C5 (Germany)
C5: Compliance

C5 (Germany) C5-COM-03: Internal audits of the information security management system

Have subject matter experts run internal audits at least annually to test whether the information security management system meets the identified legal, regulatory, self imposed and contractual requirements and internal policies, with findings risk assessed and corrective measures defined and tracked.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 52 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APRA CPS 234 · 4 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P33 Skill of Personnel Providing Control Assurance
  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • CPS220-P47 Minimum Assessment Required by the Framework Review

FedRAMP High · 3 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring

FedRAMP Moderate · 3 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring

NIS2 Directive · 3 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

ISO 22301:2019 · 2 controls

ISO 27001:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27701:2019 · 2 controls

  • 5.7.2 Internal audit
  • 5.8.1 Nonconformity and corrective action
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

NIST SP 800-161 Rev 1 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • PV-2 Audit and enforce secure configurations

CMMC 2.0 · 1 control

DORA · 1 control

GDPR · 1 control

HIPAA Security Rule · 1 control

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions

PCI DSS 4.0 · 1 control

  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Compliance

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) C5-COM-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 52 it maps to, and the evidence behind each claim, over MCP and REST.