ISO/IEC 2701841
ISO/IEC 27018:2019 Annex A.10.1 · ISO/IEC 27018:2019 Annex A.10.2 · ISO/IEC 27018:2019 Annex A.10.3 · ISO/IEC 27018:2019 Annex A.11.1 · ISO/IEC 27018:2019 Annex A.11.10 · ISO/IEC 27018:2019 Annex A.11.11 · ISO/IEC 27018:2019 Annex A.11.12 · ISO/IEC 27018:2019 Annex A.11.13 · ISO/IEC 27018:2019 Annex A.11.2 · ISO/IEC 27018:2019 Annex A.11.3 · ISO/IEC 27018:2019 Annex A.11.4 · ISO/IEC 27018:2019 Annex A.11.5 · ISO/IEC 27018:2019 Annex A.11.6 · ISO/IEC 27018:2019 Annex A.11.7 · ISO/IEC 27018:2019 Annex A.11.8 · ISO/IEC 27018:2019 Annex A.11.9 · ISO/IEC 27018:2019 Annex A.12.1 · ISO/IEC 27018:2019 Annex A.12.2 · ISO/IEC 27018:2019 Annex A.2.1 · ISO/IEC 27018:2019 Annex A.3.1 · ISO/IEC 27018:2019 Annex A.3.2 · ISO/IEC 27018:2019 Annex A.5.1 · ISO/IEC 27018:2019 Annex A.6.1 · ISO/IEC 27018:2019 Annex A.6.2 · ISO/IEC 27018:2019 Annex A.8.1 · ISO/IEC 27018:2019 Clause 10.1.1 · ISO/IEC 27018:2019 Clause 10.1.2 · ISO/IEC 27018:2019 Clause 11.2.7 · ISO/IEC 27018:2019 Clause 12.3.1 · ISO/IEC 27018:2019 Clause 12.4.1 · ISO/IEC 27018:2019 Clause 12.4.2 · ISO/IEC 27018:2019 Clause 13.2.1 · ISO/IEC 27018:2019 Clause 16.1.1 · ISO/IEC 27018:2019 Clause 18.1.1 · ISO/IEC 27018:2019 Clause 18.1.4 · ISO/IEC 27018:2019 Clause 5.1.1 · ISO/IEC 27018:2019 Clause 6.1.1 · ISO/IEC 27018:2019 Clause 7.2.2 · ISO/IEC 27018:2019 Clause 8.2.2 · ISO/IEC 27018:2019 Clause 9.2.1 · ISO/IEC 27018:2019 Clause 9.4.2
Requirements in this framework
- Access to data on pre-used data storage space
- Classification of information
- Cloud service customer user ID contracts
- Confidentiality or non-disclosure agreements
- Contracts regarding PII processing
- Control of data restoration
- Disclosure of sub-contracted PII processing
- Encryption of PII transmitted over public networks
- Event logging
- Geographical location of PII
- Identification of applicable legislation and contractual requirements
- Information backup
- Information security awareness, education and training
- Information security roles and responsibilities
- Information transfer policies and procedures
- Intended destination of PII
- Key management
- Mutually agreed upon PII disposal process
- Notification of a data breach involving PII
- Obligation to cooperate regarding PII principals' rights
- PII disclosure notification
- PII return, transfer and disposal
- Policies for information security
- Policy on the use of cryptographic controls
- Privacy and protection of personally identifiable information
- Protection of log information
- Protection of PII on storage media leaving the premises
- Public cloud PII processor's commercial use
- Public cloud PII processor's purpose
- Recording of PII disclosures
- Responsibilities and procedures
- Restriction of creation of hardcopy material
- Retention period for administrative security policies
- Secure disposal of hardcopy materials
- Secure disposal or re-use of equipment
- Secure erasure of temporary files
- Secure log-on procedures
- Sub-contracted PII processing
- Unique use of cloud service customer user IDs
- Use of unencrypted portable storage media and devices
- User registration and de-registration