Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Azure logo

HIPAA HITRUST 9.2

136 controls
94 checks mapped

HIPAA safeguards the confidentiality, integrity, and availability of electronic protected health information (ePHI) handled by covered entities and business associates.

Controls assessed

Privilege Management - The organization facilitates information sharing by enabling authorized users1

To determine a business partner's access when discretion is allowed as defined by the organization and by employing manual processes or automated mechanisms to assist users in making information sharing/collaboration decisions.

Privilege Management - Contractors are provided with minimal system and physical access1

The allocation and use of privileges to information systems and services shall be restricted and controlled. Special attention shall be given to the allocation of privileged access rights, which allow users to override system controls. Only after the organization assesses the contractor's ability to comply with its security requirements and the contractor agrees to comply.

User Identification and Authentication - The organization requires that electronic signatures, unique to one individual, cannot be reused by, or reassigned to, anyone else1
User Identification and Authentication - Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records1
02 Endpoint Protection - 0201.09j1Organizational.124-09.j 09.04 Protection Against Malicious and Mobile Code3

Anti-virus and anti-spyware are installed, operating and updated on all end-user devices to conduct periodic scans of the systems to identify and remove unauthorized software. Server environments for which the server software developer specifically recommends not installing host-based anti-virus and anti-spyware software may address the requirement via a network-based malware detection (NBMD) solution.

03 Portable Media Security - 0301.09o1Organizational.123-09.o 09.07 Media Handling1

The organization, based on the data classification level, registers media (including laptops) prior to use, places reasonable restrictions on how such media be used, and provides an appropriate level of physical and logical protection (including encryption) for media containing covered information until properly destroyed or sanitized.

03 Portable Media Security - 0304.09o3Organizational.1-09.o 09.07 Media Handling3

The organization restricts the use of writable removable media and personally-owned removable media in organizational systems.

Identification of Risks Related to External Parties - Access to the organizations information and systems by external parties1

Access to the organizations information and systems by external parties is not permitted until due diligence has been conducted, the appropriate controls have been implemented, and a contract/agreement reflecting the security requirements is signed acknowledging they understand and accept their obligations.

Identification of Risks Related to External Parties - Remote access connections between the organization and external parties are encrypted2
Identification of Risks Related to External Parties - Access granted to external parties is limited to the minimum necessary and granted only for the duration required2
06 Configuration Management - 0605.10h1System.12-10.h 10.04 Security of System Files2

Only authorized administrators are allowed to implement approved upgrades to software, applications, and program libraries, based on business requirements and the security implications of the release.

06 Configuration Management - 0635.10k1Organizational.12-10.k 10.05 Security In Development and Support Processes1

Managers responsible for application systems are also responsible for the strict control (security) of the project or support environment and ensure that all proposed system changes are reviewed to check that they do not compromise the security of either the system or the operating environment.

06 Configuration Management - 0636.10k2Organizational.1-10.k 10.05 Security In Development and Support Processes1

The organization formally addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance for configuration management.

06 Configuration Management - 0637.10k2Organizational.2-10.k 10.05 Security In Development and Support Processes1

The organization has developed, documented, and implemented a configuration management plan for the information system.

06 Configuration Management - 0638.10k2Organizational.34569-10.k 10.05 Security In Development and Support Processes1

Changes are formally controlled, documented and enforced in order to minimize the corruption of information systems.

06 Configuration Management - 0639.10k2Organizational.78-10.k 10.05 Security In Development and Support Processes1

Installation checklists and vulnerability scans are used to validate the configuration of servers, workstations, devices and appliances and ensure the configuration meets minimum standards.

06 Configuration Management - 0640.10k2Organizational.1012-10.k 10.05 Security In Development and Support Processes1

Where development is outsourced, change control procedures to address security are included in the contract(s) and specifically require the developer to track security flaws and flaw resolution within the system, component, or service and report findings to organization-defined personnel or roles.

06 Configuration Management - 0641.10k2Organizational.11-10.k 10.05 Security In Development and Support Processes1

The organization does not use automated updates on critical systems.

06 Configuration Management - 0642.10k3Organizational.12-10.k 10.05 Security In Development and Support Processes1

The organization develops, documents, and maintains, under configuration control, a current baseline configuration of the information system, and reviews and updates the baseline as required.

