ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.9.1: Operational procedures and responsibilities

Operating procedures must be documented, change managed, capacity managed, and development, test and operational environments kept separate, read as covering the systems that process personal data.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 73 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 10 controls

  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.3 6.5.3 Separate pre-production from production
  • 6.5.4 6.5.4 Separate roles between production and pre-production

SOC 2 · 9 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • SOC2-PI1.4 PI1.4 Controls over output delivery
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

ISO 27001:2022 · 5 controls

  • 5.2 Information security roles and responsibilities
  • 5.37 Documented operating procedures
  • 8.31 Separation of development, test and production environments
  • 8.32 Change management
  • 8.6 Capacity management

C5 (Germany) · 4 controls

  • C5-DEV-03 Policies for changes to information systems
  • C5-DEV-10 Separation of environments
  • C5-OPS-01 Capacity Management - Planning
  • C5-SP-01 Documentation, communication and provision of policies and instructions

HIPAA Security Rule · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

FedRAMP High · 3 controls

  • CM-1 Policy and Procedures
  • CM-3 Configuration Change Control
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))

FedRAMP Moderate · 3 controls

  • CM-1 Policy and Procedures
  • CM-3 Configuration Change Control
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))

CIS Controls v8 · 2 controls

  • CIS-16.8 Separate Production and Non-Production Systems
  • CIS-4.1 Establish and Maintain a Secure Configuration Process

CMMC 2.0 · 2 controls

ISO 27002:2022 · 2 controls

  • 5.2 Information security roles and responsibilities
  • 5.37 Documented operating procedures

ISO 19011:2018 · 1 control

  • 5.4.1 Roles and responsibilities of the individual(s) managing the audit programme

ISO 27017:2015 · 1 control

  • 12.1 Operational procedures and responsibilities

ISO 27018:2019 · 1 control

  • 12.1 Operational procedures and responsibilities

ISO/IEC 27010:2015 · 1 control

  • 27010-12.1 Operational Procedures

ISO/IEC 27043:2015 · 1 control

  • ISO27043-21 Operational procedures and responsibilities

ISO/SAE 21434 · 1 control

  • ISO21434-21 Operational procedures and responsibilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.9.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 73 it maps to, and the evidence behind each claim, over MCP and REST.