GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.32: Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 180 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-5 Limit, prevent, detect and remove malware
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

SOC 2 · 7 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-C1.1 Confidential information is identified and protected during receipt, processing, storage
  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.7 Transmission of data is restricted to authorized users
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-P4.3 Personal information is securely disposed of
  • CBPR-06 Security Safeguards
  • CBPR-PR-27 Physical, technical and administrative safeguards
  • CBPR-PR-28 Safeguards proportional to risk
  • CBPR-PR-30 Specific proportional safeguards in place
  • CBPR-PR-32 Detection, prevention and response measures
  • CBPR-PR-33 Testing the effectiveness of safeguards

ISO 27701:2019 · 6 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.7.1 Cryptographic controls
  • 6.9.3 Backup
  • 7.4.9 PII transmission controls
  • 8.2.1 Customer agreement
  • 8.4.3 PII transmission controls

ISO 27001:2022 · 5 controls

  • 5.30 ICT readiness for business continuity
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.35 Independent review of information security
  • 8.13 Information backup
  • 8.24 Use of cryptography

ISO 27002:2022 · 5 controls

  • 5.30 ICT readiness for business continuity
  • 5.34 Privacy and protection of PII
  • 5.35 Independent review of information security
  • 8.13 Information backup
  • 8.24 Use of cryptography

NIS2 Directive · 5 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • Art.21.2.i Human resources security, access control policies and asset management
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

NIST SP 800-53 Rev 5 · 5 controls

C5 (Germany) · 4 controls

  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

DORA · 4 controls

  • DORA-Art.12 Backup policies and procedures, restoration and recovery
  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.56 Data protection
  • DORA-Art.9 Protection and prevention

FedRAMP High · 4 controls

  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • SI-6 Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system

FedRAMP Moderate · 4 controls

  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • SI-6 Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system
  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • SI-6 Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system

APPI · 3 controls

Canadian PIPEDA · 3 controls

  • CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I)
  • CRA-Art.14_16 Reporting obligations and the single reporting platform (Articles 14 and 16)
  • CRA-Art.31 Technical documentation (Article 31 + Annex VII)
  • PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment
  • PSD2-Art.95 Management of operational and security risks (PSD2 Article 95)
  • PSD2-Art.97 Strong Customer Authentication (PSD2 Article 97) - knowledge / possession / inherence + dynamic linking
  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • CA-7 Continuous Monitoring
  • CP-10 System Recovery and Reconstitution
  • SC-13 Cryptographic Protection
  • ZDPA-07 Security of Processing
  • ZDPA-17 Cybersecurity and Critical Information Infrastructure
  • ZIMBABWE-3 Security and Cross-Border

CCPA/CPRA · 2 controls

  • §1798.100 General Duties of Businesses that Collect Personal Information
  • §1798.150 Private Right of Action for Data Breaches
  • CDR-PS-12 Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification
  • CDR-RULE-SECURITY Information Security (CDR Rules Schedule 2)
  • EMV3DS-20 Message security and key management
  • EMV3DS-21 Cardholder data protection and minimisation

ETSI EN 303 645 · 2 controls

  • EN303645-5.8 Ensure that personal data is secure
  • EN303645-6 Data Protection Provisions for Consumer IoT (Clause 6)

EU AI Act · 2 controls

  • EUAI-Art.15 Accuracy, robustness and cybersecurity
  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • AILD-Art.3.1 Disclosure of evidence on request (Article 3(1))
  • AILD-Art.4.1 Rebuttable presumption of a causal link (Article 4(1))
  • DGA-Art.12 Conditions for providing data intermediation services (Article 12)
  • DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6)
  • NCCS-Art.29_30_31 Common electricity cybersecurity framework and minimum cybersecurity controls (NCCS Articles 29-31) - for high-impact entities
  • NCCS-Art.48_49_50 Information protection and classification (NCCS Articles 48-50)
  • CPNI-64.2009 Safeguards required for use of CPNI (47 CFR 64.2009)
  • CPNI-64.2011 Notification of CPNI security breaches (47 CFR 64.2011)
  • APP-11 APP 11 - Security of personal information
  • AT-DSG-4 Section 6 - Data secrecy (Datengeheimnis)

Bahrain PDPL · 1 control

  • BW-DPA-s32 Safeguards for processing of personal data

COPPA · 1 control

  • COPPA-312.8 Confidentiality, Security, and Integrity (Written Information Security Program)
  • CZ-110-§40 Zabezpeceni zpracovani (security of processing)
  • ESRB-PC-15 Confidentiality, security and integrity of child PI
  • CSA-Art.8 Security of the Alert System (Article 8)
  • EMFA-Art.4 Rights of media service providers (Article 4) - editorial independence, source protection, anti-spyware
  • IVDR-Art.102_103_104 Confidentiality, data protection and Medical Device Coordination Group cooperation (Articles 102-104)
  • ePD-Art.4 Security of services and personal-data-breach notification (Article 4)
  • EST-IKS-§43-45 Security measures and breach notification in law enforcement processing

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 180 it maps to, and the evidence behind each claim, over MCP and REST.