attachment_3_RFP-2027-NHH-03-PATIE.xlsx
XLSX spreadsheet 84 KB Posted
- Attached to
- Patient Identification Software System State and local contract opportunity
- Solicitation number
- RFP-2027-NHH-02-PATIE
- Issued by
- Merrimack County, New Hampshire
About this file
The document is the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQv4.0.2), a comprehensive security assessment framework for cloud service providers (CSPs) and cloud service customers (CSCs). This version 4.0.2 questionnaire aligns with the Cloud Control Matrix (CCM) and features 261 questions structured across 17 domains, designed to help organizations conduct self-assessments of their cloud security compliance. The questionnaire allows CSPs to respond to each control with "Yes", "No", or "N/A" and provides a mechanism for detailing security responsibility ownership across different cloud service environments.
The document is structured to enable detailed security evaluations, with sections covering critical areas such as governance, risk management, identity and access management, infrastructure security, data protection, and incident response. Each section includes specific control specifications, implementation guidelines, and requirements for documenting security practices, with an emphasis on shared security responsibility models. The questionnaire is intended to be used in the Cloud Security Alliance's STAR-Level 1 program, allowing organizations to complete and submit self-assessments to the CSA's STAR Registry, and is copyrighted with specific usage restrictions that limit its application to personal, non-commercial informational purposes.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| attachment_1_RFP-2027-NHH-02-PATIE.xlsx | XLSX spreadsheet | |
| attachment_2_RFP-2027-NHH-02-PATIE.pdf | ||
| RFP-2027-NHH-02-PATIE.pdf | ||
| attachment-2-rfp-2027-nhh-02-patie.pdf | ||
| addendum-2-rfp-2027-nhh-02-patie-0.pdf | ||
| addendum-3-rfp-2027-nhh-02-patie-0.pdf | ||
| attachment-4-rfp-2027-nhh-02-patie.pdf | ||
| attachment-3-rfp-2027-nhh-03-patie.xlsx | XLSX spreadsheet | |
| rfp-2027-nhh-02-patie.pdf | ||
| addendum-1-rfp-2027-nhh-02-patie.pdf | ||
| attachment-1-rfp-2027-nhh-02-patie.xlsx | XLSX spreadsheet |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Introduction
| v4.0.2 | CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE v4.0.2 |
| Introduction |
| Consensus Assessments Initiative Questionnaire (CAIQ): |
| This tab includes the questionnaire associated with the Cloud Control Matrix (CCM) controls, commonly known as the CAIQ. |
| The Consensus Assessments Initiative Questionnaire version 4 (or CAIQv4.0.2) aligns with the CCMv4.0.2 control specifications. The CAIQv4.0.2’s purpose is to help organizations conduct self-assessments to test their compliance against the CCM V4. It is developed under CSA’s STAR-Level 1 program umbrella, allowing organizations to complete and submit self-assessments to CSA’s STAR Registry. |
| The CAIQv4.0.2 features 261 questions structured and formulated based on the 17 domains and underlying control specifications of the CCM. |
| Each question is described using the following attributes: |
| Question ID |
| The question identifiers. |
| Assessment Question |
| The description of the question. |
| In addition, this tab includes the following sections (groups of columns). |
| CSP CAIQ Answer |
| The Cloud Service Provider (CSP) must respond with “Yes”/ ”No”/ ”NA” next to the corresponding assessment question, and for the portion(s) of the CCM control specification they are responsible and accountable for implementing. |
| Meaning of possible replies: |
| • “Yes”: The portion(s) of the CCM control requirement corresponding to the assessment question is met. |
| • “No”: The portion(s) of the CCM control requirement corresponding to the assessment question is not met. |
| • “N/A”: The question is not in scope and does not apply to the cloud service under assessment. |
| NOTES: |
| A “Yes” answer indicates that the portion of the control in question is implemented. The CSP indicates the responsible and accountable parties (SSRM control ownership), and optionally elaborates on the implementation “how-to” per relevant party CSP and/or CSC. |
| A “No” answer indicates that the portion of the control in question is not implemented, while in scope of the assessment. The CSP has to assign the implementation responsibility of the control to the relevant party under column “SSRM control ownership”, and optionally elaborate on the “why” (has not been implemented), and “what” has to be done for its implementation by that party. |
| A “N/A” answer indicates that the portion of the control in question is out of scope of the assessment. The “SSRM control ownership” column is to be left blank (e.g., greyed out), and optionally the CSP may explain why it is the case (“CSP Implementation Description”). |
| Shared Security Responsibility Model (SSRM) control ownership |
| The CSP control responses shall identify control applicability and ownership for their specific service. |
| • CSP-owned: The CSP is entirely responsible and accountable for the CCM control implementation. |
