Germany Federal Data Protection Act (BDSG)
Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG)

Germany Federal Data Protection Act (BDSG) s64: s 64 Implement risk-based security measures, including the fourteen control objectives for automated processing

Controller and processor implement technical and organisational measures giving security appropriate to the risk, particularly for special categories, taking account of the Federal Office for Information Security's technical guidelines and recommendations; measures may include pseudonymisation and encryption and should ensure ongoing confidentiality, integrity, availability and resilience and timely restoration after an incident. For automated processing, after a risk evaluation, measures must achieve equipment access control, data media control, storage control, user control, data access control, communication control, input control, transport control, recovery, reliability, integrity, processing control, availability control and separability; state-of-the-art encryption can serve several of these.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.