated tools to collect Information Technology inventory information, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Leadership and high level objectives
Use automated tools to collect Information Technology inventory information, as necessary.
Use content filtering scans to identify information flows by data type usage.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Use content filtering scans to identify information flows by data type usage.
Use locks to protect against unauthorized physical access.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Use locks to protect against unauthorized physical access.
Use locks with electronic authentication systems or cipher locks, as necessary.
SNow
Classification: PreventiveState: PublishedCategory: Physical and environmental protection
Use locks with electronic authentication systems or cipher locks, as necessary.
Use of DNS Filtering Services
SNow
Classification: ProtectState: PublishedCategory: Network
Use DNS filtering services to help block access to known malicious domains.
Use of Dedicated Machines For All Administrative Tasks
SNow
Classification: ProtectState: PublishedCategory: Users
Ensure administrators use a dedicated machine for all administrative tasks or tasks requiring administrative access. This machine will be segmented from the organization's primary network and not be allowed Internet access. This machine will not be used for reading e-mail, composing documents, or br
Use only secure communication protocols for remote system management.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Use only secure communication protocols for remote system management.
Use strong data encryption to transmit restricted data or restricted information over public networks.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Use strong data encryption to transmit restricted data or restricted information over public networks.
Use the latest version of all software.
SNow
Classification: PreventiveState: PublishedCategory: System hardening through configuration management
Use the latest version of all software.
User accounts and the associated permissions should be reviewed regularly
SNow
Classification: ProtectState: PublishedCategory: Periodic Review
User accounts and the associated permissions should be reviewed regularly
Utilization of USB portable storage should be restricted for the manufacturing system as described within the PL ID 22984490 Use cases and Requirement for supporting and security requirements for manufacturing systems.
SNow
Classification: PreventiveState: PublishedCategory: Technical Security
Utilization of USB portable storage should be restricted for the manufacturing system as described within the PL ID 22984490 Use cases and Requirement for supporting and security requirements for manufacturing systems.
Utilization of USB portable storage should be restricted for the manufacturing system.
SNow
Classification: ProtectState: PublishedCategory: Technical security
Utilization of USB portable storage should be restricted for the manufacturing system.
Utilize Application Whitelisting
SNow
Classification: ProtectState: PublishedCategory: Applications
Utilize application whitelisting technology on all assets to ensure that only authorized software executes and all unauthorized software is blocked from executing on assets.
Utilize Centrally Managed Anti-malware Software
SNow
Classification: ProtectState: PublishedCategory: Devices
Any enterprise class AV software will have this capability. By having a centrally managed AV, you can easily enable individual requirements.
Utilize Client Certificates to Authenticate Hardware Assets
SNow
Classification: ProtectState: PublishedCategory: Devices
Use client certificates to authenticate hardware assets connecting to the organization's trusted network.
Utilize Software Inventory Tools
SNow
Classification: IdentifyState: PublishedCategory: Applications
Utilize software inventory tools throughout the organization to automate the documentation of all software on business systems.
Utilize Three Synchronized Time Sources
SNow
Classification: DetectState: PublishedCategory: Network
Use at least three synchronized time sources from which all servers and network devices retrieve time information on a regular basis so that timestamps in logs are consistent.
Utilize a Risk-rating Process
SNow
Classification: RespondState: PublishedCategory: Applications
Utilize a risk-rating process to prioritize the remediation of discovered vulnerabilities.
Utilize an Active Discovery Tool
SNow
Classification: IdentifyState: PublishedCategory: Devices
Utilize an active discovery tool to identify devices connected to the organization's network and update the hardware asset inventory.
Utilize an Active Discovery Tool to Identify Sensitive Data
SNow
Classification: DetectState: PublishedCategory: Data
Utilize an active discovery tool to identify all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider and update the organization's sensitive information inventory.
Utilize resource availability management controls.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Utilize resource availability management controls.
Utilize resource capacity management controls.
SNow
Classification: DetectiveState: PublishedCategory: Operational management
Utilize resource capacity management controls.
Validate all testing assumptions in the test plans.
SNow
Classification: DetectiveState: PublishedCategory: Monitoring and measurement
Validate all testing assumptions in the test plans.
Validate the system before implementing approved changes.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Validate the system before implementing approved changes.