| • CSC-owned: The Cloud Service Customer (CSC) is entirely responsible and accountable for the CCM control implementation. |
| • Third-party outsourced: The third-party CSP in the supply chain (e.g., an IaaS provider) is responsible for CCM control implementation, while the CSP is fully accountable. |
| • Shared CSP and CSC: Both the CSP and CSC share CCM control implementation responsibility and accountability. |
| • Shared CSP and third party: Any CCM control implementation responsibility is shared between CSP and the third party, but the CSP remains fully accountable. |
| Note: The CAIQv4 SSRM schema is tailored to CCMv4’s Supply Chain Management, Transparency, and Accountability (STA) domain, controls 1-6, and their corresponding implementation guidelines. |
| CSP implementation description (optional/recommended) |
| A description (with references) of how the cloud service provider meets (or does not meet) the portion(s) of the SSRM control they are responsible for. If “NA,” explain why. |
| CSC responsibilities (optional/recommended) |
| A summary description of the cloud service customer security responsibilities for the portion(s) of the SSRM control that is responsible for, with corresponding guidance and references. |
| End of Introduction |
| © Copyright 2021-2022 Cloud Security Alliance - All rights reserved. You may download, store, display on your computer, view, print, and link to the Cloud Security Alliance “Consensus Assessments Initiative Questionnaire (CAIQ) Version 4.0.2” at http://www.cloudsecurityalliance.org subject to the following: (a) the Consensus Assessments Initiative Questionnaire v4.0.2 may be used solely for your personal, informational, non-commercial use; (b) the Consensus Assessments Initiative Questionnaire v4.0.2 may not be modified or altered in any way; (c) the Consensus Assessments Initiative Questionnaire v4.0.2 may not be redistributed; and (d) the trademark, copyright or other notices may not be removed. You may quote portions of the Consensus Assessments Initiative Questionnaire v4.0.2 as permitted by the Fair Use provisions of the United States Copyright Act, provided that you attribute the portions to the Cloud Security Alliance Consensus Assessments Initiative Questionnaire Version 4.0.2. If you are interested in obtaining a license to this #material for other usages not addresses in the copyright notice, please contact info@cloudsecurityalliance.org. |
CAIQv4.0.2
| v4.0.2 | CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE v4.0.2 | ||||||||
| Question ID | Question | CSP CAIQ Answer | SSRM Control Ownership | CSP Implementation Description (Optional/Recommended) | CSC Responsibilities (Optional/Recommended) | CCM Control ID | CCM Control Specification | CCM Control Title | CCM Domain Title |
| A&A-01.1 | Are audit and assurance policies, procedures, and standards established, documented, |
approved, communicated, applied, evaluated, and maintained?
A&A-01 Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.
| Audit and Assurance Policy and Procedures | Audit & Assurance |
| A&A-01.2 | Are audit and assurance policies, procedures, and standards reviewed and updated |
at least annually?
A&A-02.1 Are independent audit and assurance assessments conducted according to relevant standards at least annually?
A&A-02 Conduct independent audit and assurance assessments according to relevant standards at least annually.
| Independent Assessments | |
| A&A-03.1 | Are independent audit and assurance assessments performed according to risk-based |
plans and policies?
A&A-03 Perform independent audit and assurance assessments according to risk-based plans and policies.
| Risk Based Planning Assessment | |
| A&A-04.1 | Is compliance verified regarding all relevant standards, regulations, legal/contractual, |
and statutory requirements applicable to the audit?
A&A-04 Verify compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit.
| Requirements Compliance | |
| A&A-05.1 | Is an audit management process defined and implemented to support audit planning, |
risk analysis, security control assessments, conclusions, remediation schedules, report generation, and reviews of past reports and supporting evidence?
A&A-05 Define and implement an Audit Management process to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, and review of past reports and supporting evidence.
| Audit Management Process | |
| A&A-06.1 | Is a risk-based corrective action plan to remediate audit findings established, |
documented, approved, communicated, applied, evaluated, and maintained?
A&A-06 Establish, document, approve, communicate, apply, evaluate and maintain a risk-based corrective action plan to remediate audit findings, review and report remediation status to relevant stakeholders.
| Remediation | |
| A&A-06.2 | Is the remediation status of audit findings reviewed and reported to relevant |
stakeholders?
AIS-01.1 Are application security policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained to guide appropriate planning, delivery, and support of the organization's application security capabilities?
