ExportableProof — Routines today. Proof tomorrow.

Arcfield A.5 · Organizational audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 A.5 · Organizational audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (supplier, certification, assets).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.

Results at a glance

5 %Conformity35/37 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
35 %Defined13/37 yes. Defined = yes / rated artefacts or identities. partially is not yes.
51 %Implemented19/37 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/19 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.

How A.5 · Organizational is set up

Asset Management Policy
Vol. 1installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

Information Classification Policy
Vol. 1Vol. 3installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

Contract Security Schedule
Vol. 2not installeddocumentedPremium

Named documented evidence. Not in this pack.

Artefact

Incident Management Policy
Vol. 2Vol. 3Vol. 4not installeddocumentedPremium

Named documented evidence. Not in this pack.

Artefact

Documented Operating Procedure Template
Vol. 2not installeddocumentedPremium

Named documented evidence. Not in this pack.

Artefact

Supplier Relationships Policy
Vol. 1Vol. 5installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

ISMS Communication Plan
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Asset Inventory
Vol. 1Vol. 2Vol. 3installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Information Assets Statement
Vol. 1installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Document Register
Vol. 1Vol. 2installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Access Control Matrix
Vol. 2Vol. 3not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Access Rights Register
Vol. 2Vol. 3not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

AST-001
unmappednot installedimplemented

Named implemented evidence. Not in this pack.

Artefact

AST-003
unmappednot installedimplemented

Named implemented evidence. Not in this pack.

Artefact

AST-002
unmappednot installedimplemented

Named implemented evidence. Not in this pack.

Artefact

AST-009
unmappednot installedimplemented

Named implemented evidence. Not in this pack.

Artefact

AST-007
unmappednot installedimplemented

Named implemented evidence. Not in this pack.

Artefact

AST-005
unmappednot installedimplemented

Named implemented evidence. Not in this pack.

Artefact

Mandatory Documents and Records Register
Vol. 2not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Records Retention Schedule
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Users and Access Inventory
Vol. 2Vol. 3not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Critical Supplier Security Assessment Questionnaire
Vol. 1Vol. 2Vol. 5installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Continual Improvement Log
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Evidence Log / Audit Pack Index
Vol. 2not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Legal, Regulatory and Contractual Requirements Register
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Internal Audit Plan
Vol. 1Vol. 2installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

ISO 27001 Clauses 4-10 Requirements Tracker
Vol. 2not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Supplier Inventory
Vol. 1Vol. 5installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Supplier Security Assessment Questionnaire
Vol. 1Vol. 5installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Systems Architecture Statement
Vol. 1Vol. 3Vol. 4installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Topic reports remain the process evidence: supplier, certification, assets.

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
A.5.1 Policies for information securityA.5.1 Policies for information security has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.10 Acceptable use of information and other associated assetsA.5.10 Acceptable use of information and other associated assets has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.11 Return of assetsA.5.11 Return of assets has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.13 Labelling of informationA.5.13 Labelling of information is named in this pack, but there is no effectiveness evidence. Cited policy: ICP. Cited implementation: DR.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.14 Information transferA.5.14 Information transfer has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.15 Access controlA.5.15 Access control is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.16 Identity managementA.5.16 Identity management has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.17 Authentication informationA.5.17 Authentication information has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.18 Access rightsA.5.18 Access rights is named in this pack, but there is no effectiveness evidence. Cited implementation: ARR, AST-001, AST-003, AST-002, AST-009, AST-007, AST-005.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.19 Information security in supplier relationshipsA.5.19 Information security in supplier relationships is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.2 Information security roles and responsibilitiesA.5.2 Information security roles and responsibilities has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.20 Addressing information security within supplier agreementsA.5.20 Addressing information security within supplier agreements is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: CSSAQ.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.21 Managing information security in the ICT supply chainA.5.21 Managing information security in the ICT supply chain is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.22 Monitoring, review and change management of supplier servicesA.5.22 Monitoring, review and change management of supplier services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.23 Information security for use of cloud servicesA.5.23 Information security for use of cloud services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.24 Information security incident management planning and preparationA.5.24 Information security incident management planning and preparation is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.25 Assessment and decision on information security eventsA.5.25 Assessment and decision on information security events is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.26 Response to information security incidentsA.5.26 Response to information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.27 Learning from information security incidentsA.5.27 Learning from information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: CIL, MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.28 Collection of evidenceA.5.28 Collection of evidence is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: ELAI, MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.29 Information security during disruptionA.5.29 Information security during disruption has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.3 Segregation of dutiesA.5.3 Segregation of duties has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.30 ICT readiness for business continuityA.5.30 ICT readiness for business continuity has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.31 Legal, statutory, regulatory and contractual requirementsA.5.31 Legal, statutory, regulatory and contractual requirements is named in this pack, but there is no effectiveness evidence. Cited implementation: LRR.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.32 Intellectual property rightsA.5.32 Intellectual property rights has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.33 Protection of recordsA.5.33 Protection of records is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.34 Privacy and protection of PIIA.5.34 Privacy and protection of PII has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.35 Independent review of information securityA.5.35 Independent review of information security is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.36 Compliance with policies, rules and standards for information securityA.5.36 Compliance with policies, rules and standards for information security is named in this pack, but there is no effectiveness evidence. Cited implementation: REQT.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.4 Management responsibilitiesA.5.4 Management responsibilities has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.5 Contact with authoritiesA.5.5 Contact with authorities is named in this pack, but there is no effectiveness evidence. Cited implementation: COMM-P.minorRequirement ↔ evidenceNC-A5-missing-evidence
A.5.6 Contact with special interest groupsA.5.6 Contact with special interest groups has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.7 Threat intelligenceA.5.7 Threat intelligence has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.8 Information security in project managementA.5.8 Information security in project management has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A5-not-implemented
A.5.9 Inventory of information and other associated assetsA.5.9 Inventory of information and other associated assets is named in this pack, but there is no effectiveness evidence. Cited policy: AMP. Cited implementation: AI, IAS.minorRequirement ↔ evidenceNC-A5-missing-evidence