06 Configuration Management - 0643.10k3Organizational.3-10.k 10.05 Security In Development and Support Processes1

The organization (i) establishes and documents mandatory configuration settings for information technology products employed within the information system using the latest security configuration baselines; (ii) identifies, documents, and approves exceptions from the mandatory established configuration settings for individual components based on explicit operational requirements; and (iii) monitors and controls changes to the configuration settings in accordance with organizational policies and procedures.

06 Configuration Management - 0644.10k3Organizational.4-10.k 10.05 Security In Development and Support Processes1

The organization employs automated mechanisms to (i) centrally manage, apply, and verify configuration settings; (ii) respond to unauthorized changes to network and system security-related configuration settings; and (iii) enforce access restrictions and auditing of the enforcement actions.

06 Configuration Management - 0662.09sCSPOrganizational.2-09.s 09.08 Exchange of Information2

Cloud service providers use an industry-recognized virtualization platform and standard virtualization formats (e.g., Open Virtualization Format, OVF) to help ensure interoperability, and has documented custom changes made to any hypervisor in use and all solution-specific virtualization hooks available for customer review.

08 Network Protection - 0805.01m1Organizational.12-01.m 01.04 Network Access Control12

The organization's security gateways (e.g. firewalls) enforce security policies and are configured to filter traffic between domains, block unauthorized access, and are used to maintain segregation between internal wired, internal wireless, and external network segments (e.g., the Internet) including DMZs and enforce access control policies for each of the domains.

08 Network Protection - 0806.01m2Organizational.12356-01.m 01.04 Network Access Control12

The organizations network is logically and physically segmented with a defined security perimeter and a graduated set of controls, including subnetworks for publicly accessible system components that are logically separated from the internal network, based on organizational requirements; and traffic is controlled based on functionality required and classification of the data/systems based on a risk assessment and their respective security requirements.

08 Network Protection - 0809.01n2Organizational.1234-01.n 01.04 Network Access Control13

Network traffic is controlled in accordance with the organizations access control policy through firewall and other network-related restrictions for each network access point or external telecommunication service's managed interface.

08 Network Protection - 0810.01n2Organizational.5-01.n 01.04 Network Access Control13

Transmitted information is secured and, at a minimum, encrypted over open, public networks.

08 Network Protection - 0811.01n2Organizational.6-01.n 01.04 Network Access Control13

Exceptions to the traffic flow policy are documented with a supporting mission/business need, duration of the exception, and reviewed at least annually; traffic flow policy exceptions are removed when no longer supported by an explicit mission/business need.

08 Network Protection - 0812.01n2Organizational.8-01.n 01.04 Network Access Control13

Remote devices establishing a non-remote connection are not allowed to communicate with external (remote) resources.

08 Network Protection - 0814.01n1Organizational.12-01.n 01.04 Network Access Control13

The ability of users to connect to the internal network is restricted using a deny-by-default and allow-by-exception policy at managed interfaces according to the access control policy and the requirements of clinical and business applications.

08 Network Protection - 0835.09n1Organizational.1-09.n 09.06 Network Security Management2

Agreed services provided by a network service provider/manager are formally managed and monitored to ensure they are provided securely.

08 Network Protection - 0836.09.n2Organizational.1-09.n 09.06 Network Security Management1

The organization formally authorizes and documents the characteristics of each connection from an information system to other information systems outside the organization. The organization formally authorizes and documents the characteristics of each connection from an information system to other information systems outside the organization.

08 Network Protection - 0837.09.n2Organizational.2-09.n 09.06 Network Security Management1

Formal agreements with external information system providers include specific obligations for security and privacy.

08 Network Protection - 0858.09m1Organizational.4-09.m 09.06 Network Security Management3

The organization monitors for all authorized and unauthorized wireless access to the information system and prohibits installation of wireless access points (WAPs) unless explicitly authorized in writing by the CIO or his/her designated representative.

08 Network Protection - 0861.09m2Organizational.67-09.m 09.06 Network Security Management3

To identify and authenticate devices on local and/or wide area networks, including wireless networks, the information system uses either a (i) shared known information solution or (ii) an organizational authentication solution, the exact selection and strength of which is dependent on the security categorization of the information system.

08 Network Protection - 0862.09m2Organizational.8-09.m 09.06 Network Security Management1

The organization ensures information systems protect the confidentiality and integrity of transmitted information, including during preparation for transmission and during reception.