AIS-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at least annually.
| Application and Interface Security Policy and Procedures | Application & Interface Security |
| AIS-01.2 | Are application security policies and procedures reviewed and updated at least |
annually?
AIS-02.1 Are baseline requirements to secure different applications established, documented, and maintained?
AIS-02 Establish, document and maintain baseline requirements for securing different applications.
| Application Security Baseline Requirements | |
| AIS-03.1 | Are technical and operational metrics defined and implemented according to |
business objectives, security requirements, and compliance obligations?
AIS-03 Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.
| Application Security Metrics | |
| AIS-04.1 | Is an SDLC process defined and implemented for application design, development, |
deployment, and operation per organizationally designed security requirements?
AIS-04 Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
| Secure Application Design and Development | |
| AIS-05.1 | Does the testing strategy outline criteria to accept new information systems, |
upgrades, and new versions while ensuring application security, compliance adherence, and organizational speed of delivery goals?
AIS-05 Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
| Automated Application Security Testing | |
| AIS-05.2 | Is testing automated when applicable and possible? |
AIS-06.1 Are strategies and capabilities established and implemented to deploy application code in a secure, standardized, and compliant manner?
AIS-06 Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
| Automated Secure Application Deployment | |
| AIS-06.2 | Is the deployment and integration of application code automated where possible? |
| AIS-07.1 | Are application security vulnerabilities remediated following defined processes? | ||
| AIS-07 | Define and implement a process to remediate application security |
vulnerabilities, automating remediation when possible.
| Application Vulnerability Remediation | |
| AIS-07.2 | Is the remediation of application security vulnerabilities automated when |
possible?
BCR-01.1 Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
BCR-01 Establish, document, approve, communicate, apply, evaluate and maintain business continuity management and operational resilience policies and procedures.
Review and update the policies and procedures at least annually.
| Business Continuity Management Policy and Procedures | Business Continuity Management and Operational Resilience |
| BCR-01.2 | Are the policies and procedures reviewed and updated at least annually? |
BCR-02.1 Are criteria for developing business continuity and operational resiliency strategies and capabilities established based on business disruption and risk impacts?
BCR-02 Determine the impact of business disruptions and risks to establish criteria for developing business continuity and operational resilience strategies and capabilities.
| Risk Assessment and Impact Analysis | |
| BCR-03.1 | Are strategies developed to reduce the impact of, withstand, and recover from |
business disruptions in accordance with risk appetite?
BCR-03 Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.
| Business Continuity Strategy | |
| BCR-04.1 | Are operational resilience strategies and capability results incorporated |
to establish, document, approve, communicate, apply, evaluate, and maintain a business continuity plan?
BCR-04 Establish, document, approve, communicate, apply, evaluate and maintain a business continuity plan based on the results of the operational resilience strategies and capabilities.
| Business Continuity Planning | |
| BCR-05.1 | Is relevant documentation developed, identified, and acquired to support business |
continuity and operational resilience plans?
BCR-05 Develop, identify, and acquire documentation that is relevant to support the business continuity and operational resilience programs. Make the documentation available to authorized stakeholders and review periodically.
| Documentation | |
| BCR-05.2 | Is business continuity and operational resilience documentation available |
to authorized stakeholders?
BCR-05.3 Is business continuity and operational resilience documentation reviewed periodically?
BCR-06.1 Are the business continuity and operational resilience plans exercised and tested at least annually and when significant changes occur?
BCR-06 Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.
| Business Continuity Exercises | |
| BCR-07.1 | Do business continuity and resilience procedures establish communication with |
stakeholders and participants?
BCR-07 Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
| Communication | |||
| BCR-08.1 | Is cloud data periodically backed up? | ||
| BCR-08 | Periodically backup data stored in the cloud. Ensure the confidentiality, |
integrity and availability of the backup, and verify data restoration from backup for resiliency.
| Backup | |
| BCR-08.2 | Is the confidentiality, integrity, and availability of backup data ensured? |
BCR-08.3 Can backups be restored appropriately for resiliency?
BCR-09.1 Is a disaster response plan established, documented, approved, applied, evaluated, and maintained to ensure recovery from natural and man-made disasters?
BCR-09 Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.
| Disaster Response Plan | |
| BCR-09.2 | Is the disaster response plan updated at least annually, and when significant |
changes occur?
BCR-10.1 Is the disaster response plan exercised annually or when significant changes occur?
BCR-10 Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.
| Response Plan Exercise | |
| BCR-10.2 | Are local emergency authorities included, if possible, in the exercise? |
BCR-11.1 Is business-critical equipment supplemented with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards?