Vendor Quality Assessment
SNow
State: PublishedCategory: Uncategorized
Vendor Quality Assessments are mandatory for GxP systems
Vendor Risk Assessment (VRA)
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
This control mandates a formal assessment to ensure that third-party vendors meet Roche information security, privacy (VSA) and quality (VQA) requirements. This assessment must be performed before the software is used by Roche or connected (access granted) to our network, systems, or data. This proc
Vendor Security Assessment
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
An assessment conducted to verify whether a vendor meets Roche’s information security and privacy requirements to process, host, and/or to have access to Roche’s network which includes business critical or personal data related to its services to Roche.
Vendor Security Assessment is not older than 3 years
SNow
Classification: PreventiveState: PublishedCategory: Uncategorized
Vendor has Cyber risk insurance which covers Data Breaches and Cyber Liability
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Vendor has a formal onboarding and offboarding process for employees as well as contractors working for the ODC
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Vendor has an industry recognized security certification from an accredited third party
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Vendor has an up to date Business Continutiy Plan for the services provided to Roche
SNow
Classification: PreventiveState: PublishedCategory: Third Party and supply chain oversight
Verify That Acquired Software is Still Supported
SNow
Classification: ProtectState: PublishedCategory: Applications
Verify that the version of all software acquired from outside your organization is still supported by the developer or appropriately hardened based on developer security recommendations.
Verify data elements that contain the full magnetic stripe data from a payment card are not stored under any circumstance.
SNow
Classification: DetectiveState: PublishedCategory: Privacy protection for information and data
Verify data elements that contain the full magnetic stripe data from a payment card are not stored under any circumstance.
Verify firewalls perform stateful inspection or Dynamic Packet Filtering.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Verify firewalls perform stateful inspection or Dynamic Packet Filtering.
Verify only Wireless Local Area Network Network Interface Cards that turn off or disable Peer-To-Peer Wireless Local Area Network communications are used on the system.
SNow
Classification: DetectiveState: PublishedCategory: System hardening through configuration management
Verify only Wireless Local Area Network Network Interface Cards that turn off or disable Peer-To-Peer Wireless Local Area Network communications are used on the system.
Verify outside Wireless Local Area Network services that access the network are configured in accordance with organizational Information Assurance standards.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Verify outside Wireless Local Area Network services that access the network are configured in accordance with organizational Information Assurance standards.
Verify restricted data or restricted information is encrypted with the most secure and up-to-date methods and standards.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Verify restricted data or restricted information is encrypted with the most secure and up-to-date methods and standards.
Verify signature files are up to date.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Verify signature files are up to date.
Verify the antivirus software checks e-mail and e-mail attachments.
SNow
Classification: PreventiveState: PublishedCategory: Technical security
Verify the antivirus software checks e-mail and e-mail attachments.
Verify third parties meet organizational compliance standards.
SNow
Classification: DetectiveState: PublishedCategory: Third Party and supply chain oversight
Verify third parties meet organizational compliance standards.
Verify user identities before manually resetting a password or unlocking an account.
SNow
Classification: DetectiveState: PublishedCategory: Technical security
Verify user identities before manually resetting a password or unlocking an account.
Vulnerability Assessment and Security Testing
SNow
Classification: PreventiveState: PublishedCategory: Vulnerability and Configuration Analysis
Vulnerability Assessment is an essential part of the software development life cycle and the deployment of systems into production.   This assessment must be present from the development until the later stages like the acceptance or the actual production of the system and it is conducted via securi
Vulnerability and Configuration Scan
SNow
Classification: DetectiveState: PublishedCategory: Vulnerability and Configuration Analysis
An initial and periodic (or regular) vulnerability and configuration scan will provide the necessary information to make informed decisions on corrective actions to ensure the system or solution is securely configured prior to go-live (release to production) and throughout ongoing operations.
Web Application Firewall
SNow
State: RetiredCategory: Network and Infrastructure
Web Application Security Scan
SNow
Classification: DetectiveState: PublishedCategory: Vulnerability and Configuration Analysis
The Web Application Security Scan (WASS) is an inspection of a web application, while similar to a vulnerability scan, it is designed to provide a rapid assessment of the security state of a Roche-managed website.
Wipe all data on systems prior to when the system is redeployed or the system is disposed.
SNow
Classification: PreventiveState: PublishedCategory: Operational management
Wipe all data on systems prior to when the system is redeployed or the system is disposed.
Working in Secure Areas
SNow
Classification: PreventiveState: PublishedCategory: Physical Security
Working in Secure Areas
and Analytics
Mapping
Category: Mapping
test_ elena
SNow
State: RetiredCategory: Uncategorized
Graph Explorer