08 Network Protection - 0863.09m2Organizational.910-09.m 09.06 Network Security Management1

The organization builds a firewall configuration that restricts connections between un-trusted networks and any system components in the covered information environment; and any changes to the firewall configuration are updated in the network diagram.

08 Network Protection - 0864.09m2Organizational.12-09.m 09.06 Network Security Management1

Usage restrictions and implementation guidance are formally defined for VoIP, including the authorization and monitoring of the service.

08 Network Protection - 0865.09m2Organizational.13-09.m 09.06 Network Security Management1

The organization (i) authorizes connections from the information system to other information systems outside of the organization through the use of interconnection security agreements or other formal agreement; (ii) documents each connection, the interface characteristics, security requirements, and the nature of the information communicated; (iii) employs a deny all, permit by exception policy for allowing connections from the information system to other information systems outside of the organization; and (iv) applies a default-deny rule that drops all traffic via host-based firewalls or port filtering tools on its endpoints (workstations, servers, etc.), except those services and ports that are explicitly allowed.

08 Network Protection - 0866.09m3Organizational.1516-09.m 09.06 Network Security Management1

The organization describes the groups, roles, and responsibilities for the logical management of network components and ensures coordination of and consistency in the elements of the network infrastructure.

08 Network Protection - 0868.09m3Organizational.18-09.m 09.06 Network Security Management1

The organization builds a firewall configuration to restrict inbound and outbound traffic to that which is necessary for the covered data environment.

08 Network Protection - 0869.09m3Organizational.19-09.m 09.06 Network Security Management1

The router configuration files are secured and synchronized.

08 Network Protection - 0870.09m3Organizational.20-09.m 09.06 Network Security Management1

Access to all proxies is denied, except for those hosts, ports, and services that are explicitly required.

08 Network Protection - 0871.09m3Organizational.22-09.m 09.07 Network Security Management1

Authoritative DNS servers are segregated into internal and external roles.

08 Network Protection - 0885.09n2Organizational.3-09.n 09.06 Network Security Management1

The organization reviews and updates the interconnection security agreements on an ongoing basis verifying enforcement of security requirements.

08 Network Protection - 0886.09n2Organizational.4-09.n 09.06 Network Security Management1

The organization employs and documents in a formal agreement or other document, either i) allow-all, deny-by-exception, or, ii) deny-all, permit-by-exception (preferred), policy for allowing specific information systems to connect to external information systems.

08 Network Protection - 0887.09n2Organizational.5-09.n 09.06 Network Security Management1

The organization requires external/outsourced service providers to identify the specific functions, ports, and protocols used in the provision of the external/outsourced services.

08 Network Protection - 0888.09n2Organizational.6-09.n 09.06 Network Security Management1

The contract with the external/outsourced service provider includes the specification that the service provider is responsible for the protection of covered information shared.

08 Network Protection - 0894.01m2Organizational.7-01.m 01.04 Network Access Control13

Networks are segregated from production-level networks when migrating physical servers, applications or data to virtualized servers.

Back-up - Workforce members roles and responsibilities in the data backup process are identified and communicated to the workforce; in particular, Bring Your Own Device (BYOD) users are required to perform backups of organizational and/or client data on their devices1
Network Controls - Wireless access points are placed in secure areas and shut down when not in use (e.g. nights, weekends)1

Ensure the protection of information in networks and protection of the supporting network infrastructure.

On-line Transactions - The organization requires the use of encryption between, and the use of electronic signatures by, each of the parties involved in the transaction1
09 Transmission Protection - 0901.09s1Organizational.1-09.s 09.08 Exchange of Information2

The organization formally addresses multiple safeguards before allowing the use of information systems for information exchange.

09 Transmission Protection - 0902.09s2Organizational.13-09.s 09.08 Exchange of Information2

Remote (external) access to the organization's information assets and access to external information assets (for which the organization has no control) is based on clearly defined terms and conditions.

09 Transmission Protection - 0912.09s1Organizational.4-09.s 09.08 Exchange of Information2

Cryptography is used to protect the confidentiality and integrity of remote access sessions to the internal network and to external systems.

09 Transmission Protection - 0913.09s1Organizational.5-09.s 09.08 Exchange of Information2

Strong cryptography protocols are used to safeguard covered information during transmission over less trusted / open public networks.