BCR-11 Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.
| Equipment Redundancy | |
| CCC-01.1 | Are risk management policies and procedures associated with changing organizational |
assets including applications, systems, infrastructure, configuration, etc., established, documented, approved, communicated, applied, evaluated and maintained (regardless of whether asset management is internal or external)?
CCC-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced). Review and update the policies and procedures at least annually.
| Change Management Policy and Procedures | Change Control and Configuration Management |
| CCC-01.2 | Are the policies and procedures reviewed and updated at least annually? |
CCC-02.1 Is a defined quality change control, approval and testing process (with established baselines, testing, and release standards) followed?
CCC-02 Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.
| Quality Testing | |
| CCC-03.1 | Are risks associated with changing organizational assets (including applications, |
systems, infrastructure, configuration, etc.) managed, regardless of whether asset management occurs internally or externally (i.e., outsourced)?
CCC-03 Manage the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced).
| Change Management Technology | |
| CCC-04.1 | Is the unauthorized addition, removal, update, and management of organization |
assets restricted?
CCC-04 Restrict the unauthorized addition, removal, update, and management of organization assets.
| Unauthorized Change Protection | |
| CCC-05.1 | Are provisions to limit changes that directly impact CSC-owned environments |
and require tenants to authorize requests explicitly included within the service level agreements (SLAs) between CSPs and CSCs?
CCC-05 Include provisions limiting changes directly impacting CSCs owned environments/tenants to explicitly authorized requests within service level agreements between CSPs and CSCs.
| Change Agreements | |
| CCC-06.1 | Are change management baselines established for all relevant authorized changes |
on organizational assets?
CCC-06 Establish change management baselines for all relevant authorized changes on organization assets.
| Change Management Baseline | |
| CCC-07.1 | Are detection measures implemented with proactive notification if changes |
deviate from established baselines?
CCC-07 Implement detection measures with proactive notification in case of changes deviating from the established baseline.
| Detection of Baseline Deviation | |
| CCC-08.1 | Is a procedure implemented to manage exceptions, including emergencies, in |
the change and configuration process?
CCC-08 'Implement a procedure for the management of exceptions, including emergencies, in the change and configuration process. Align the procedure with the requirements of GRC-04: Policy Exception Process.'
| Exception Management | |
| CCC-08.2 | 'Is the procedure aligned with the requirements of the GRC-04: Policy Exception |
Process?'
CCC-09.1 Is a process to proactively roll back changes to a previously known "good state" defined and implemented in case of errors or security concerns?
CCC-09 Define and implement a process to proactively roll back changes to a previous known good state in case of errors or security concerns.
| Change Restoration | |
| CEK-01.1 | Are cryptography, encryption, and key management policies and procedures established, |
documented, approved, communicated, applied, evaluated, and maintained?
CEK-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.
| Encryption and Key Management Policy and Procedures | Cryptography, Encryption & Key Management |
| CEK-01.2 | Are cryptography, encryption, and key management policies and procedures reviewed |
and updated at least annually?
CEK-02.1 Are cryptography, encryption, and key management roles and responsibilities defined and implemented?
CEK-02 Define and implement cryptographic, encryption and key management roles and responsibilities.
| CEK Roles and Responsibilities | |
| CEK-03.1 | Are data at-rest and in-transit cryptographically protected using cryptographic |
libraries certified to approved standards?
CEK-03 Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
| Data Encryption | |
| CEK-04.1 | Are appropriate data protection encryption algorithms used that consider data |
classification, associated risks, and encryption technology usability?
CEK-04 Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
| Encryption Algorithm | |
| CEK-05.1 | Are standard change management procedures established to review, approve, |
implement and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources?
CEK-05 Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.
| Encryption Change Management | |
| CEK-06.1 | Are changes to cryptography-, encryption- and key management-related systems, |
policies, and procedures, managed and adopted in a manner that fully accounts for downstream effects of proposed changes, including residual risk, cost, and benefits analysis?
CEK-06 Manage and adopt changes to cryptography-, encryption-, and key management-related systems (including policies and procedures) that fully account for downstream effects of proposed changes, including residual risk, cost, and benefits analysis.
| Encryption Change Cost Benefit Analysis | |
| CEK-07.1 | Is a cryptography, encryption, and key management risk program established |
and maintained that includes risk assessment, risk treatment, risk context, monitoring, and feedback provisions?
CEK-07 Establish and maintain an encryption and key management risk program that includes provisions for risk assessment, risk treatment, risk context, monitoring, and feedback.
| Encryption Risk Management | |
| CEK-08.1 | Are CSPs providing CSCs with the capacity to manage their own data encryption |
keys?
