Nonconformity register
Source: Arcfield EN Companion · Volume 1 audit. Assessment Results stay the kernel SSOT. This register cites them.
One register for this run. Nonconformities are major or minor. Observations stay observations — they are not relabelled as an NC. Requirement ↔ policy stays HITL. Kernel FAIL is Policy ↔ evidence, default minor. Requirement ↔ evidence is no policy and no implementation, or implementation without effectiveness evidence. 10.2 is the procedure, not the violated requirement. NC-RP and CAR stay journal citations, not a join. Not a certification statement.
Nonconformities
| ID | Title | Grade | Requirement | Topic |
|---|---|---|---|---|
| NC-A5-not-implemented | This pack cites neither a policy nor operating evidence. | minor | A.5.1 Policies for information security | a5 |
| NC-A5-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | A.5.10 Acceptable use of information and other associated assets | a5 |
| NC-A5-not-implemented-03 | This pack cites neither a policy nor operating evidence. | minor | A.5.11 Return of assets | a5 |
| NC-A5-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | A.5.13 Labelling of information | a5 |
| NC-A5-not-implemented-04 | This pack cites neither a policy nor operating evidence. | minor | A.5.14 Information transfer | a5 |
| NC-A5-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | A.5.15 Access control | a5 |
| NC-A5-not-implemented-05 | This pack cites neither a policy nor operating evidence. | minor | A.5.16 Identity management | a5 |
| NC-A5-not-implemented-06 | This pack cites neither a policy nor operating evidence. | minor | A.5.17 Authentication information | a5 |
| NC-A5-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | A.5.18 Access rights | a5 |
| NC-A5-missing-evidence-04 | Named evidence is present, but effectiveness is not shown. | minor | A.5.19 Information security in supplier relationships | a5 |
| NC-A5-not-implemented-07 | This pack cites neither a policy nor operating evidence. | minor | A.5.2 Information security roles and responsibilities | a5 |
| NC-A5-missing-evidence-05 | Named evidence is present, but effectiveness is not shown. | minor | A.5.20 Addressing information security within supplier agreements | a5 |
| NC-A5-missing-evidence-06 | Named evidence is present, but effectiveness is not shown. | minor | A.5.21 Managing information security in the ICT supply chain | a5 |
| NC-A5-missing-evidence-07 | Named evidence is present, but effectiveness is not shown. | minor | A.5.22 Monitoring, review and change management of supplier services | a5 |
| NC-A5-missing-evidence-08 | Named evidence is present, but effectiveness is not shown. | minor | A.5.23 Information security for use of cloud services | a5 |
| NC-A5-missing-evidence-09 | Named evidence is present, but effectiveness is not shown. | minor | A.5.24 Information security incident management planning and preparation | a5 |
| NC-A5-missing-evidence-10 | Named evidence is present, but effectiveness is not shown. | minor | A.5.25 Assessment and decision on information security events | a5 |
| NC-A5-missing-evidence-11 | Named evidence is present, but effectiveness is not shown. | minor | A.5.26 Response to information security incidents | a5 |
| NC-A5-missing-evidence-12 | Named evidence is present, but effectiveness is not shown. | minor | A.5.27 Learning from information security incidents | a5 |
| NC-A5-missing-evidence-13 | Named evidence is present, but effectiveness is not shown. | minor | A.5.28 Collection of evidence | a5 |
| NC-A5-not-implemented-08 | This pack cites neither a policy nor operating evidence. | minor | A.5.29 Information security during disruption | a5 |
| NC-A5-not-implemented-09 | This pack cites neither a policy nor operating evidence. | minor | A.5.3 Segregation of duties | a5 |
| NC-A5-not-implemented-10 | This pack cites neither a policy nor operating evidence. | minor | A.5.30 ICT readiness for business continuity | a5 |
| NC-A5-missing-evidence-14 | Named evidence is present, but effectiveness is not shown. | minor | A.5.31 Legal, statutory, regulatory and contractual requirements | a5 |
| NC-A5-not-implemented-11 | This pack cites neither a policy nor operating evidence. | minor | A.5.32 Intellectual property rights | a5 |
| NC-A5-missing-evidence-15 | Named evidence is present, but effectiveness is not shown. | minor | A.5.33 Protection of records | a5 |
| NC-A5-not-implemented-12 | This pack cites neither a policy nor operating evidence. | minor | A.5.34 Privacy and protection of PII | a5 |