09 Transmission Protection - 0915.09s2Organizational.2-09.s 09.08 Exchange of Information2

The organization limits the use of organization-controlled portable storage media by authorized individuals on external information systems.

09 Transmission Protection - 0916.09s2Organizational.4-09.s 09.08 Exchange of Information2

The information system prohibits remote activation of collaborative computing devices and provides an explicit indication of use to users physically present at the devices.

09 Transmission Protection - 0943.09y1Organizational.1-09.y 09.09 Electronic Commerce Services1

The organization verifies every ninety (90) days for each extract of covered information recorded that the data is erased or its use is still required.

09 Transmission Protection - 0947.09y2Organizational.2-09.y 09.09 Electronic Commerce Services2

The organization ensures the storage of the transaction details are located outside of any publicly accessible environments (e.g., on a storage platform existing on the organization's intranet) and not retained and exposed on a storage medium directly accessible from the Internet.

09 Transmission Protection - 0948.09y2Organizational.3-09.y 09.09 Electronic Commerce Services2

Where a trusted authority is used (e.g., for the purposes of issuing and maintaining digital signatures and/or digital certificates), security is integrated and embedded throughout the entire end-to-end certificate/signature management process.

09 Transmission Protection - 0949.09y2Organizational.5-09.y 09.09 Electronic Commerce Services4

The protocols used for communications are enhanced to address any new vulnerability, and the updated versions of the protocols are adopted as soon as possible.

09 Transmission Protection - 0960.09sCSPOrganizational.1-09.s 09.08 Exchange of Information2

Cloud service providers use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved.

11 Access Control - 11112.01q2Organizational.67-01.q 01.05 Operating System Access Control1

The information system employs replay-resistant authentication mechanisms such as nonce, one-time passwords, or time stamps to secure network access for privileged accounts; and, for hardware token-based authentication, employs mechanisms that satisfy minimum token requirements discussed in NIST SP 800-63-2, Electronic Authentication Guideline.

11 Access Control - 1125.01q2System.1-01.q 01.05 Operating System Access Control1

Multi-factor authentication methods are used in accordance with organizational policy, (e.g., for remote network access).

11 Access Control - 1144.01c1System.4-01.c 01.02 Authorized Access to Information Systems1

The organization explicitly authorizes access to specific security relevant functions (deployed in hardware, software, and firmware) and security-relevant information.

11 Access Control - 1145.01c2System.1-01.c 01.02 Authorized Access to Information Systems1

Role-based access control is implemented and capable of mapping each user to one or more roles, and each role to one or more system functions.

11 Access Control - 1146.01c2System.23-01.c 01.02 Authorized Access to Information Systems1

The organization promotes the development and use of programs that avoid the need to run with elevated privileges and system routines to avoid the need to grant privileges to users.

11 Access Control - 1147.01c2System.456-01.c 01.02 Authorized Access to Information Systems1

Elevated privileges are assigned to a different user ID from those used for normal business use, all users access privileged services in a single role, and such privileged access is minimized.

11 Access Control - 1148.01c2System.78-01.c 01.02 Authorized Access to Information Systems2

The organization restricts access to privileged functions and all security-relevant information.

11 Access Control - 1151.01c3System.1-01.c 01.02 Authorized Access to Information Systems1

The organization limits authorization to privileged accounts on information systems to a pre-defined subset of users.

11 Access Control - 1152.01c3System.2-01.c 01.02 Authorized Access to Information Systems1

The organization audits the execution of privileged functions on information systems and ensures information systems prevent non-privileged users from executing privileged functions.

11 Access Control - 1153.01c3System.35-01.c 01.02 Authorized Access to Information Systems1

All file system access not explicitly required is disabled, and only authorized users are permitted access to only that which is expressly required for the performance of the users' job duties.

11 Access Control - 1194.01l2Organizational.2-01.l 01.04 Network Access Control2

Ports, services, and similar applications installed on a computer or network systems, which are not specifically required for business functionality, are disabled or removed.

11 Access Control - 1195.01l3Organizational.1-01.l 01.04 Network Access Control2

The organization reviews the information system within every three hundred and sixty-five (365) days to identify and disables unnecessary and non-secure functions, ports, protocols, and/or services.