CEK-08 CSPs must provide the capability for CSCs to manage their own data encryption keys.
| CSC Key Management Capability | |
| CEK-09.1 | Are encryption and key management systems, policies, and processes audited |
with a frequency proportional to the system's risk exposure, and after any security event?
CEK-09 Audit encryption and key management systems, policies, and processes with a frequency that is proportional to the risk exposure of the system with audit occurring preferably continuously but at least annually and after any security event(s).
| Encryption and Key Management Audit | |
| CEK-09.2 | Are encryption and key management systems, policies, and processes audited |
(preferably continuously but at least annually)?
CEK-10.1 Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications?
CEK-10 Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.
| Key Generation | |
| CEK-11.1 | Are private keys provisioned for a unique purpose managed, and is cryptography |
secret?
CEK-11 Manage cryptographic secret and private keys that are provisioned for a unique purpose.
| Key Purpose | |
| CEK-12.1 | Are cryptographic keys rotated based on a cryptoperiod calculated while considering |
information disclosure risks and legal and regulatory requirements?
CEK-12 Rotate cryptographic keys in accordance with the calculated cryptoperiod, which includes provisions for considering the risk of information disclosure and legal and regulatory requirements.
| Key Rotation | |
| CEK-13.1 | Are cryptographic keys revoked and removed before the end of the established |
cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures to include legal and regulatory requirement provisions?
CEK-13 Define, implement and evaluate processes, procedures and technical measures to revoke and remove cryptographic keys prior to the end of its established cryptoperiod, when a key is compromised, or an entity is no longer part of the organization, which include provisions for legal and regulatory requirements.
| Key Revocation | |
| CEK-14.1 | Are processes, procedures and technical measures to destroy unneeded keys |
defined, implemented and evaluated to address key destruction outside secure environments, revocation of keys stored in hardware security modules (HSMs), and include applicable legal and regulatory requirement provisions?
CEK-14 Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.
| Key Destruction | |
| CEK-15.1 | Are processes, procedures, and technical measures to create keys in a pre-activated |
state (i.e., when they have been generated but not authorized for use) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?
CEK-15 Define, implement and evaluate processes, procedures and technical measures to create keys in a pre-activated state when they have been generated but not authorized for use, which include provisions for legal and regulatory requirements.
| Key Activation | |
| CEK-16.1 | Are processes, procedures, and technical measures to monitor, review and approve |
key transitions (e.g., from any state to/from suspension) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?
CEK-16 Define, implement and evaluate processes, procedures and technical measures to monitor, review and approve key transitions from any state to/from suspension, which include provisions for legal and regulatory requirements.
| Key Suspension | |
| CEK-17.1 | Are processes, procedures, and technical measures to deactivate keys (at the |
time of their expiration date) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?
CEK-17 Define, implement and evaluate processes, procedures and technical measures to deactivate keys at the time of their expiration date, which include provisions for legal and regulatory requirements.
| Key Deactivation | |
| CEK-18.1 | Are processes, procedures, and technical measures to manage archived keys |
in a secure repository (requiring least privilege access) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?
CEK-18 Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
| Key Archival | |
| CEK-19.1 | Are processes, procedures, and technical measures to encrypt information in |
specific scenarios (e.g., only in controlled circumstances and thereafter only for data decryption and never for encryption) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?
CEK-19 Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
| Key Compromise | |
| CEK-20.1 | Are processes, procedures, and technical measures to assess operational continuity |
risks (versus the risk of losing control of keying material and exposing protected data) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?
CEK-20 Define, implement and evaluate processes, procedures and technical measures to assess the risk to operational continuity versus the risk of the keying material and the information it protects being exposed if control of the keying material is lost, which include provisions for legal and regulatory requirements.
| Key Recovery | |
| CEK-21.1 | Are key management system processes, procedures, and technical measures being |
defined, implemented, and evaluated to track and report all cryptographic materials and status changes that include legal and regulatory requirements provisions?
CEK-21 Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
| Key Inventory Management | |
| DCS-01.1 | Are policies and procedures for the secure disposal of equipment used outside |
the organization's premises established, documented, approved, communicated, enforced, and maintained?
DCS-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible must be applied. Review and update the policies and procedures at least annually.
| Off-Site Equipment Disposal Policy and Procedures | Datacenter Security |
| DCS-01.2 | Is a data destruction procedure applied that renders information recovery |
information impossible if equipment is not physically destroyed?
DCS-01.3 Are policies and procedures for the secure disposal of equipment used outside the organization's premises reviewed and updated at least annually?
