Arcfield A.5 · Organizational audit
Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION
How this report is elaborated
Scope is the Volume 1 A.5 · Organizational audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (supplier, certification, assets).
The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.
How to read this report
Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.
Results at a glance
Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.
How A.5 · Organizational is set up
Upper row is documented information. Lower row is operating evidence. Green is installed here. Dashed is named, not packed. The subject is the clause or control.
Documented evidence in this pack. Not a certification PASS.
Documented evidence in this pack. Not a certification PASS.
Named documented evidence. Not in this pack.
Named documented evidence. Not in this pack.
Named documented evidence. Not in this pack.
Documented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Implemented evidence in this pack. Not a certification PASS.
Topic reports remain the process evidence: supplier, certification, assets.
Nonconformities
Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.
| Requirement | Statement | Grade | Path | Detail |
|---|---|---|---|---|
| A.5.1 Policies for information security | A.5.1 Policies for information security has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.10 Acceptable use of information and other associated assets | A.5.10 Acceptable use of information and other associated assets has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.11 Return of assets | A.5.11 Return of assets has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.13 Labelling of information | A.5.13 Labelling of information is named in this pack, but there is no effectiveness evidence. Cited policy: ICP. Cited implementation: DR. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.14 Information transfer | A.5.14 Information transfer has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.15 Access control | A.5.15 Access control is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.16 Identity management | A.5.16 Identity management has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.17 Authentication information | A.5.17 Authentication information has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.18 Access rights | A.5.18 Access rights is named in this pack, but there is no effectiveness evidence. Cited implementation: ARR, AST-001, AST-003, AST-002, AST-009, AST-007, AST-005. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.19 Information security in supplier relationships | A.5.19 Information security in supplier relationships is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.2 Information security roles and responsibilities | A.5.2 Information security roles and responsibilities has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.20 Addressing information security within supplier agreements | A.5.20 Addressing information security within supplier agreements is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: CSSAQ. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.21 Managing information security in the ICT supply chain | A.5.21 Managing information security in the ICT supply chain is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.22 Monitoring, review and change management of supplier services | A.5.22 Monitoring, review and change management of supplier services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.23 Information security for use of cloud services | A.5.23 Information security for use of cloud services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.24 Information security incident management planning and preparation | A.5.24 Information security incident management planning and preparation is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.25 Assessment and decision on information security events | A.5.25 Assessment and decision on information security events is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.26 Response to information security incidents | A.5.26 Response to information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.27 Learning from information security incidents | A.5.27 Learning from information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: CIL, MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.28 Collection of evidence | A.5.28 Collection of evidence is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: ELAI, MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.29 Information security during disruption | A.5.29 Information security during disruption has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.3 Segregation of duties | A.5.3 Segregation of duties has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.30 ICT readiness for business continuity | A.5.30 ICT readiness for business continuity has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.31 Legal, statutory, regulatory and contractual requirements | A.5.31 Legal, statutory, regulatory and contractual requirements is named in this pack, but there is no effectiveness evidence. Cited implementation: LRR. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.32 Intellectual property rights | A.5.32 Intellectual property rights has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.33 Protection of records | A.5.33 Protection of records is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.34 Privacy and protection of PII | A.5.34 Privacy and protection of PII has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.35 Independent review of information security | A.5.35 Independent review of information security is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.36 Compliance with policies, rules and standards for information security | A.5.36 Compliance with policies, rules and standards for information security is named in this pack, but there is no effectiveness evidence. Cited implementation: REQT. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.4 Management responsibilities | A.5.4 Management responsibilities has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.5 Contact with authorities | A.5.5 Contact with authorities is named in this pack, but there is no effectiveness evidence. Cited implementation: COMM-P. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
| A.5.6 Contact with special interest groups | A.5.6 Contact with special interest groups has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.7 Threat intelligence | A.5.7 Threat intelligence has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.8 Information security in project management | A.5.8 Information security in project management has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A5-not-implemented |
| A.5.9 Inventory of information and other associated assets | A.5.9 Inventory of information and other associated assets is named in this pack, but there is no effectiveness evidence. Cited policy: AMP. Cited implementation: AI, IAS. | minor | Requirement ↔ evidence | NC-A5-missing-evidence |
ISO 27001 norms and controls
Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.
| Index | Name | Kind | Defined | Implemented | Effective |
|---|---|---|---|---|---|
| A.5.1 | Policies for information security | control | no | no | DK |
| A.5.2 | Information security roles and responsibilities | control | no | no | DK |
| A.5.3 | Segregation of duties | control | no | no | DK |
| A.5.4 | Management responsibilities | control | no | no | DK |
| A.5.5 | Contact with authorities | control | no | yes | no |
| A.5.6 | Contact with special interest groups | control | no | no | DK |
| A.5.7 | Threat intelligence | control | no | no | DK |
| A.5.8 | Information security in project management | control | no | no | DK |
| A.5.9 | Inventory of information and other associated assets | control | yes | yes | no |
| A.5.10 | Acceptable use of information and other associated assets | control | no | no | DK |
| A.5.11 | Return of assets | control | no | no | DK |
| A.5.12 | Classification of information | control | yes | no | DK |
| A.5.13 | Labelling of information | control | yes | yes | no |
| A.5.14 | Information transfer | control | no | no | DK |
| A.5.15 | Access control | control | no | yes | no |
| A.5.16 | Identity management | control | no | no | DK |
| A.5.17 | Authentication information | control | no | no | DK |
| A.5.18 | Access rights | control | no | yes | no |
| A.5.19 | Information security in supplier relationships | control | yes | yes | no |
| A.5.20 | Addressing information security within supplier agreements | control | yes | yes | no |
| A.5.21 | Managing information security in the ICT supply chain | control | no | yes | no |
| A.5.22 | Monitoring, review and change management of supplier services | control | yes | yes | no |
| A.5.23 | Information security for use of cloud services | control | yes | yes | no |
| A.5.24 | Information security incident management planning and preparation | control | yes | yes | no |
| A.5.25 | Assessment and decision on information security events | control | yes | yes | no |
| A.5.26 | Response to information security incidents | control | yes | yes | no |
| A.5.27 | Learning from information security incidents | control | yes | yes | no |
| A.5.28 | Collection of evidence | control | yes | yes | no |
| A.5.29 | Information security during disruption | control | no | no | DK |
| A.5.30 | ICT readiness for business continuity | control | no | no | DK |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | control | no | yes | no |
| A.5.32 | Intellectual property rights | control | no | no | DK |
| A.5.33 | Protection of records | control | no | yes | no |
| A.5.34 | Privacy and protection of PII | control | no | no | DK |
| A.5.35 | Independent review of information security | control | no | yes | no |
| A.5.36 | Compliance with policies, rules and standards for information security | control | no | yes | no |
| A.5.37 | Documented operating procedures | control | yes | no | DK |
What we found
What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.