12 Audit Logging & Monitoring - 1204.09aa1System.3-09.aa 09.10 Monitoring1

The activities of privileged users (administrators, operators, etc.) include the success/failure of the event, time the event occurred, the account involved, the processes involved, and additional information about the event.

12 Audit Logging & Monitoring - 1205.09aa2System.1-09.aa 09.10 Monitoring1

Logs of messages sent and received are maintained including the date, time, origin and destination of the message, but not its contents.

12 Audit Logging & Monitoring - 1207.09aa2System.4-09.aa 09.10 Monitoring2

Audit records are retained for 90 days and older audit records are archived for one year.

12 Audit Logging & Monitoring - 1208.09aa3System.1-09.aa 09.10 Monitoring2

Audit logs are maintained for management activities, system and application startup/shutdown/errors, file changes, and security policy changes.

12 Audit Logging & Monitoring - 1209.09aa3System.2-09.aa 09.10 Monitoring2

The information system generates audit records containing the following detailed information: filename accessed, program or command used to initiate the event and source and destination addresses.

12 Audit Logging & Monitoring - 12102.09ab1Organizational.4-09.ab 09.10 Monitoring1

The organization shall periodically test its monitoring and detection processes, remediate deficiencies, and improve its processes.

12 Audit Logging & Monitoring - 1211.09aa3System.4-09.aa 09.10 Monitoring3

The organization verifies every ninety (90) days for each extract of covered information recorded that the data is erased or its use is still required.

12 Audit Logging & Monitoring - 1213.09ab2System.128-09.ab 09.10 Monitoring1

Automated systems deployed throughout the organization's environment are used to monitor key events and anomalous activity, and analyze system logs, the results of which are reviewed regularly.

12 Audit Logging & Monitoring - 1217.09ab3System.3-09.ab 09.10 Monitoring1

Alerts are generated for technical personnel to analyze and investigate suspicious activity or suspected violations.

12 Audit Logging & Monitoring - 1220.09ab3System.56-09.ab 09.10 Monitoring1

Monitoring includes inbound and outbound communications and file integrity monitoring.

12 Audit Logging & Monitoring - 1229.09c1Organizational.1-09.c 09.01 Documented Operating Procedures1

Separation of duties is used to limit the risk of unauthorized or unintentional modification of information and systems.

12 Audit Logging & Monitoring - 1230.09c2Organizational.1-09.c 09.01 Documented Operating Procedures1

No single person is able to access, modify, or use information systems without authorization or detection.

12 Audit Logging & Monitoring - 1232.09c3Organizational.12-09.c 09.01 Documented Operating Procedures1

Access for individuals responsible for administering access controls is limited to the minimum necessary based upon each user's role and responsibilities and these individuals cannot access audit functions related to these controls.

12 Audit Logging & Monitoring - 1277.09c2Organizational.4-09.c 09.01 Documented Operating Procedures1

The initiation of an event is separated from its authorization to reduce the possibility of collusion.

13 Education, Training and Awareness - 1325.09s1Organizational.3-09.s 09.08 Exchange of Information2

Ensure the exchange of information within an organization and with any external entity is secured and protected, and carried out in compliance with relevant legislation and exchange agreements.

14 Third Party Assurance - 1450.05i2Organizational.2-05.i 05.02 External Parties2

The organization obtains satisfactory assurances that reasonable information security exists across their information supply chain by performing an annual review, which includes all partners/third party-providers upon which their information supply chain depends.

14 Third Party Assurance - 1451.05iCSPOrganizational.2-05.i 05.02 External Parties1

Cloud service providers design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privilege access for all personnel within their supply chain.

16 Business Continuity & Disaster Recovery - 1616.09l1Organizational.16-09.l 09.05 Information Back-Up1

Backup copies of information and software are made and tests of the media and restoration procedures are regularly performed at appropriate intervals.

16 Business Continuity & Disaster Recovery - 1617.09l1Organizational.23-09.l 09.05 Information Back-Up1

A formal definition of the level of backup required for each system is defined and documented including how each system will be restored, the scope of data to be imaged, frequency of imaging, and duration of retention based on relevant contractual, legal, regulatory and business requirements.

