The Privacy Protection (Data Security) Regulations 5777-2017 (Takhanot Hagannat Hapratiyot - Avtahat Meidah) supplement the 1981 Law with detailed technical and organisational security requirements + graduated by Security Level Classification (Basic/Medium/High). (1) Information Security Officer (ISO/CISO) per Article 3: every controller with medium or high security level database must appoint an ISO Information Security Officer (Mamuneh Avtahat Meidah) responsible for (a) developing + maintaining + implementing the information security policy; (b) advising on database security risks; (c) periodic reporting to management; (d) liaising with PPA on security matters; (e) coordinating incident response; reports to senior management + sufficient independence + qualifications and training appropriate. (2) Information Security Policy + Procedures per Article 4: documented + approved by management + reviewed annually + cascaded to authorised personnel + includes risk assessment + access control + incident response + business continuity + acceptable use + change management + third party management. (3) Access Control per Article 5: role-based access control (RBAC) + least privilege + unique user IDs + password complexity (minimum 8 characters + complexity + 90-day rotation for high security level) + Multi-Factor Authentication (MFA) recommended/required per security level + privileged access management + session controls + access reviews. (4) Logging and Monitoring per Article 6: comprehensive audit logs of access + changes + administrative actions + retained for 24 months minimum + tamper-evident + reviewed regularly + suspicious activity detection + integration with SIEM. (5) Backup and Recovery per Article 7: regular backups + tested restore procedures + offsite storage + retention per regulatory requirements + business continuity planning + RTO/RPO. (6) Physical Security per Article 8: data centre access controls + visitor management + environmental controls + Class A high-security facilities for high-security databases. (7) Removable Media and Mobile Device Control per Article 9: encrypted removable media + mobile device management (MDM) + remote wipe + BYOD policy + data loss prevention (DLP). (8) Risk Assessment per Article 10: periodic risk assessment + considering threats + vulnerabilities + impacts + treatment plan + integration with broader risk management. (9) Penetration Testing per Article 10A: high-security databases require annual external penetration testing by qualified testers + findings remediation tracking. (10) Annual Internal Audit per Article 11: documented internal audit covering all security regulations + reported to senior management + findings tracked through remediation. (11) Cybersecurity Coordination: Israeli National Cyber Directorate (INCD) sectoral CERT integration + critical infrastructure protection + sector-specific (Finance + Healthcare + Telecom + Energy). (12) Amendment 13 Cyber Updates 2024: enhanced cyber requirements + ransomware preparedness + supply chain risk + cloud-specific controls + Israel National Cyber Directorate coordination + INCD guidelines integration. Coordinates with ISO 27001 + ISO 27017 + ISO 27018 + ISO 22301 + NIST CSF + Israel National Cyber Directorate guidelines + Israel CERT + IL-CERT + Sector CERTs + INCD Critical Infrastructure Protection. Israel POPL Data Security Regulations 2017 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.