| NC-A5-missing-evidence-16 | Named evidence is present, but effectiveness is not shown. | minor | A.5.35 Independent review of information security | a5 |
| NC-A5-missing-evidence-17 | Named evidence is present, but effectiveness is not shown. | minor | A.5.36 Compliance with policies, rules and standards for information security | a5 |
| NC-A5-not-implemented-13 | This pack cites neither a policy nor operating evidence. | minor | A.5.4 Management responsibilities | a5 |
| NC-A5-missing-evidence-18 | Named evidence is present, but effectiveness is not shown. | minor | A.5.5 Contact with authorities | a5 |
| NC-A5-not-implemented-14 | This pack cites neither a policy nor operating evidence. | minor | A.5.6 Contact with special interest groups | a5 |
| NC-A5-not-implemented-15 | This pack cites neither a policy nor operating evidence. | minor | A.5.7 Threat intelligence | a5 |
| NC-A5-not-implemented-16 | This pack cites neither a policy nor operating evidence. | minor | A.5.8 Information security in project management | a5 |
| NC-A5-missing-evidence-19 | Named evidence is present, but effectiveness is not shown. | minor | A.5.9 Inventory of information and other associated assets | a5 |
| NC-A6-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | A.6.1 Screening | a6 |
| NC-A6-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | A.6.2 Terms and conditions of employment | a6 |
| NC-A6-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | A.6.3 Information security awareness, education and training | a6 |
| NC-A6-not-implemented | This pack cites neither a policy nor operating evidence. | minor | A.6.4 Disciplinary process | a6 |
| NC-A6-missing-evidence-04 | Named evidence is present, but effectiveness is not shown. | minor | A.6.5 Responsibilities after termination or change of employment | a6 |
| NC-A6-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | A.6.6 Confidentiality or non-disclosure agreements | a6 |
| NC-A6-not-implemented-03 | This pack cites neither a policy nor operating evidence. | minor | A.6.7 Remote working | a6 |
| NC-A6-not-implemented-04 | This pack cites neither a policy nor operating evidence. | minor | A.6.8 Information security event reporting | a6 |
| NC-A8-not-implemented | This pack cites neither a policy nor operating evidence. | minor | A.8.1 User endpoint devices | a8 |
| NC-A8-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | A.8.10 Information deletion | a8 |
| NC-A8-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | A.8.11 Data masking | a8 |
| NC-A8-not-implemented-03 | This pack cites neither a policy nor operating evidence. | minor | A.8.12 Data leakage prevention | a8 |
| NC-A8-not-implemented-04 | This pack cites neither a policy nor operating evidence. | minor | A.8.13 Information backup | a8 |
| NC-A8-not-implemented-05 | This pack cites neither a policy nor operating evidence. | minor | A.8.14 Redundancy of information processing facilities | a8 |
| NC-A8-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | A.8.15 Logging | a8 |
| NC-A8-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | A.8.16 Monitoring activities | a8 |
| NC-A8-not-implemented-06 | This pack cites neither a policy nor operating evidence. | minor | A.8.17 Clock synchronization | a8 |
| NC-A8-not-implemented-07 | This pack cites neither a policy nor operating evidence. | minor | A.8.18 Use of privileged utility programs | a8 |
| NC-A8-not-implemented-08 | This pack cites neither a policy nor operating evidence. | minor | A.8.2 Privileged access rights | a8 |
| NC-A8-not-implemented-09 | This pack cites neither a policy nor operating evidence. | minor | A.8.20 Networks security | a8 |
| NC-A8-not-implemented-10 | This pack cites neither a policy nor operating evidence. | minor | A.8.21 Security of network services | a8 |
| NC-A8-not-implemented-11 | This pack cites neither a policy nor operating evidence. | minor | A.8.22 Segregation of networks | a8 |
| NC-A8-not-implemented-12 | This pack cites neither a policy nor operating evidence. | minor | A.8.23 Web filtering | a8 |
| NC-A8-not-implemented-13 | This pack cites neither a policy nor operating evidence. | minor | A.8.24 Use of cryptography | a8 |
| NC-A8-not-implemented-14 | This pack cites neither a policy nor operating evidence. | minor | A.8.25 Secure development life cycle | a8 |
| NC-A8-not-implemented-15 | This pack cites neither a policy nor operating evidence. | minor | A.8.26 Application security requirements | a8 |
| NC-A8-not-implemented-16 | This pack cites neither a policy nor operating evidence. | minor | A.8.27 Secure system architecture and engineering principles | a8 |