DCS-02.1 Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location established, documented, approved, communicated, implemented, enforced, maintained?
DCS-02 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization.
Review and update the policies and procedures at least annually.
| Off-Site Transfer Authorization Policy and Procedures | |
| DCS-02.2 | Does a relocation or transfer request require written or cryptographically |
verifiable authorization?
DCS-02.3 Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location reviewed and updated at least annually?
DCS-03.1 Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained?
DCS-03 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.
| Secure Area Policy and Procedures | |
| DCS-03.2 | Are policies and procedures for maintaining safe, secure working environments |
(e.g., offices, rooms) reviewed and updated at least annually?
DCS-04.1 Are policies and procedures for the secure transportation of physical media established, documented, approved, communicated, enforced, evaluated, and maintained?
DCS-04 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.
| Secure Media Transportation Policy and Procedures | |
| DCS-04.2 | Are policies and procedures for the secure transportation of physical media |
reviewed and updated at least annually?
DCS-05.1 Is the classification and documentation of physical and logical assets based on the organizational business risk?
DCS-05 Classify and document the physical, and logical assets (e.g., applications) based on the organizational business risk.
| Assets Classification | |
| DCS-06.1 | Are all relevant physical and logical assets at all CSP sites cataloged and |
tracked within a secured system?
DCS-06 Catalogue and track all relevant physical and logical assets located at all of the CSP's sites within a secured system.
| Assets Cataloguing and Tracking | |
| DCS-07.1 | Are physical security perimeters implemented to safeguard personnel, data, |
and information systems?
DCS-07 Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.
| Controlled Access Points | |
| DCS-07.2 | Are physical security perimeters established between administrative and business |
areas, data storage, and processing facilities?
| DCS-08.1 | Is equipment identification used as a method for connection authentication? | ||
| DCS-08 | Use equipment identification as a method for connection authentication. | ||
| Equipment Identification | |||
| DCS-09.1 | Are solely authorized personnel able to access secure areas, with all ingress |
and egress areas restricted, documented, and monitored by physical access control mechanisms?
DCS-09 Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.
| Secure Area Authorization | |
| DCS-09.2 | Are access control records retained periodically, as deemed appropriate by |
the organization?
DCS-10.1 Are external perimeter datacenter surveillance systems and surveillance systems at all ingress and egress points implemented, maintained, and operated?
DCS-10 Implement, maintain, and operate datacenter surveillance systems at the external perimeter and at all the ingress and egress points to detect unauthorized ingress and egress attempts.
| Surveillance System | |
| DCS-11.1 | Are datacenter personnel trained to respond to unauthorized access or egress |
attempts?
DCS-11 Train datacenter personnel to respond to unauthorized ingress or egress attempts.
| Unauthorized Access Response Training | |
| DCS-12.1 | Are processes, procedures, and technical measures defined, implemented, and |
evaluated to ensure risk-based protection of power and telecommunication cables from interception, interference, or damage threats at all facilities, offices, and rooms?
DCS-12 Define, implement and evaluate processes, procedures and technical measures that ensure a risk-based protection of power and telecommunication cables from a threat of interception, interference or damage at all facilities, offices and rooms.
| Cabling Security | |
| DCS-13.1 | Are data center environmental control systems designed to monitor, maintain, |
and test that on-site temperature and humidity conditions fall within accepted industry standards effectively implemented and maintained?
DCS-13 Implement and maintain data center environmental control systems that monitor, maintain and test for continual effectiveness the temperature and humidity conditions within accepted industry standards.
| Environmental Systems | |
| DCS-14.1 | Are utility services secured, monitored, maintained, and tested at planned |
intervals for continual effectiveness?
DCS-14 Secure, monitor, maintain, and test utilities services for continual effectiveness at planned intervals.
| Secure Utilities | |
| DCS-15.1 | Is business-critical equipment segregated from locations subject to a high |
probability of environmental risk events?
DCS-15 Keep business-critical equipment away from locations subject to high probability for environmental risk events.
| Equipment Location | |
| DSP-01.1 | Are policies and procedures established, documented, approved, communicated, |
enforced, evaluated, and maintained for the classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level?
DSP-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and procedures at least annually.
| Security and Privacy Policy and Procedures | Data Security and Privacy Lifecycle Management |
| DSP-01.2 | Are data security and privacy policies and procedures reviewed and updated |
at least annually?
DSP-02.1 Are industry-accepted methods applied for secure data disposal from storage media so information is not recoverable by any forensic means?