ISO 27001 norms and controls

Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.

IndexNameKindDefinedImplementedEffective
A.5.1Policies for information securitycontrolnonoDK
A.5.2Information security roles and responsibilitiescontrolnonoDK
A.5.3Segregation of dutiescontrolnonoDK
A.5.4Management responsibilitiescontrolnonoDK
A.5.5Contact with authoritiescontrolnoyesno
A.5.6Contact with special interest groupscontrolnonoDK
A.5.7Threat intelligencecontrolnonoDK
A.5.8Information security in project managementcontrolnonoDK
A.5.9Inventory of information and other associated assetscontrolyesyesno
A.5.10Acceptable use of information and other associated assetscontrolnonoDK
A.5.11Return of assetscontrolnonoDK
A.5.12Classification of informationcontrolyesnoDK
A.5.13Labelling of informationcontrolyesyesno
A.5.14Information transfercontrolnonoDK
A.5.15Access controlcontrolnoyesno
A.5.16Identity managementcontrolnonoDK
A.5.17Authentication informationcontrolnonoDK
A.5.18Access rightscontrolnoyesno
A.5.19Information security in supplier relationshipscontrolyesyesno
A.5.20Addressing information security within supplier agreementscontrolyesyesno
A.5.21Managing information security in the ICT supply chaincontrolnoyesno
A.5.22Monitoring, review and change management of supplier servicescontrolyesyesno
A.5.23Information security for use of cloud servicescontrolyesyesno
A.5.24Information security incident management planning and preparationcontrolyesyesno
A.5.25Assessment and decision on information security eventscontrolyesyesno
A.5.26Response to information security incidentscontrolyesyesno
A.5.27Learning from information security incidentscontrolyesyesno
A.5.28Collection of evidencecontrolyesyesno
A.5.29Information security during disruptioncontrolnonoDK
A.5.30ICT readiness for business continuitycontrolnonoDK
A.5.31Legal, statutory, regulatory and contractual requirementscontrolnoyesno
A.5.32Intellectual property rightscontrolnonoDK
A.5.33Protection of recordscontrolnoyesno
A.5.34Privacy and protection of PIIcontrolnonoDK
A.5.35Independent review of information securitycontrolnoyesno
A.5.36Compliance with policies, rules and standards for information securitycontrolnoyesno
A.5.37Documented operating procedurescontrolyesnoDK

What we found

What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

A.5.1 Policies for information security

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.1 Policies for information security has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.2 Information security roles and responsibilities

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.2 Information security roles and responsibilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.3 Segregation of duties

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.3 Segregation of duties has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.4 Management responsibilities

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.4 Management responsibilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.5 Contact with authorities

Quantitative

Qualitative

Cited artefacts in this pack: COMM-P. Nonconformities recorded: A.5.5 Contact with authorities is named in this pack, but there is no effectiveness evidence. Cited implementation: COMM-P.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.6 Contact with special interest groups

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.6 Contact with special interest groups has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.7 Threat intelligence

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.7 Threat intelligence has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.8 Information security in project management

