Implementation of Appropriate Security Measures, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 32(1).
Assessment Step
1
Implementation of Appropriate Security Measures (ImplementationofAppropriateSecurityMeasures)
Does the entity implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including (where applicable): pseudonymisation and encryption; ongoing confidentiality, integrity, availability, and resilience of systems; timely restoration of access and availability after incidents; and regular testing, assessment, and evaluation of the effectiveness of its security measures?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Implementation of Appropriate Security Measures
The data controller and the data processor must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, where appropriate: pseudonymisation and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; the ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of processing.
Citation
GDPR
Art. 32(1), Recital 83
|