DSP-02 Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.
| Secure Disposal | |
| DSP-03.1 | Is a data inventory created and maintained for sensitive and personal information |
(at a minimum)?
DSP-03 Create and maintain a data inventory, at least for any sensitive data and personal data.
| Data Inventory | |||
| DSP-04.1 | Is data classified according to type and sensitivity levels? | ||
| DSP-04 | Classify data according to its type and sensitivity level. | ||
| Data Classification | |||
| DSP-05.1 | Is data flow documentation created to identify what data is processed and |
where it is stored and transmitted?
DSP-05 Create data flow documentation to identify what data is processed, stored or transmitted where. Review data flow documentation at defined intervals, at least annually, and after any change.
| Data Flow Documentation | |
| DSP-05.2 | Is data flow documentation reviewed at defined intervals, at least annually, |
and after any change?
DSP-06.1 Is the ownership and stewardship of all relevant personal and sensitive data documented?
DSP-06 Document ownership and stewardship of all relevant documented personal and sensitive data. Perform review at least annually.
| Data Ownership and Stewardship | |
| DSP-06.2 | Is data ownership and stewardship documentation reviewed at least annually? |
DSP-07.1 Are systems, products, and business practices based on security principles by design and per industry best practices?
DSP-07 Develop systems, products, and business practices based upon a principle of security by design and industry best practices.
| Data Protection by Design and Default | |
| DSP-08.1 | Are systems, products, and business practices based on privacy principles |
by design and according to industry best practices?
DSP-08 Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.
| Data Privacy by Design and Default | |
| DSP-08.2 | Are systems' privacy settings configured by default and according to all applicable |
laws and regulations?
DSP-09.1 Is a data protection impact assessment (DPIA) conducted when processing personal data and evaluating the origin, nature, particularity, and severity of risks according to any applicable laws, regulations and industry best practices?
DSP-09 Conduct a Data Protection Impact Assessment (DPIA) to evaluate the origin, nature, particularity and severity of the risks upon the processing of personal data, according to any applicable laws, regulations and industry best practices.
| Data Protection Impact Assessment | |
| DSP-10.1 | Are processes, procedures, and technical measures defined, implemented, and |
evaluated to ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope (as permitted by respective laws and regulations)?
DSP-10 Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.
| Sensitive Data Transfer | |
| DSP-11.1 | Are processes, procedures, and technical measures defined, implemented, and |
evaluated to enable data subjects to request access to, modify, or delete personal data (per applicable laws and regulations)?
DSP-11 Define and implement, processes, procedures and technical measures to enable data subjects to request access to, modification, or deletion of their personal data, according to any applicable laws and regulations.
| Personal Data Access, Reversal, Rectification and Deletion | |
| DSP-12.1 | Are processes, procedures, and technical measures defined, implemented, and |
evaluated to ensure personal data is processed (per applicable laws and regulations and for the purposes declared to the data subject)?
DSP-12 Define, implement and evaluate processes, procedures and technical measures to ensure that personal data is processed according to any applicable laws and regulations and for the purposes declared to the data subject.
| Limitation of Purpose in Personal Data Processing | |
| DSP-13.1 | Are processes, procedures, and technical measures defined, implemented, and |
evaluated for the transfer and sub-processing of personal data within the service supply chain (according to any applicable laws and regulations)?
DSP-13 Define, implement and evaluate processes, procedures and technical measures for the transfer and sub-processing of personal data within the service supply chain, according to any applicable laws and regulations.
| Personal Data Sub-processing | |
| DSP-14.1 | Are processes, procedures, and technical measures defined, implemented, and |
evaluated to disclose details to the data owner of any personal or sensitive data access by sub-processors before processing initiation?
DSP-14 Define, implement and evaluate processes, procedures and technical measures to disclose the details of any personal or sensitive data access by sub-processors to the data owner prior to initiation of that processing.
| Disclosure of Data Sub-processors | |
| DSP-15.1 | Is authorization from data owners obtained, and the associated risk managed, |
before replicating or using production data in non-production environments?
DSP-15 Obtain authorization from data owners, and manage associated risk before replicating or using production data in non-production environments.
| Limitation of Production Data Use | |
| DSP-16.1 | Do data retention, archiving, and deletion practices follow business requirements, |
applicable laws, and regulations?
DSP-16 Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.
| Data Retention and Deletion | |
| DSP-17.1 | Are processes, procedures, and technical measures defined and implemented |
to protect sensitive data throughout its lifecycle?
DSP-17 Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
| Sensitive Data Protection | |
| DSP-18.1 | Does the CSP have in place, and describe to CSCs, the procedure to manage |
and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations?