16 Business Continuity & Disaster Recovery - 1618.09l1Organizational.45-09.l 09.05 Information Back-Up2

The backups are stored in a physically secure remote location, at a sufficient distance to make them reasonably immune from damage to data at the primary site, and reasonable physical and environmental controls are in place to ensure their protection at the remote location.

16 Business Continuity & Disaster Recovery - 1619.09l1Organizational.7-09.l 09.05 Information Back-Up1

Inventory records for the backup copies, including content and current location, are maintained.

16 Business Continuity & Disaster Recovery - 1620.09l1Organizational.8-09.l 09.05 Information Back-Up1

When the backup service is delivered by the third party, the service level agreement includes the detailed protections to control confidentiality, integrity and availability of the backup information.

16 Business Continuity & Disaster Recovery - 1621.09l2Organizational.1-09.l 09.05 Information Back-Up1

Automated tools are used to track all backups.

16 Business Continuity & Disaster Recovery - 1622.09l2Organizational.23-09.l 09.05 Information Back-Up1

The integrity and security of the backup copies are maintained to ensure future availability, and any potential accessibility problems with the backup copies are identified and mitigated in the event of an area-wide disaster.

16 Business Continuity & Disaster Recovery - 1623.09l2Organizational.4-09.l 09.05 Information Back-Up2

Covered information is backed-up in an encrypted format to ensure confidentiality.

16 Business Continuity & Disaster Recovery - 1624.09l3Organizational.12-09.l 09.05 Information Back-Up1

The organization performs incremental or differential backups daily and full backups weekly to separate media.

16 Business Continuity & Disaster Recovery - 1625.09l3Organizational.34-09.l 09.05 Information Back-Up1

Three (3) generations of backups (full plus all related incremental or differential backups) are stored off-site, and both on-site and off-site backups are logged with name, date, time and action.

16 Business Continuity & Disaster Recovery - 1626.09l3Organizational.5-09.l 09.05 Information Back-Up2

The organization ensures a current, retrievable copy of covered information is available before movement of servers.

16 Business Continuity & Disaster Recovery - 1627.09l3Organizational.6-09.l 09.05 Information Back-Up1

The organization tests backup information following each backup to verify media reliability and information integrity, and at least annually thereafter.

16 Business Continuity & Disaster Recovery - 1635.12b1Organizational.2-12.b 12.01 Information Security Aspects of Business Continuity Management2

Information security aspects of business continuity are (i) based on identifying events (or sequence of events) that can cause interruptions to the organization's critical business processes (e.g., equipment failure, human errors, theft, fire, natural disasters acts of terrorism); (ii) followed by a risk assessment to determine the probability and impact of such interruptions, in terms of time, damage scale and recovery period; (iii) based on the results of the risk assessment, a business continuity strategy is developed to identify the overall approach to business continuity; and (iv) once this strategy has been created, endorsement is provided by management, and a plan created and endorsed to implement this strategy.

16 Business Continuity & Disaster Recovery - 1637.12b2Organizational.2-12.b 12.01 Information Security Aspects of Business Continuity Management1

Business impact analysis are used to evaluate the consequences of disasters, security failures, loss of service, and service availability.

1143.01c1System.123-01.c 01.02 Authorized Access to Information Systems1

Privileges are formally authorized and controlled, allocated to users on a need-to-use and event-by-event basis for their functional role (e.g., user or administrator), and documented for each system product/element.

1150.01c2System.10-01.c 01.02 Authorized Access to Information Systems1

The access control system for the system components storing, processing or transmitting covered information is set with a default 'deny-all' setting.

1193.01l2Organizational.13-01.l 01.04 Network Access Control1

Controls for the access to diagnostic and configuration ports include the use of a key lock and the implementation of supporting procedures to control physical access to the port.

11180.01c3System.6-01.c 01.02 Authorized Access to Information Systems1

Access to management functions or administrative consoles for systems hosting virtualized systems are restricted to personnel based upon the principle of least privilege and supported through technical controls.

1119.01j2Organizational.3-01.j 01.04 Network Access Control1

Network equipment is checked for unanticipated dial-up capabilities.

1120.09ab3System.9-09.ab 09.10 Monitoring1

Unauthorized remote connections to the information systems are monitored and reviewed at least quarterly, and appropriate action is taken if an unauthorized connection is discovered.

1175.01j1Organizational.8-01.j 01.04 Network Access Control1

Remote access to business information across public networks only takes place after successful identification and authentication.