A.5.1 Policies for information security
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.1 Policies for information security has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.2 Information security roles and responsibilities
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.2 Information security roles and responsibilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.3 Segregation of duties
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.3 Segregation of duties has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.4 Management responsibilities
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.4 Management responsibilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.5 Contact with authorities
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: COMM-P. Nonconformities recorded: A.5.5 Contact with authorities is named in this pack, but there is no effectiveness evidence. Cited implementation: COMM-P.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.6 Contact with special interest groups
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.6 Contact with special interest groups has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.7 Threat intelligence
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.7 Threat intelligence has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.8 Information security in project management
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.8 Information security in project management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.9 Inventory of information and other associated assets
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 3.
Qualitative
Cited artefacts in this pack: AMP, AI, IAS. Nonconformities recorded: A.5.9 Inventory of information and other associated assets is named in this pack, but there is no effectiveness evidence. Cited policy: AMP. Cited implementation: AI, IAS.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.10 Acceptable use of information and other associated assets
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.10 Acceptable use of information and other associated assets has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.11 Return of assets
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.11 Return of assets has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.12 Classification of information
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 0.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: ICP. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.13 Labelling of information
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 2.
Qualitative
Cited artefacts in this pack: ICP, DR. Nonconformities recorded: A.5.13 Labelling of information is named in this pack, but there is no effectiveness evidence. Cited policy: ICP. Cited implementation: DR.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.14 Information transfer
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.14 Information transfer has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.15 Access control
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: ACM. Nonconformities recorded: A.5.15 Access control is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.16 Identity management
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.16 Identity management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.17 Authentication information
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.17 Authentication information has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.18 Access rights
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 7.
Qualitative
Cited artefacts in this pack: ARR, AST-001, AST-003, AST-002, AST-009, AST-007, AST-005. Nonconformities recorded: A.5.18 Access rights is named in this pack, but there is no effectiveness evidence. Cited implementation: ARR, AST-001, AST-003, AST-002, AST-009, AST-007, AST-005.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.19 Information security in supplier relationships
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 7.
Qualitative
Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI, CSSAQ. Nonconformities recorded: A.5.19 Information security in supplier relationships is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.20 Addressing information security within supplier agreements
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 2.
Qualitative
Cited artefacts in this pack: CSS, CSSAQ. Nonconformities recorded: A.5.20 Addressing information security within supplier agreements is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.21 Managing information security in the ICT supply chain
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: CSSAQ. Nonconformities recorded: A.5.21 Managing information security in the ICT supply chain is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.22 Monitoring, review and change management of supplier services
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 7.
Qualitative
Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI, CSSAQ. Nonconformities recorded: A.5.22 Monitoring, review and change management of supplier services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI, CSSAQ.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.23 Information security for use of cloud services
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.23 Information security for use of cloud services is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.24 Information security incident management planning and preparation
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: IMP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.24 Information security incident management planning and preparation is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.25 Assessment and decision on information security events
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: IMP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.25 Assessment and decision on information security events is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.26 Response to information security incidents
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: IMP, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.26 Response to information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.27 Learning from information security incidents
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 7.
Qualitative
Cited artefacts in this pack: IMP, CIL, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.27 Learning from information security incidents is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: CIL, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.28 Collection of evidence
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 7.
Qualitative
Cited artefacts in this pack: IMP, ELAI, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.5.28 Collection of evidence is named in this pack, but there is no effectiveness evidence. Cited policy: IMP. Cited implementation: ELAI, MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.29 Information security during disruption
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.29 Information security during disruption has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.30 ICT readiness for business continuity
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.30 ICT readiness for business continuity has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.31 Legal, statutory, regulatory and contractual requirements
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: LRR. Nonconformities recorded: A.5.31 Legal, statutory, regulatory and contractual requirements is named in this pack, but there is no effectiveness evidence. Cited implementation: LRR.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.32 Intellectual property rights
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.32 Intellectual property rights has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.33 Protection of records
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: RRS. Nonconformities recorded: A.5.33 Protection of records is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.34 Privacy and protection of PII
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.5.34 Privacy and protection of PII has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.35 Independent review of information security
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: IAP. Nonconformities recorded: A.5.35 Independent review of information security is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.36 Compliance with policies, rules and standards for information security
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: REQT. Nonconformities recorded: A.5.36 Compliance with policies, rules and standards for information security is named in this pack, but there is no effectiveness evidence. Cited implementation: REQT.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.5.37 Documented operating procedures
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 0.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: DOP. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.