| NC-A8-not-implemented-17 | This pack cites neither a policy nor operating evidence. | minor | A.8.28 Secure coding | a8 |
| NC-A8-not-implemented-18 | This pack cites neither a policy nor operating evidence. | minor | A.8.29 Security testing in development and acceptance | a8 |
| NC-A8-missing-evidence-04 | Named evidence is present, but effectiveness is not shown. | minor | A.8.3 Information access restriction | a8 |
| NC-A8-not-implemented-19 | This pack cites neither a policy nor operating evidence. | minor | A.8.31 Separation of development, test and production environments | a8 |
| NC-A8-not-implemented-20 | This pack cites neither a policy nor operating evidence. | minor | A.8.32 Change management | a8 |
| NC-A8-not-implemented-21 | This pack cites neither a policy nor operating evidence. | minor | A.8.33 Test information | a8 |
| NC-A8-missing-evidence-05 | Named evidence is present, but effectiveness is not shown. | minor | A.8.34 Protection of information systems during audit testing | a8 |
| NC-A8-not-implemented-22 | This pack cites neither a policy nor operating evidence. | minor | A.8.4 Access to source code | a8 |
| NC-A8-not-implemented-23 | This pack cites neither a policy nor operating evidence. | minor | A.8.5 Secure authentication | a8 |
| NC-A8-not-implemented-24 | This pack cites neither a policy nor operating evidence. | minor | A.8.6 Capacity management | a8 |
| NC-A8-not-implemented-25 | This pack cites neither a policy nor operating evidence. | minor | A.8.7 Protection against malware | a8 |
| NC-A8-not-implemented-26 | This pack cites neither a policy nor operating evidence. | minor | A.8.8 Management of technical vulnerabilities | a8 |
| NC-A8-missing-evidence-06 | Named evidence is present, but effectiveness is not shown. | minor | A.8.9 Configuration management | a8 |
| NC-ASSETS-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 7.5 Documented information | assets |
| NC-ASSETS-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | A.5.10 Acceptable use of information and other associated assets | assets |
| NC-ASSETS-not-implemented-03 | This pack cites neither a policy nor operating evidence. | minor | A.5.11 Return of assets | assets |
| NC-ASSETS-not-implemented-04 | This pack cites neither a policy nor operating evidence. | minor | A.5.32 Intellectual property rights | assets |
| NC-ASSETS-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | A.5.9 Inventory of information and other associated assets | assets |
| NC-ASSETS-not-implemented-05 | This pack cites neither a policy nor operating evidence. | minor | A.8.8 Management of technical vulnerabilities | assets |
| NC-C10-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 10.1 Continual improvement | c10 |
| NC-C10-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 10.2 Nonconformity and corrective action | c10 |
| NC-C4-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 4.1 Understanding the organization and its context | c4 |
| NC-C4-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | 4.2 Understanding the needs and expectations of interested parties | c4 |
| NC-C4-not-implemented-03 | This pack cites neither a policy nor operating evidence. | minor | 4.3 Determining the scope of the ISMS | c4 |
| NC-C4-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 4.4 Information security management system | c4 |
| NC-C5-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 5.1 Leadership and commitment | c5 |
| NC-C5-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 5.2 Information security policy | c5 |
| NC-C5-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | 5.3 Organizational roles, responsibilities and authorities | c5 |
| NC-C6-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 6.1.1 Actions to address risks and opportunities | c6 |
| NC-C6-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 6.1.2 Information security risk assessment | c6 |
| NC-C6-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | 6.1.3 Information security risk treatment | c6 |
| NC-C6-missing-evidence-04 | Named evidence is present, but effectiveness is not shown. | minor | 6.2 Information security objectives and planning to achieve them | c6 |
| NC-C6-missing-evidence-05 | Named evidence is present, but effectiveness is not shown. | minor | 6.3 Planning of changes | c6 |
| NC-C7-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 7.1 Resources | c7 |
| NC-C7-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 7.2 Competence | c7 |