1179.01j3Organizational.1-01.j 01.04 Network Access Control1

The information system monitors and controls remote access methods.

1192.01l1Organizational.1-01.l 01.04 Network Access Control1

Access to network equipment is physically protected.

1202.09aa1System.1-09.aa 09.10 Monitoring1

A secure audit record is created for all activities on the system (create, read, update, delete) involving covered information.

1203.09aa1System.2-09.aa 09.10 Monitoring1

Audit records include the unique user ID, unique data subject ID, function performed, and date/time the event was performed.

1210.09aa3System.3-09.aa 09.10 Monitoring1

All disclosures of covered information within or outside of the organization are logged including type of disclosure, date/time of the event, recipient, and sender.

12100.09ab2System.15-09.ab 09.10 Monitoring1

The organization monitors the information system to identify irregularities or anomalies that are indicators of a system malfunction or compromise and help confirm the system is functioning in an optimal, resilient and secure state.

12101.09ab1Organizational.3-09.ab 09.10 Monitoring1

The organization specifies how often audit logs are reviewed, how the reviews are documented, and the specific roles and responsibilities of the personnel conducting the reviews, including the professional certifications or other qualifications required.

1212.09ab1System.1-09.ab 09.10 Monitoring1

All applicable legal requirements related to monitoring authorized access and unauthorized access attempts are met.

1214.09ab2System.3456-09.ab 09.10 Monitoring1

Monitoring includes privileged operations, authorized access or unauthorized access attempts, including attempts to access deactivated accounts, and system alerts or failures.

1215.09ab2System.7-09.ab 09.10 Monitoring1

Auditing and monitoring systems employed by the organization support audit reduction and report generation.

1216.09ab3System.12-09.ab 09.10 Monitoring1

Automated systems are used to review monitoring activities of security systems (e.g., IPS/IDS) and system records on a daily basis, and identify and document anomalies.

1219.09ab3System.10-09.ab 09.10 Monitoring1

The information system is able to automatically process audit records for events of interest based on selectable criteria.

1270.09ad1System.12-09.ad 09.10 Monitoring1

The organization ensures proper logging is enabled in order to audit administrator activities; and reviews system administrator and operator logs on a regular basis.

1271.09ad1System.1-09.ad 09.10 Monitoring1

An intrusion detection system managed outside of the control of system and network administrators is used to monitor system and network administration activities for compliance.

1634.12b1Organizational.1-12.b 12.01 Information Security Aspects of Business Continuity Management1

The organization identifies the critical business processes requiring business continuity.

1638.12b2Organizational.345-12.b 12.01 Information Security Aspects of Business Continuity Management1

Business continuity risk assessments (i) are carried out annually with full involvement from owners of business resources and processes; (ii) consider all business processes and is not limited to the information assets, but includes the results specific to information security; and (iii) identifies, quantifies, and prioritizes risks against key business objectives and criteria relevant to the organization, including critical resources, impacts of disruptions, allowable outage times, and recovery priorities.

The identification of risks related to external party access takes into account a minimal set of specifically defined issues1
0860.09m1Organizational.9-09.m 09.06 Network Security Management1

The organization formally manages equipment on the network, including equipment in user areas.

0302.09o2Organizational.1-09.o 09.07 Media Handling1

The organization protects and controls media containing sensitive information during transport outside of controlled areas.

0709.10m1Organizational.1-10.m 10.06 Technical Vulnerability Management4

Technical vulnerabilities are identified, evaluated for risk and corrected in a timely manner.

0710.10m2Organizational.1-10.m 10.06 Technical Vulnerability Management1

A hardened configuration standard exists for all system and network components.

0711.10m2Organizational.23-10.m 10.06 Technical Vulnerability Management1

A technical vulnerability management program is in place to monitor, assess, rank, and remediate vulnerabilities identified in systems.

0716.10m3Organizational.1-10.m 10.06 Technical Vulnerability Management1

The organization conducts an enterprise security posture review as needed but no less than once within every three-hundred-sixty-five (365) days, in accordance with organizational IS procedures.

0719.10m3Organizational.5-10.m 10.06 Technical Vulnerability Management1

The organization updates the list of information system vulnerabilities scanned within every thirty (30) days or when new vulnerabilities are identified and reported.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.