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.8 Information security in project management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.9 Inventory of information and other associated assets

Quantitative

Qualitative

Cited artefacts in this pack: AMP, AI, IAS. Nonconformities recorded: A.5.9 Inventory of information and other associated assets is named in this pack, but there is no effectiveness evidence. Cited policy: AMP. Cited implementation: AI, IAS.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.10 Acceptable use of information and other associated assets

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.10 Acceptable use of information and other associated assets has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.11 Return of assets

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.11 Return of assets has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.12 Classification of information

Quantitative

Qualitative

Cited artefacts in this pack: ICP. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.13 Labelling of information

Quantitative

Qualitative

Cited artefacts in this pack: ICP, DR. Nonconformities recorded: A.5.13 Labelling of information is named in this pack, but there is no effectiveness evidence. Cited policy: ICP. Cited implementation: DR.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.14 Information transfer

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.14 Information transfer has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.15 Access control

Quantitative

Qualitative

Cited artefacts in this pack: ACM. Nonconformities recorded: A.5.15 Access control is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.16 Identity management

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.16 Identity management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.17 Authentication information

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.17 Authentication information has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.18 Access rights

Quantitative

Qualitative

Cited artefacts in this pack: ARR, AST-001, AST-003, AST-002, AST-009, AST-007, AST-005. Nonconformities recorded: A.5.18 Access rights is named in this pack, but there is no effectiveness evidence. Cited implementation: ARR, AST-001, AST-003, AST-002, AST-009, AST-007, AST-005.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.19 Information security in supplier relationships

Quantitative

Qualitative

Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI, CSSAQ. Nonconformities recorded: A.5.19 Information security in supplier relationships is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.20 Addressing information security within supplier agreements

Quantitative

Qualitative

Cited artefacts in this pack: CSS, CSSAQ. Nonconformities recorded: A.5.20 Addressing information security within supplier agreements is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.21 Managing information security in the ICT supply chain

Quantitative

Qualitative

Cited artefacts in this pack: CSSAQ. Nonconformities recorded: A.5.21 Managing information security in the ICT supply chain is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.22 Monitoring, review and change management of supplier services

Quantitative

Qualitative

Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI, CSSAQ. Nonconformities recorded: A.5.22 Monitoring, review and change management of supplier services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.23 Information security for use of cloud services

Quantitative

Qualitative

Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.23 Information security for use of cloud services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.24 Information security incident management planning and preparation

Quantitative

Qualitative

Cited artefacts in this pack: IMP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.24 Information security incident management planning and preparation is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.25 Assessment and decision on information security events

Quantitative

Qualitative

Cited artefacts in this pack: IMP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.25 Assessment and decision on information security events is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.26 Response to information security incidents

Quantitative

Qualitative

Cited artefacts in this pack: IMP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.26 Response to information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.27 Learning from information security incidents

Quantitative

Qualitative

Cited artefacts in this pack: IMP, CIL, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.27 Learning from information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: CIL, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.28 Collection of evidence

Quantitative

Qualitative

Cited artefacts in this pack: IMP, ELAI, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.28 Collection of evidence is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: ELAI, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.29 Information security during disruption

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.29 Information security during disruption has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.30 ICT readiness for business continuity

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.30 ICT readiness for business continuity has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.31 Legal, statutory, regulatory and contractual requirements

Quantitative

Qualitative

Cited artefacts in this pack: LRR. Nonconformities recorded: A.5.31 Legal, statutory, regulatory and contractual requirements is named in this pack, but there is no effectiveness evidence. Cited implementation: LRR.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.32 Intellectual property rights

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.32 Intellectual property rights has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.33 Protection of records

Quantitative

Qualitative

Cited artefacts in this pack: RRS. Nonconformities recorded: A.5.33 Protection of records is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.34 Privacy and protection of PII

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.34 Privacy and protection of PII has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.35 Independent review of information security

Quantitative

Qualitative

Cited artefacts in this pack: IAP. Nonconformities recorded: A.5.35 Independent review of information security is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.36 Compliance with policies, rules and standards for information security

Quantitative

Qualitative

Cited artefacts in this pack: REQT. Nonconformities recorded: A.5.36 Compliance with policies, rules and standards for information security is named in this pack, but there is no effectiveness evidence. Cited implementation: REQT.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.5.37 Documented operating procedures

Quantitative

Qualitative

Cited artefacts in this pack: DOP. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 3Vol. 4Vol. 5

Presence

installednot installed

Kind

evidencepolicyassetprocessoperational-targetunmappeddependencyassessmentcontrolsystem

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…