| NC-C7-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | 7.4 Communication | c7 |
| NC-C7-missing-evidence-04 | Named evidence is present, but effectiveness is not shown. | minor | 7.5 Documented information | c7 |
| NC-C8-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 8.1 Operational planning and control | c8 |
| NC-C8-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 8.2 Information security risk assessment | c8 |
| NC-C8-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | 8.3 Information security risk treatment | c8 |
| NC-C9-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 9.1 Monitoring, measurement, analysis and evaluation | c9 |
| NC-C9-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 9.2 Internal audit | c9 |
| NC-C9-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | 9.3 Management review | c9 |
| NC-CERTIFICATION-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 9.2 Internal audit | certification |
| NC-CERTIFICATION-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | A.5.35 Independent review of information security | certification |
| NC-CERTIFICATION-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | A.8.34 Protection of information systems during audit testing | certification |
| NC-DOCUMENTED-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 7.5 Documented information | documented |
| NC-FOUNDATION-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 4.2 Understanding the needs and expectations of interested parties | foundation |
| NC-FOUNDATION-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | 5.1 Leadership and commitment | foundation |
| NC-FOUNDATION-not-implemented-03 | This pack cites neither a policy nor operating evidence. | minor | 5.2 Information security policy | foundation |
| NC-FOUNDATION-not-implemented-04 | This pack cites neither a policy nor operating evidence. | minor | 7.4 Communication | foundation |
| NC-FOUNDATION-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 7.5 Documented information | foundation |
| NC-FOUNDATION-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 9.3 Management review | foundation |
| NC-HR-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 7.5 Documented information | hr |
| NC-HR-not-implemented-02 | This pack cites neither a policy nor operating evidence. | minor | A.6.4 Disciplinary process | hr |
| NC-IDENTITY-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 7.5 Documented information | identity |
| NC-IDENTITY-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 8.1 Operational planning and control | identity |
| NC-IMPLEMENTATION-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 4.4 Information security management system | implementation |
| NC-IMPLEMENTATION-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 6.2 Information security objectives and planning to achieve them | implementation |
| NC-IMPLEMENTATION-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | 9.1 Monitoring, measurement, analysis and evaluation | implementation |
| NC-IMPROVEMENT-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 10.1 Continual improvement | improvement |
| NC-IMPROVEMENT-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 7.5 Documented information | improvement |
| NC-IMPROVEMENT-not-implemented | This pack cites neither a policy nor operating evidence. | minor | 8.1 Operational planning and control | improvement |
| NC-RISK-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | 7.5 Documented information | risk |
| NC-RISK-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | 8.1 Operational planning and control | risk |
| NC-SUPPLIER-missing-evidence | Named evidence is present, but effectiveness is not shown. | minor | A.5.19 Information security in supplier relationships | supplier |
| NC-SUPPLIER-missing-evidence-02 | Named evidence is present, but effectiveness is not shown. | minor | A.5.20 Addressing information security within supplier agreements | supplier |
| NC-SUPPLIER-missing-evidence-03 | Named evidence is present, but effectiveness is not shown. | minor | A.5.21 Managing information security in the ICT supply chain | supplier |
| NC-SUPPLIER-missing-evidence-04 | Named evidence is present, but effectiveness is not shown. | minor | A.5.22 Monitoring, review and change management of supplier services | supplier |
| NC-SUPPLIER-not-implemented | This pack cites neither a policy nor operating evidence. | minor | A.5.23 Information security for use of cloud services | supplier |
Observations
No observation in this pack.
