C5 (Germany)
C5: Organisation of Information Security

C5 (Germany) OIS-01: Information Security Management System (ISMS)

Operate an information security management system aligned to ISO/IEC 27001 covering the organisational units, sites and processes that deliver the cloud service, and retain documented scope, statement of applicability and the latest management review results.

What else in your programme already covers this

This control maps to 55 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

APRA CPS 234 · 4 controls

  • CPS234-13 Board Responsibility for Information Security
  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CPS234-19 Information Security Policy Framework

PCI DSS 4.0 · 4 controls

  • 1.1.2 Roles and responsibilities for Requirement 1
  • 12.1.1 An overall information security policy is: • Established. • Published. • Maintained. • Disseminated to all relevant personnel, as well as to relevant vendors and business partners
  • 12.1.3 Information security roles and responsibilities defined and acknowledged
  • 12.1.4 CISO or equivalent responsibility
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-37 Protection of Swap Data Repository Data
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

HIPAA Security Rule · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-PM-1 Information Security Program Plan. Develop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security program and a description of the security program management controls and
  • NIST800-PM-2 Information Security Program Leadership Role. Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program
  • NIST800-PM-29 Risk Management Program Leadership Roles. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and Establish a Risk Executive

SOC 2 · 3 controls

  • SOC2-CC1.1 COSO principle 1: Demonstrates commitment to integrity and ethical values
  • SOC2-CC1.2 COSO principle 2: Board exercises oversight responsibility
  • SOC2-CC1.3 COSO principle 3: Management establishes structures, reporting lines, and authorities
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment
  • ASBv3-GS-5 Define and implement security posture management strategy
  • GS-1 Align organization roles, responsibilities and accountabilities

ISO 27001:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

DORA · 1 control

FedRAMP High · 1 control

  • PL-2 System Security and Privacy Plans

FedRAMP Moderate · 1 control

  • PL-2 System Security and Privacy Plans

ISO 22301:2019 · 1 control

  • 5.3 Roles, responsibilities and authorities

ISO 27701:2019 · 1 control

  • 5.2.4 Information security management system

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document
  • PL-2 System Security and Privacy Plans
  • PL-2 System Security and Privacy Plans
  • PL-2 System Security and Privacy Plans

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Organisation of Information Security

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) OIS-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 55 it maps to, and the evidence behind each claim, over MCP and REST.