Implementation of Appropriate Security Measures, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 32(1).

Assessment Step

1
Implementation of Appropriate Security Measures (ImplementationofAppropriateSecurityMeasures)
Does the entity implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including (where applicable): pseudonymisation and encryption; ongoing confidentiality, integrity, availability, and resilience of systems; timely restoration of access and availability after incidents; and regular testing, assessment, and evaluation of the effectiveness of its security measures?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Implementation of Appropriate Security Measures
The data controller and the data processor must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, where appropriate: pseudonymisation and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; the ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of processing.
Citation
GDPR
Art. 32(1), Recital 83