Australia Consumer Data Right - Banking (CDR)
Information Security (Schedule 2)

Australia Consumer Data Right - Banking (CDR) AUCDR-IS-3: Securely manage information assets over their lifecycle

Securely manage information assets within the CDR data environment over their lifecycle, including data loss prevention, controls over CDR data in non-production environments, and information asset lifecycle management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 82 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 6 controls

  • AC-4 Information Flow Enforcement
  • CM-12 Information Location (CM-12)
  • MP-6 Media Sanitization
  • SA-3 System Development Life Cycle
  • SI-12 Information Management and Retention
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))

FedRAMP Moderate · 6 controls

  • AC-4 Information Flow Enforcement
  • CM-12 Information Location (CM-12)
  • MP-6 Media Sanitization
  • SA-3 System Development Life Cycle
  • SI-12 Information Management and Retention
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))

ISO 27001:2022 · 6 controls

  • 5.9 Inventory of information and other associated assets
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion
  • 8.12 Data leakage prevention
  • 8.31 Separation of development, test and production environments
  • 8.33 Test information

ISO 27002:2022 · 6 controls

  • 5.9 Inventory of information and other associated assets
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion
  • 8.12 Data leakage prevention
  • 8.31 Separation of development, test and production environments
  • 8.33 Test information

ISO 27701:2019 · 5 controls

NIST SP 800-171 Rev 3 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

  • AM-3 Ensure security of asset lifecycle management
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • ASBv3-DS-7 Enable logging and monitoring in DevOps
  • DP-2 Monitor anomalies and threats targeting sensitive data

CIS Controls v8 · 4 controls

  • CIS-16.8 Separate Production and Non-Production Systems
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.2 Establish and Maintain a Data Inventory

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

C5 (Germany) · 3 controls

  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected

NIST SP 800-161 Rev 1 · 3 controls

  • 161R1-CM-8 System Component Inventory
  • 161R1-PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
  • 161R1-SI-12 Information Management and Retention

CMMC 2.0 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 6.5.5 6.5.5 No live PANs in pre-production

APRA CPS 234 · 1 control

  • CPS234-20 Information Asset Classification
  • BR-OF-A5 Scope of data and services shared

GDPR · 1 control

SOC 2 · 1 control

  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Information Security (Schedule 2)

You are reading one control. How much of Australia Consumer Data Right - Banking (CDR) have you already done?

Australia Consumer Data Right - Banking (CDR) AUCDR-IS-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Australia Consumer Data Right - Banking (CDR) your existing evidence covers. Hold ISO 27701:2019 and 16 of 24 Australia Consumer Data Right - Banking (CDR) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 82 it maps to, and the evidence behind each claim, over MCP and REST.