DSP-18 The CSP must have in place, and describe to CSCs the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations. The CSP must give special attention to the notification procedure to interested CSCs, unless otherwise prohibited, such as a prohibition under criminal law to preserve confidentiality of a law enforcement investigation.
| Disclosure Notification | |
| DSP-18.2 | Does the CSP give special attention to the notification procedure to interested |
CSCs, unless otherwise prohibited, such as a prohibition under criminal law to preserve confidentiality of a law enforcement investigation?
DSP-19.1 Are processes, procedures, and technical measures defined and implemented to specify and document physical data locations, including locales where data is processed or backed up?
DSP-19 Define and implement, processes, procedures and technical measures to specify and document the physical locations of data, including any locations in which data is processed or backed up.
| Data Location | |
| GRC-01.1 | Are information governance program policies and procedures sponsored by organizational |
leadership established, documented, approved, communicated, applied, evaluated, and maintained?
GRC-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.
| Governance Program Policy and Procedures | Governance, Risk and Compliance |
| GRC-01.2 | Are the policies and procedures reviewed and updated at least annually? |
GRC-02.1 Is there an established formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks?
GRC-02 Establish a formal, documented, and leadership-sponsored Enterprise Risk Management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks.
| Risk Management Program | |
| GRC-03.1 | Are all relevant organizational policies and associated procedures reviewed |
at least annually, or when a substantial organizational change occurs?
GRC-03 Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.
| Organizational Policy Reviews | |
| GRC-04.1 | Is an approved exception process mandated by the governance program established |
and followed whenever a deviation from an established policy occurs?
GRC-04 Establish and follow an approved exception process as mandated by the governance program whenever a deviation from an established policy occurs.
| Policy Exception Process | |
| GRC-05.1 | Has an information security program (including programs of all relevant CCM |
domains) been developed and implemented?
GRC-05 Develop and implement an Information Security Program, which includes programs for all the relevant domains of the CCM.
| Information Security Program | |
| GRC-06.1 | Are roles and responsibilities for planning, implementing, operating, assessing, |
and improving governance programs defined and documented?
GRC-06 Define and document roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs.
| Governance Responsibility Model | |
| GRC-07.1 | Are all relevant standards, regulations, legal/contractual, and statutory |
requirements applicable to your organization identified and documented?
GRC-07 Identify and document all relevant standards, regulations, legal/contractual, and statutory requirements, which are applicable to your organization.
| Information System Regulatory Mapping | |
| GRC-08.1 | Is contact established and maintained with cloud-related special interest |
groups and other relevant entities?
GRC-08 Establish and maintain contact with cloud-related special interest groups and other relevant entities in line with business context.
| Special Interest Groups | |
| HRS-01.1 | Are background verification policies and procedures of all new employees (including |
but not limited to remote employees, contractors, and third parties) established, documented, approved, communicated, applied, evaluated, and maintained?
HRS-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for background verification of all new employees (including but not limited to remote employees, contractors, and third parties) according to local laws, regulations, ethics, and contractual constraints and proportional to the data classification to be accessed, the business requirements, and acceptable risk. Review and update the policies and procedures at least annually.
| Background Screening Policy and Procedures | Human Resources |
| HRS-01.2 | Are background verification policies and procedures designed according to |
local laws, regulations, ethics, and contractual constraints and proportional to the data classification to be accessed, business requirements, and acceptable risk?
HRS-01.3 Are background verification policies and procedures reviewed and updated at least annually?
HRS-02.1 Are policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets established, documented, approved, communicated, applied, evaluated, and maintained?
HRS-02 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets. Review and update the policies and procedures at least annually.
| Acceptable Use of Technology Policy and Procedures | |
| HRS-02.2 | Are the policies and procedures for defining allowances and conditions for |
the acceptable use of organizationally-owned or managed assets reviewed and updated at least annually?
HRS-03.1 Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained?
HRS-03 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures that require unattended workspaces to not have openly visible confidential data. Review and update the policies and procedures at least annually.
| Clean Desk Policy and Procedures | |
| HRS-03.2 | Are policies and procedures requiring unattended workspaces to conceal confidential |
data reviewed and updated at least annually?
HRS-04.1 Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained?
HRS-04 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
| Remote and Home Working Policy and Procedures | |
| HRS-04.2 | Are policies and procedures to protect information accessed, processed, or |
stored at remote sites and locations reviewed and updated at least annually?
HRS-05.1 Are return procedures of organizationally-owned assets by terminated employees established and documented?
HRS-05 Establish and document procedures for the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .