lagen.nu
Technical Guidelines for the implementation of minimum security measures for Digital Service Providers

Technical Guidelines for the implementation of minimum security measures for Digital Service Providers

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2017-02-16
Språk
engelska
Ämnesord
Cybersecurity of Critical Sectors
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

Technical Guidelines for the implementation of minimum security measures for Digital Service Providers DECEMBER, 2016 www.enisa.europa.eu European Union Agency For Network And Information Security

About ENISA

The European Union Agency for Network and Information Security (ENISA) is a centre of network and information security expertise for the EU, its member states, the private sector and Europe’s citizens. ENISA works with these groups to develop advice and recommendations on good practice in information security. It assists EU member states in implementing relevant EU legislation and works to improve the resilience of Europe’s critical information infrastructure and networks. ENISA seeks to enhance existing expertise in EU member states by supporting the development of cross-border communities committed to improving network and information security throughout the EU. More information about ENISA and its work can be found at www.enisa.europa.eu.

Contact

For contacting the authors please use resilience@enisa.europa.eu For media enquires about this paper, please use press@enisa.europa.eu.

Acknowledgements

Special thank the experts of the ENISA Cloud Security and Resilience expert group, BSI, ANSSI, Microsoft, Google, VMWare, Palo Alto Networks and cyber security experts from the EU Member States, who provided useful comments and feedback on earlier drafts of this document: https://resilience.enisa.europa.eu/cloud-security-and-resilience

Legal notice

Notice must be taken that this publication represents the views and interpretations of ENISA, unless stated otherwise. This publication should not be construed to be a legal action of ENISA or the ENISA bodies unless adopted pursuant to the Regulation (EU) No 526/2013. This publication does not necessarily represent state-of the-art and ENISA may update it from time to time.

Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication.

This publication is intended for information purposes only. It must be accessible free of charge. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication.

Copyright Notice

© European Union Agency for Network and Information Security (ENISA), 2016 Reproduction is authorised provided the source is acknowledged.

ISBN 978-92-9204-203-5, doi 10.2824/456345

Table of Contents

Executive Summary 6

1. Introduction 7

Background 7

1.1.1 General introduction 7 1.1.2 Objectives 7 1.1.3 Scope & Target Audience 7 1.1.4 Document overview 8 1.1.5 Methodology 9

2. List of security objectives and measures for DSPs 11

Description 11

The role of risk assessment 12

SO 01 - Information security policy 12

Description 12 Security measures within sophistication levels 13 Mapping 14

SO 02 – Risk Management 14

Description 14 Security measures in sophistication levels 14 Mapping 15

SO 03 – Security Roles 15

Description 15 Security measures within sophistication levels 16 Mapping 17

SO 04 – Third party management 17

Description 17 Security measures within sophistication levels 17 Mapping 19

SO 05 – Background checks 19

Description 19 Security measures within sophistication levels 19 Mapping 20

SO 06 – Security knowledge and training 20

Description 20 Security measures within sophistication levels 20 Mapping 22

SO 07 – Personnel changes 22

Description 22 Security measures within sophistication levels 22

Mapping 23

SO 08 – Physical and environmental security 23

Description 23 Security measures within sophistication levels 23 Mapping 25

SO 09 – Security of supporting utilities 26

Description 26 Security measures within sophistication levels 26 Mapping 26

SO 10 – Access control to network and information systems 27

Description 27 Security measures within sophistication levels 27 Mapping 28

SO 11 – Integrity of network components and information systems 29

Description 29 Security measures within sophistication levels 29 Mapping 30

SO 12 – Operating procedures 30

Description 30 Security measures within sophistication levels 30 Mapping 31

SO 13 – Change management 31

Description 31 Security measures within sophistication levels 31 Mapping 32

SO 14 – Asset management 32

Description 32 Security measures within sophistication levels 32 Mapping 34

SO 15 – Security incident detection & Response 34

Description 34 Security measures within sophistication levels 34 Mapping 36

SO 16 – Security incident reporting 36

Description 36 Security measures within sophistication levels 36 Mapping 37

SO 17 – Business continuity 37

Description 37 Security measures within sophistication levels 37 Mapping 39

SO 18 – Disaster recovery capabilities 39

Description 39 Security measures within sophistication levels 39 Mapping 40

SO 19 – Monitoring and logging 40

Description 40 Security measures within sophistication levels 40 Mapping 41

SO 20 – System tests 41

Description 41 Security measures within sophistication levels 42 Mapping 43

SO 21 – Security assessments 43

Description 43 Security measures within sophistication levels 43 Mapping 44

SO 22 – Compliance 44

Description 44 Security measures within sophistication levels 44 Mapping 45

SO 23 – Security of data at rest 46

Description 46 Security measures within sophistication levels 46 Mapping 48

SO 24 –Interface security 48

Description 48 Security measures within sophistication levels 49 Mapping 50

SO 25 –Software security 50

Description 50 Security measures within sophistication levels 50 Mapping 51

SO 26 – Interoperability and portability 51

Description 51 Security measures within sophistication levels 52 Mapping 52

SO 27 – Customer Monitoring and log access 52

Description 52 Security measures within sophistication levels 52 Mapping 53

3. Summary 54

Executive Summary

Online marketplaces, online search engines and cloud computing services are considered as Digital Service Providers (DSPs) in the context of the recently adopted Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union, hereafter referred to as the Network and Information Security (NIS) Directive.

The NIS Directive aims to bring cybersecurity capabilities on the same level of development in all the EU Member States. Its purpose is to ensure that exchange of information and cooperation related to security amongst Member States are efficient, including at the cross-border level . With NIS becoming a requirement, the introduction of specific laws in this area across the European Union will have a significant impact to all industry sectors including those relating to DSP categories.

Many businesses in the Union rely on these DSPs for the provision of their services. Some digital services could be an important resource for their users, including Operators of Essential Services (OES), and as such users might not always have alternatives available. The security, continuity and reliability of the type of digital services referred to in this Directive are of the essence for the smooth functioning of many businesses. A disruption of such a digital service could prevent the provision of other services which depend on it and could consequently have an impact on key economic and societal activities in the Union. Such digital services might therefore be critical for the smooth functioning of businesses that depend on them, for the internal market and cross- border trade across the Union .

It is essential for all Member States to make sure that they have minimum capabilities to ensure a high level of NIS in their territory and to improve the functioning of the internal market. Commonly defined security measures can support harmonised security practices across EU Member States and potentially enhance the overall level of NIS in the EU.

Therefore, ENISA has issued this report to assist Member States and DSPs in providing a common approach regarding the security measures for DSPs. Although ENISA has already drafted a set of security objectives in the context of cloud security in 2014 , this study goes further than that by broadening the scope of its work and by including security objectives for all three categories of digital service providers. This study lists 27 Security Objectives (SOs) for DSPs. In those 27 SOs, security measures that map to the NIS Directive requirements are also included.

This particular initiative has been achieved by examining current information and network security practices for the DSPs across the EU. It has brought light to some important findings that can add to existing security objectives and measures in information technology infrastructures in Europe. It is recommended that stakeholders and responsible parties analyse their information security needs in detail in order to evaluate and adapt each of the security objectives and measures according to their specific business requirements.

1. Introduction

Background 1.1.1 General introduction

The world is becoming increasingly interconnected as industries continue to revolutionize and knowledge continues to be shared. With the advent of digital services, network and information systems and services are becoming highly crucial to the society. Thus, it is imperative that their security and reliability is significantly ensured.

In fact, if security and resilience of networks and information systems are not ensured, this can impede the pursuit of economic activities, lead to financial losses, undermine the confidence or cause major damage to the economy of a country. For example, network and information systems, and primarily the Internet, play an essential role in facilitating the cross–border movement of goods, services and people. Substantial disruptions of those systems, whether intentional or unintentional and regardless of where they occur, can affect individual Member States and the Union as a whole. Knowing how to properly address network and information security is key to avoid any damaging effects.

DSPs operate in a fast changing environment and should ensure a level of security proportionate to the degree of risk posed to the digital services they provide. Responsibilities in ensuring the security of network and information systems lie to a great extent with DSPs themselves. A culture of risk management, involving risk assessment and the implementation of security measures appropriate to the risks faced, should be promoted and developed through appropriate regulatory requirements, standards and commonly acceptable industry practices.

1.1.2 Objectives

The objectives of this report are to:

 Define common baseline security objectives for Digital Service Providers (DSPs).  Describe different levels of sophistication in the implementation of security objectives.  Map the security objectives against well-known industry standards, national frameworks and certification schemes.

1.1.3 Scope & Target Audience

This study analyses the security objectives by providing security measures and examples of implementation concerning the digital service providers and in particular:

 Cloud computing service providers  Online marketplaces  Online search engines

The three DSP categories are described in the NIS Directive as follows:

 Online marketplaces:

An online marketplace allows consumers and/or traders to conclude online sales and service contracts with traders, and is the final destination for the conclusion of those contracts. It does not

cover online services that serve only as an intermediary to third-party services where a contract can ultimately be concluded. It therefore does not cover online services that compare the price of particular products or services from different traders, and then redirect the user to the preferred trader to purchase the product. Computing services provided by the online marketplace may include processing of transactions, aggregations of data or profiling of users. Application stores, which operate as online stores enabling the digital distribution of applications or software programmes from third parties, are to be understood as being a type of online marketplace  Online search engines:

An online search engine should allow the user to perform searches of in principle all websites on the basis of a query on any subject. It may alternatively be focused on websites in a particular language. The definition of an online search engine provided in this Directive should not cover search functions that are limited to the content of a specific website, irrespective of whether the search function is provided by an external search engine. It should also not cover online services that compare the price of particular products or services from different traders, and then redirect the user to the preferred trader to purchase the product.  Cloud computing service providers:

Cloud computing services span a wide range of activities that can be delivered according to different models. For the purposes of this report, "cloud computing services" means services that enable access to a scalable and elastic pool of shareable computing resources. The term "computing resources" covers resources such as networks, servers or other infrastructure, storage, applications and services. "Scalable" means that, in order to handle fluctuations in demand, computing resources are flexibly allocated by the cloud service provider irrespective of the geographical location of the resources.

Privacy is of outmost importance for the personal data being processed by DSPs but it is considered out of scope for this particular report. This is because, there is a good deal of data protection requirements (i.e. consent of the data subject, the purpose definition, proportionality of collected data etc.) and tools (i.e. privacy by design, privacy impact assessment, privacy seals, notifications of the processing to and audits by the national Data Protection Authorities (DPAs) and data breach notifications) which are examined under a very specific piece of EU Regulation, the General Data Protection Regulation (GDPR). The identification of the entire set of organisational and technical measures which are deemed adequate to GDPR is a subject for thorough analysis which exceeds the boundaries of the current undertaking. For this reason, this report focuses only on the objectives which are solely considered most relevant to the security element of the information systems and data maintained by the DSPs. However, some security measures described herein i.e. encryption, secure disposal of data, media access policy etc. are extensively used to address data protection requirements as well.

1.1.4 Document overview

The report lists and describes the high-level security objectives for the DSP categories together with the different sophistication levels in the implementation of security measures. For each sophistication level (basic, industry-standard and state of the art), the corresponding measures and examples are provided.

The report also provides a mapping between security objectives, industry standards, certification schemes and national frameworks. The goal of the mapping is to allow DSP communities to understand more easily if their NIS requirements and security objectives meet the requirements of those frameworks.

1.1.5 Methodology

This study is based on the Cloud Certification Schemes Meta framework (CCSM) released in November 2014 by ENISA, regarding cloud service providers. This tool is a meta-framework that provides a neutral high-level mapping from the customer's Network and Information Security requirements to security objectives in existing cloud certification schemes.

Additional security objectives concerning cloud services that may have come into play since 2014 have also been examined. The list of objectives has been validated with the ENISA Cloud Expert Group through extra consultation and a validation workshop.

A questionnaire was developed and a publicly available online survey was launched in order to identify several security controls and measures implemented, along with good practices and standards deployed by DSP and in particular online market places and online search engines.

The diagram below illustrates the relationship between security requirements, security objectives and security measures which are key terminologies that have been used throughout the document. Further to this,

examples of these terminologies are also described below.

 Security requirement: Customers have security requirements. In the procurement phase customers usually check which security requirements are met by the security objectives of the provider. This process is often referred to as due-diligence.  Security objectives: Providers have security objectives. Objectives are high-level goals and usually do not include many technical details. For example, “we offer an uptime of 99.9%”, or “customer data cannot be accessed by unauthorized personnel”. Security objectives are sometimes grouped in “security domains” (e.g. “software security”). Security objectives are sometimes called “control objectives”).  Security measures: Providers have security measures in place, to reach the security objectives. Security measures are sometimes called “controls” or “security controls”-.

The report also provides a mapping between security objectives and the following industry standards, certification schemes and national frameworks:

 ISO/IEC 27001:2013  CSA CCM: Cloud Controls Matrix v3.0.1  BSI C5: Cloud Computing Compliance Controls Catalogue (C5), criteria to assess the information security of cloud services, version 1.0 – as of February 2016  COBIT5: Framework for the governance and management of enterprise IT  CCS CSC: The CIS Critical Security Controls for Effective Cyber Defence, Version 6.1, August 31, 2016  OCF: CSA STAR PROGRAM & OPEN CERTIFICATION FRAMEWORK IN 2016 AND BEYOND  NIST: Framework for Improving Critical Infrastructure Cybersecurity, Version 1.0, National Institute

of Standards and Technology, February 12, 2014

 PCI DSS: Payment Card Industry (PCI) Security Standards Council, Data Security Standard Requirements and Security Assessment Procedures, Version 3.2, April 2016  CES: Cyber Essentials Scheme, Requirements for basic technical protection from cyber attacks, June 2014

2. List of security objectives and measures for DSPs

Description

For each security objective we provide:

 Brief description of the security objective.  Levels of sophistication on the implementation of security measures with examples.  A mapping with industry standards, certification schemes and national frameworks

The list below, categorizes security measures into three sophistication levels. Each level contains the practices to assess the adequacy of the design and evidence that should be provided in order to check the effective implementation of the security practice. For each security objective, we have provided security measures that are either basic, industry-standard or state of the art. Readers can refer to the table below for the definition of each of these sophistication levels and can also refer to the list below for an overview of the security levels of each objective.

Sophistication levels are applied independently to each objective. As a result, a DSP may receive different sophistication ratings for different objectives. It is important to realise that the sophistication levels that are applicable to a given organisation depend on its specific characteristics such as its size or the services provided. For example, for a provider with only 5 employees it may be unnecessary to have a security policy that is fully aligned with best practice industry standards, or to have a documented formal procedure for hiring personnel.

The practices that complete each sophistication level are selected from relevant standards, guidelines and frameworks which have been identified during the stock taking exercise and described in the section 1.1.5.

The role of risk assessment

DSPs wishing to establish, implement, operate, monitor and continuously maintain and improve an appropriate level of security, must also carefully and continuously consider and assess the actual level of preparedness and the related security risks they face.

A risk assessment should be performed throughout the system life cycle: during requirements definition, procurement, control definition and configuration, system operations, and system close-out.

A “Risk Assessment” (RA) would be, in this context, an important step to be performed before deciding the required sophistication levels needed by the DSP. The extent and granularity of the Risk Assessment should take into account several factors such as the size of the organisation, the implementation cost of the measures etc.

The risk assessment allows the DSP to define a threshold for the minimum acceptance level before the establishment of a risk value and to perform the risk assessment for the assets in scope. Therefore, a risk assessment is a key preliminary step that should be conducted in order to understand what risk level is appropriate/acceptable for each organisation before deciding upon the required sophistication levels needed by DSPs.

The organisation should select specific controls, measures and sophistication levels by considering and effectively using the results of the risk assessment. This way, the proposed security measures could be considered as an appropriate benchmark enabling the security managers to determine which specific aspects of security require attention and priority within their respective organisations.

Establishing a security benchmark within a context that has been defined by DSP security experts is considered to be a successful formula, because such a benchmark can be properly focused on DSP specific security issues. Such benchmark can complement the outcome of the risk assessment and provide an additional input for defining and selecting the specific controls, measures and sophistication levels for the security of the services offered by the DSPs.

The above-described proposed approach is aligned with general risk management good practices – and therefore will help create synergies between the risk management and the security efforts of the DSP. In contrast with a compliance based approach, this approach is considered to be more pragmatic and efficient. Moreover, the proposed approach is considered to be more powerful because it takes into consideration the specific characteristics of DSPs. Therefore, it can be applied to a wide range of DSPs independently of their size or maturity.

The use of sophistication levels allows the definition of different quality requirements for each measure. This approach is different from a maturity level approach because, in practice, an organisation will probably not have all its measures developed to the same level of maturity.

The identification of a suitable risk assessment methodology for DSPs is beyond the scope of this report; therefore, it has not been described in detail. Only the relevance and usefulness of performing a suitable risk assessment, before deciding the required sophistication levels, was highlighted (SO 02: Risk Management).

SO 01 - Information security policy Description

The DSP establishes and maintains an information security policy. The document details information on main assets and processes, strategic security objectives.

Security measures within sophistication levels

1

2

3

Mapping

ISO27001: A.5 Information Security policies CSA CCM: (GRM-01, GRM-03, GRM-04, GRM-05, GRM-06, GRM-

07, GRM-08, GRM-09)

CSA CCM: (GRM-01, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09) Governance and Risk

Management

BSI C5: OIS-01, OIS-01H, OIS-02, SA-01, SPN-02, SPN-03

CCS: 5.15 Configuration Management, 5.16 Data Management, 6.1 Location of Data and Data Centers, 6.2

Compliance Management, 6.3 Policy Management, 6.4 Audit Management, 6.12 Security Management

OCF: (GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11)

Governance and Risk Management

NIST: ID.GV-1: Organizational information security policy is established

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.1 &

12.1.1

SO 02 – Risk Management Description

The DSP establishes and maintains an appropriate governance and risk management framework, to identify and address risks for the security of the offered services. Risks management procedures can include (but are not limited to), maintaining a list of risks and assets, using Governance Risk management and Compliance (GRC) tools and Risk Assessment (RA) tools etc.

Security measures in sophistication levels Mapping

ISO27001: ISO27001:2013 (all)

CSA CCM: CSA CCM (GRM-02, GRM-04, GRM-08, GRM-10, GRM-11, STA-01, STA-04, STA-04, STA-05, STA-06) Governance and Risk Management, Supply Chain Management, Transparency and Accountability

BSI C5: OIS-06, OIS-07, OIS-07H, OIS-03H, SA-01, SA-03, BEI-04, SPN-02, SPN-03

CCS: CCS, 6.2 Compliance Management, 6.3 Policy Management, 6.11 Risk Management, 6.12 Security Man-

agement

OCF: OFC, (GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10,

GRM-11) Governance and Risk Management, (STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA- 08, STA-09) Supply Chain Management, Transparency and Accountability

NIST: ID.BE-2: The organization’s place in critical infrastructure and its industry sector is identified and commu-

nicated

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.2

SO 03 – Security Roles Description

The DSP assigns appropriate security roles and security responsibilities to designated personnel. (i.e. CSO, CISO, CTO etc.) .

Security measures within sophistication levels

1

Mapping

ISO27001: A.6.1 Internal organization

CSA CCM: (BCR-10, CCC-01, DSI-06, GRM-06, HRS-03, HRS-07, IAM-02, IAM-05, IAM-09, IAM-10, SEF-01, SEF-

02, SEF-03) Business Continuity Management & Operational Resilience, Change Control & Configuration Management, Data Security & Information Lifecycle Management, Governance and Risk Management, Identity & Access Management, Security Incident Management, E-Discovery & Cloud Forensics

BSI C5: OIS-02, OIS-03, OIS-04, SA-01, BCM-01

CCS: 5.13 User Management and Authentication, 6.5 Data Protection, 6.10 Employee Management

OCF: OCF, (BCR-01, BCR-02, BCR-03,BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11) Busi-

ness Continuity Management & Operational Resilience, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS- 06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human Resources, IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11,IAM-12,IAM-13 Identity & Access Management, SEF-01, SEF-02, SEF-03, SEF-04, SEF-05 Security Incident Management, E-Discovery & Cloud Forensics

NIST: ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders

(e.g., suppliers, customers, partners) are established

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.4

SO 04 – Third party management Description

The DSP establishes and maintains a policy with security requirements for contracts with suppliers and customers. SLAs, security requirements in contracts, outsourcing agreements etc., are established to ensure that the dependencies on suppliers and residual risks do not negatively affect security of the offered services.

Security measures within sophistication levels Mapping

ISO27001: A.15.1 Information security in supplier relationships

CSA CCM: (CCC-02, STA-01, STA-02, STA-03, STA-04, STA-05, STA-05, STA-06, STA-07, STA-08, STA-09) Change

Control & Configuration Management and Supply Chain Management, Transparency & Accountability

BSI C5: HR-03H, DLL-01, DLL-02, UP-01, BEI-02

CCS: 6.6 Terms and Conditions of Use, 6.8 Contract Management, 6.13 Embedding External Services, 7.7 Ser-

vice Level Management

OCF: OFC, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, STA-01,

STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability

NIST: PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand roles & responsibili-

ties

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.8.3

SO 05 – Background checks Description

The DSP performs appropriate background checks on personnel (employees, contractors and third party users) before hiring, if required, for their duties and responsibilities provided that this is allowed by the local regulatory framework. Background checks may include checking past jobs, checking professional references, etc.

Security measures within sophistication levels

1

Mapping

ISO27001: A.7.1 Human resource security - Prior to employment

CSA CCM: CSA CCM, (HRS-02) Human Resources

BSI C5: HR-01

CCS: 5.11 System Administration and Management, 5.13 User Management and Authentication, 6.10 Em-

ployee Management

OCF: OFC, HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human

Resources

NIST: PR. IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screen-

ing)

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.7

SO 06 – Security knowledge and training Description

The DSP verifies and ensures that personnel have sufficient security knowledge and that they are provided with regular security training. This is achieved through for example, security awareness raising, security education, security training etc.

Security measures within sophistication levels

2

3

Mapping

ISO27001: A.7.2.2, A.6.1.1, A.7.2.2

CSA CCM: CCS CCM (HRS-08, HRS-09) Human Resources

BSI C5: HR-02, HR-03, SA-01

COBIT5: COBIT 5 APO07.03, BAI05.07, COBIT 5 APO07.02, DSS06.03, COBIT 5 APO07.03, APO10.04, APO10.05,

COBIT 5 APO07.03

CCS: CCS, 5.11 System Administration and Management, 5.13 User Management and Authentication, 6.10 Em-

ployee Management

OCF: OCF, BCR-01, BCR-02, BCR-03, BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11 Business

Continuity Management & Operational Resilience, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human Resources, SEF-01, SEF-02, SEF-03, SEF-04, SEF-05

NIST: PR.AT-1: All users are informed and trained

PCI-DSS: Requirement 6 - Develop and maintain secure systems and applications: 6.5, Requirement 9: Restrict

physical access to cardholder data: 9.9, 9.9.3, Requirement 12: Maintain a policy that addresses information security for all personnel:12.6.1, 12.10.4, A3.1 - Implement a PCI DSS compliance program: A3.1.4

SO 07 – Personnel changes Description

The DSP establishes and maintains an appropriate process for managing changes in personnel or changes in their roles and responsibilities.

Security measures within sophistication levels Mapping

ISO27001: A.7.3.1

CSA CCM: CSA CCM, (HRS-04) Human Resources

BSI C5: HR-02, HR-05

CCS: 5.11 System Administration and Management, 5.13 User Management and Authentication, 6.10 Em-

ployee Management

OCF: HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human Re-

sources

NIST: PR. IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screen-

ing

PCI-DSS: A3.2- Document and validate PCI DSS scope: A3.2.3

SO 08 – Physical and environmental security Description

The DSP establishes and maintains policies and measures for physical and environmental security of datacenters such as physical access controls, alarm systems, environmental controls and automated fire extinguishers etc.

Security measures within sophistication levels

2

Mapping

ISO27001: A.11

CSA CCM: CSA CCM (DCS-01, DCS-02, DCS-03, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09, DCS-

10, DCS-11) - Datacenter security

BSI C5: PS-01, PS-02, PS-03, PS-04, PS-05, BCM-05

CCS: 5.17 Physical Security

OCF: OCF, DCS-01, DCS-02, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09 Datacenter Security,

HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human Resources

NIST: ID.AM-1: Physical devices and systems within the organization are inventoried, PR.AC-2: Physical access

to assets is managed and, PR.AT-5: Physical and information security personnel understand roles & responsibilities, PR.IP-5: Policy and regulations regarding the physical operating environment for organizational assets are met, PR.IP-5: Policy and regulations regarding the physical operating environment for organizational assets are met

PCI-DSS: Requirement 8 - Identify and authenticate access to system components: 8.6, Requirement 9 - Re-

strict physical access to cardholder data: all

SO 09 – Security of supporting utilities Description

The DSP establishes and maintains appropriate security measures to ensure the security of supporting utilities such as electricity, fuel, HVAC etc. For example, this may be through the protection of power grid connections, diesel generators, fuel supplies, etc.

Security measures within sophistication levels

1

Mapping

ISO27001: ISO/IEC/27001 A.11.2.2

BSI C5: PS-04, BCM-05

CCS: 5.17 Physical Security

OCF: BCR-01, BCR-02, BCR-03,BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11 Business Con-

tinuity Management & Operational Resilience, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, DCS-01, DCS-02, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09 Datacenter Security, HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS- 10, HRS-11 Human Resources, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS- 11,IVS-12,IVS-13 Infrastructure & Virtualization Security

SO 10 – Access control to network and information systems Description

The DSP established and maintains appropriate policies and measures for access to business resources. For example, zero trust model, ID management, authentication of users, access control systems, firewall and network security etc.

Security measures within sophistication levels

1

2

3

Mapping

ISO27001: ISO/IEC 27001:2013 A.9.2.1, A.9.2.2, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, ISO/IEC 27001:2013 A.11.1.1,

A.11.1.2, A.11.1.4, A.11.1.6, A.11.2.3, ISO/IEC 27001:2013 A.6.2.2, A.13.1.1, A.13.2.1, ISO/IEC 27001:2013 A.6.1.2, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, ISO/IEC 27001:2013 A.13.1.1, A.13.1.3, A.13.2.1

CSA CCM: CCA CCM (EKM-01, EKM-02, EKM-03, EKM-04) Encryption & key management

BSI C5: IDM-01, IDM-02, IDM-03, IDM-04, IDM-05, IDM-06, IDM-07, IDM-08, IDM-09, IDM-10, IDM-11, IDM-12,

KOS-01, KOS-02, KOS-03, KOS-04, KOS-05, KOS-06, KOS-07, KOS-08 COBIT 5: COBIT 5 DSS05.04, DSS06.03, COBIT 5 DSS01.04, DSS05.05, COBIT 5 APO13.01, DSS01.04, DSS05.03

CCS: CCS, 5.3 Client Separation, 5.4 Security Architecture, 5.6 Network Segmentation, 5.7 Network Architec-

ture, 5.11 System Administration and Management, 5.13 User Management and Authentication, 6.5 Data Protection

OCF: OCF, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, DSI-01, DSI-

02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, EKM-01, EKM- 02, EKM-03, EKM-04 Encryption & Key Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human Resources, IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11,IAM-12,IAM-13 Identity & Access Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability

NIST: PR.AC-5: Network integrity is protected, incorporating network segregation where appropriate

PCI-DSS: Requirement 1: Install and maintain a firewall configuration to protect cardholder data: all Require-

ment 2: Do not use vendor-supplied defaults for system passwords and other security parameters: all

SO 11 – Integrity of network components and information systems Description

The DSP establishes, protects, and maintains the integrity of its own network, platforms and services by taking steps to prevent successful security incidents. The goal is the protection from viruses, code injections and other malware that can alter the functionality of the systems or integrity or accessibility of information.

Security measures within sophistication levels Mapping

ISO27001: A.13.1

BSI C5: RB-05, RB-17, RB-18, RB-23, IDM-08, IDM-11, KOS-02, KOS-03, KOS-05, BEI-01

CCS: 5.4 Security Architecture, 5.5 Encryption, 5.6 Network Segmentation, 5.7 Network Architecture, 6.5 Data

Protection

OCF: CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, DSI-01, DSI-02,

DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, EKM-01, EKM-02, EKM-03, EKM-04 Encryption & Key Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11,IAM-12,IAM-13 Identity & Access Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability, MOS- 01,MOS-02,MOS-03,MOS-04,MOS-05,MOS-06,MOS-07,MOS-08,MOS-09,MOS-10,MOS-11,MOS-12,MOS-13 to MOS-20 Mobile Security, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability, TVM-01, TVM-02, TVM-03 Threat and Vulnerability Management

NIST: PR.AC-5: Network integrity is protected, incorporating network segregation where appropriate, PR.IP-5:

Policy and regulations regarding the physical operating environment for organizational assets are met

PCI-DSS: Requirement 4: Encrypt transmission of cardholder data across open, public networks

SO 12 – Operating procedures Description

The DSP establishes and maintains procedures for the operation of key network and information systems by personnel. (i.e. operating procedures, user manual, administration procedures for critical systems etc.)

Security measures within sophistication levels Mapping

ISO27001: ISO/IEC 27001:2013 A12.1.1, A.12.5.1, A.13.2.1, A.14.2.2

CCS: 4.1 Service Desk, 4.2 Application Management, 4.3 Technical Management, 4.4 Operations Management

BSI C5: SA-01, AM-03, AM-07, PS-05, RB-06, RB-10, RB-11, RB-17, RB-19, IDM-01, KRY-01, KOS-07, PI-03, BEI-

01, BEI-03, SIM-01, BCM-02, MDM-01

OCF: BCR-01, BCR-02, BCR-03,BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11 Business Con-

tinuity Management & Operational Resilience, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, DCS-01, DCS-02, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09 Datacenter Security, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM- 11 Governance and Risk Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS- 10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security

SO 13 – Change management Description

The DSP establishes and maintains change management procedures for key network and information systems. These may include for example, change and configuration procedures and processes, change procedures and tools, procedures for applying patches etc.

Security measures within sophistication levels Mapping

ISO27001: ISO/IEC 27001:2013 A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4

CSA CCM: CSA CCM (CCC-01, CCC-02, CC03, CC04, CC05, CC06) Change control & configuration management

BSI C5: BEI-03, BEI-04, BEI-05, BEI-06, BEI-07, BEI-08, BEI-09, BEI-10, BEI-11, BEI-12, DLL-02, BCM-02, BCM-04

COBIT 5: COBIT 5 BAI06.01, BAI01.06

CCS: 4.2 Application Management, 4.4 Operations Management, 7.5 Change Management

OCF: DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management,

DCS-01, DCS-02, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09 Datacenter Security, GRM-01, GRM- 02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security

NIST: PR. IP-3: Configuration change control processes are in place

PCI-DSS: Requirement 6: Develop and maintain secure systems and applications: 6.4.6, Requirement 12 - Main-

tain a policy that addresses information security for all personnel: 12.1.1.1, A3.2- Document and validate PCI DSS scope: A3.2.2.1, A3.4.1

SO 14 – Asset management Description

The DSP establishes and maintains asset management procedures and configuration controls for key network and information systems.

Security measures within sophistication levels

1

2

Mapping

ISO27001: ISO/IEC 27001:2013 A.8.1.1, A.8.1.2, ISO/IEC 27001:2013 A.13.2.1, ISO/IEC 27001:2013 A.8.2.1,

ISO/IEC 27001:2013 A.6.1.1

CSA CCM: (DSI-01) Datacenter security - Asset management, (HRS-01) Human resources- Asset returns

BSI C5: AM-01, AM-02, AM-03, AM-04, AM-05, AM-06, AM-07, AM-08

COBIT 5: BAI09.01, BAI09.02, COBIT 5 BAI09.01, BAI09.02, BAI09.05, DSS05.02, APO02.02, APO01.02, DSS06.03

CCS: 4.2 Application Management, 5.1 Principles of Cloud Architecture, 5.16 Data Management, 6.1 Location of

Data and Data Centers, 7.6 Service Asset and Configuration Management

OCF: DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management,

DCS-01, DCS-02, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09 Datacenter Security, HRS-01, HRS- 02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS-10, HRS-11 Human Resources, IVS-01, IVS- 02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security

NIST: PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.1, 12.2

SO 15 – Security incident detection & Response Description

The DSP establishes and maintains procedures for detecting and responding to security incidents appropriately. These should consider detection, response, mitigation, recovery and remediation from a security incident. Lessons learned should also be adopted by the service provider.

Security measures within sophistication levels Mapping

ISO27001: ISO/IEC 27001:2013 A.16.1.5

CSA CCM: (SEF-03, SEF-04, SEF-05) Security incident management (reporting & response metrics)

BSI C5: SIM-01, SIM-02, SIM-03, SIM-04, SIM-05, SIM-06, SIM-07, RB-10, RB-11, RB-14, RB19, RB-20, DLL-01,

DLL-02

COBIT 5: BAI01.10

CCS: 4.1 Service Desk, 5.18 Response to Security Incidents, 6.12 Security Management, 7.1 Resolution Pro-

cesses

OCF: CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, IVS-01, IVS-02,

IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, SEF-01, SEF-02, SEF-03, SEF-04, SEF-05 Security Incident Management, E-Discovery & Cloud Forensics

NIST: DE.AE-5: Incident alert thresholds are established, RS.AN-2: The impact of the incident is understood

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.10,

12.10.1. 12.10.2

SO 16 – Security incident reporting Description

The DSP establishes and maintains appropriate procedures for reporting and communicating about security incidents.

Security measures within sophistication levels Mapping

ISO27001: ISO/IEC 27001:2013 A.16.1.5

CSA CCM: CSA CMM (SEF-01, SEF-02, SEF-04,) Security incident management (contact/authority maintenance,

management & legal preparations)

BSI C5: SIM-04, SIM-06, OIS-03, DLL-01, DLL-02

COBIT 5: EDM03.02, MEA03.02

CCS: 4.1 Service Desk, 5.18 Response to Security Incidents, 6.12 Security Management, 7.1 Resolution Pro-

cesses

OCF: CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, IVS-01, IVS-02,

IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11, IVS-12,IVS-13 Infrastructure & Virtualization Security, SEF-01, SEF-02, SEF-03, SEF-04, SEF-05 Security Incident Management, E-Discovery & Cloud Forensics

NIST: PR. IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Re-

covery and Disaster Recovery) are in place and managed

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.10.2,

12.10.4, 12.10.5, 12.10.6

SO 17 – Business continuity Description

The DSP establishes and maintains contingency plans and a continuity strategy for ensuring continuity of the services offered.

Security measures within sophistication levels

1

2

Mapping

ISO27001: ISO/IEC/27001:2013 A.17.1

CSA CCM: (BCR-01, BCR-02, BCR-03, BCR-04-BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11) Busi-

ness continuity management & operational resilience retention policy

BSI C5: BCM-01, BCM-02, BCM-03, BCM-04, BCM-05

CCS: 5.12 Backup, 7.2 IT Service Continuity Management

OCF: BCR-01, BCR-02, BCR-03, BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11 Business Con-

tinuity Management & Operational Resilience, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM- 07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management

NIST: PR. IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Re-

covery and Disaster Recovery) are in place and managed

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.10.1

SO 18 – Disaster recovery capabilities Description

The DSP establishes and maintains an appropriate disaster recovery capability for restoring the offered services in case of natural and/or major disasters.

Security measures within sophistication levels Mapping

ISO27001: ISO/IEC 27001:2013 A.16.1.1, A.17.1.1, A.17.1.2

CSA CCM: (BCR-09, BCR-11) Business continuity management & operational resilience retention policy

BSI C5: BCM-04, BCM-05

COBIT 5: DSS04.03

CCS: 5.1 Principles of Cloud Architecture, 5.12 Backup, 7.2 IT Service Continuity Management

OCF: BCR-01, BCR-02, BCR-03,BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11 Business Con-

tinuity Management & Operational Resilience, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM- 07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management

NIST: PR. IP-10: Response and recovery plans are tested

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.10.1

SO 19 – Monitoring and logging Description

The DSP establishes and maintains procedures and systems for monitoring and logging of the offered services (logs of user actions, system transactions/performance monitors, automated monitoring tools etc.).

Security measures within sophistication levels

1

2

Mapping

ISO27001: ISO/IEC 27001:2013 A.12.4

CSA CCM: CSA CCM (IVS-01)- Infrastructure & Virtualization Security (Audit Logging / Intrusion Detection)

BSI C5: RB-02, RB-07, RB-10, RB-11, RB-12, RB-13, RB-14, RB-15, RB-16, KOS-02, DLL-02

CCS: 5.11 System Administration and Management

OCF: OCF, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11, IVS-12, IVS-13

Infrastructure & Virtualization Security

NIST: DE.CM: Security continuous monitoring

PCI-DSS: A1: Additional PCI DSS Requirements for Shared Hosting Providers: A1.3

SO 20 – System tests Description

The DSP establishes and maintains appropriate procedures for testing key network and information systems underpinning the offered services.

Security measures within sophistication levels

1

Mapping

ISO27001: ISO/IEC 27001:2013 A.14.2

BSI C5: RB-18, RB-21, BEI-01, BSI-02, BEI-03, BEI-07, BEI-09

CCS: 4.3 Technical Management, 6.2 Compliance Management, 6.4 Audit Management, 6.12 Security Manage-

ment

OCF: OCF, AIS-01, AIS-02, AIS-03, AIS-04 Application & Interface Security, CCC-01, CCC-02, CCC-03, CCC-04,

CCC-05 Change Control & Configuration Management, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IVS-01, IVS-02, IVS-03, IVS- 04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability, MOS-01,MOS-02,MOS-03,MOS-04,MOS- 05,MOS-06,MOS-07,MOS-08,MOS-09,MOS-10,MOS-11,MOS-12,MOS-13 to MOS-20 Mobile Security, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability, TVM-01, TVM-02, TVM-03 Threat and Vulnerability Management

NIST: PR. IP-10: Response and recovery plans are tested

PCI-DSS: A3.2- Document and validate PCI DSS scope: A3.2.4, A3.2.5.1

SO 21 – Security assessments Description

The DSP establishes and maintains appropriate procedures for performing security assessments of critical assets.

Security measures within sophistication levels

1

Mapping

ISO27001: ISO/IEC 27001:2013 A.12.6.1, A.18.2.2

CSA CCM: (AAC-02) Audit assurance & compliance independent audits

BSI C5: COM-02, COM-03, RB-17, RB-18, RB-19, RB-21

CCS: 6.2 Compliance Management, 6.4 Audit Management, 6.12 Security Management, 6.13 Embedding Exter-

nal Services

OCF: OCF, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, GRM-01,

GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS- 12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability, MOS-01,MOS-02,MOS-03,MOS-04,MOS-05,MOS-06,MOS-07,MOS-08,MOS-09,MOS-10,MOS-11,MOS- 12,MOS-13 to MOS-20 Mobile Security, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-

09 Supply Chain Management, Transparency and Accountability

PCI-DSS: Requirement 6: Develop and maintain secure systems and applications: 6.6

SO 22 – Compliance Description

The DSP establishes and maintains a policy for checking and enforcing the compliance of internal policies against the national and EU legal requirements and industry best practices and standards. These policies are reviewed on a regular basis.

Security measures within sophistication levels

1

Mapping

ISO27001: ISO/IEC/27001:2013 A.18

CSA CCM: CSA CCM (AAC-01, AAC-02, AAC-03) Audit assurance & compliance

BSI C5: COM-01, COM-02, COM-03

COBIT 5: 5.15 Configuration Management, 6.2 Compliance Management, 6.4 Audit Management, 6.12 Security Management, 6.13 Embedding External Services

OCF: OCF, AAC-01, AAC-02, AAC-03 Audit Assurance & Compliance, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05

Change Control & Configuration Management, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, EKM-01, EKM-02, EKM-03, EKM-04 Encryption & Key Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, HRS-01, HRS-02, HRS-03, HRS-04, HRS-05, HRS-06, HRS-07, HRS-08, HRS-09, HRS- 10, HRS-11 Human Resources, IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11,IAM-12,IAM-13 Identity & Access Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY- 03, IPY-04, IPY-05 Interoperability & Portability, MOS-01,MOS-02,MOS-03,MOS-04,MOS-05,MOS-06,MOS- 07,MOS-08,MOS-09,MOS-10,MOS-11,MOS-12,MOS-13 to MOS-20 Mobile Security, SEF-01, SEF-02, SEF-03, SEF-04, SEF-05 Security Incident Management, E-Discovery & Cloud Forensics, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and accountability

SO 23 – Security of data at rest Description

The DSP establishes and maintains appropriate mechanisms for the protection of the data at rest .

Security measures within sophistication levels Mapping

ISO27001: ISO/IEC 27001:2013 A.8.2.3, ISO/IEC 27001:2013 A.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2,

A.14.1.3, ISO/IEC 27001:2013 A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, ISO/IEC 27001:2013 A.12.2.1, A.12.5.1, A.14.1.2, A.14.1.3, ISO/IEC 27001:2013 A.12.1.4

CSA CCM: (DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07) Data security

BSI C5: AM-05, SIM-02, RB-10, COM-01, KRY-01, KRY-02, KRY-03, KRY-04, PI-05, RB-11, RB-13, AM-04, AM-07,

RB-23, KOS-05, BEI-03, HR-02, HR-03

COBIT 5: APO01.06, BAI02.01, BAI06.01, DSS06.06

CCS: 5.1 Principles of Cloud Architecture, 5.2 Development Processes, 5.3 Client Separation, 5.5 Encryption, 5.7

Network Architecture, 5.9 Virtualization, 5.13 User Management and Authentication, 5.16 Data Management, 6.5 Data Protection

OCF: OCF, AIS-01, AIS-02, AIS-03, AIS-04 Application & Interface Security, AAC-01, AAC-02, AAC-03 Audit Assur-

ance & Compliance, BCR-01, BCR-02, BCR-03,BCR-04, BCR-05, BCR-06, BCR-07, BCR-08, BCR-09, BCR-10, BCR-11 Business Continuity Management & Operational Resilience, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05 Change Control & Configuration Management, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, DCS-01, DCS-02, DCS-03, DCS-04, DCS-05, DCS-06, DCS-07, DCS-08, DCS-09 Datacenter Security, EKM-01, EKM-02, EKM-03, EKM-04 Encryption & Key Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11,IAM- 12,IAM-13 Identity & Access Management, IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability

NIST: Data Security (PR.DS): Information and records (data) are managed consistent with the organization’s

risk strategy to protect the confidentiality, integrity, and availability of information. ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed

PCI-DSS: Requirement 12 - Maintain a policy that addresses information security for all personnel: 12.6

SO 24 –Interface security Description

The DSP should establish and maintain an appropriate policy for keeping secure the interfaces of services which use personal data.

Security measures within sophistication levels

1

Mapping

CSA CCM: (AIS-01, AIS-02, AIS-03, AIS -04) Application & Interface Security

BSI C5: OIS-02, SA-01, PI-01, HR-02, HR-03, KRY-01, KRY-02, SIM-07, SIM-01, SIM-03, SIM-04, SIM-05, SIM-06

IDM-08

CCS: 5.1 Principles of Cloud Architecture, 5.2 Development Processes, 5.4 Security Architecture

OCF: OCF, AIS-01, AIS-02, AIS-03, AIS-04 Application & Interface Security, EKM-01, EKM-02, EKM-03, EKM-04

Encryption & Key Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11,IAM-12,IAM-13 Identity & Access Management, IVS-01, IVS- 02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability,

PCI-DSS: Requirement 2: Do not use vendor-supplied defaults for system passwords and other security param-

eters: 2.3

SO 25 –Software security Description

The DSP establishes and maintains a policy which ensures that the software is developed in a manner which respects security .

Security measures within sophistication levels Mapping

CSA CCM: (AIS -04) -Application & Interface Security/Data Security Integrity

BSI C5: BEI-01, BEI-02

CCS: 5.1 Principles of Cloud Architecture, 5.2 Development Processes, 5.9 Virtualization, 5.14 Patch Manage-

ment

OCF: OCF, AIS-01, AIS-02, AIS-03, AIS-04 Application & Interface Security, CCC-01, CCC-02, CCC-03, CCC-04,

CCC-05 Change Control & Configuration Management, DSI-01, DSI-02, DSI-03, DSI-04, DSI-05, DSI-06, DSI-07 Data Security & Information Lifecycle Management, GRM-01, GRM-02, GRM-03, GRM-04, GRM-05, GRM-06, GRM-07, GRM-08, GRM-09, GRM-10, GRM-11 Governance and Risk Management, IVS-01, IVS-02, IVS-03, IVS- 04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11,IVS-12,IVS-13 Infrastructure & Virtualization Security, IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability, MOS-01,MOS-02,MOS-03,MOS-04,MOS- 05,MOS-06,MOS-07,MOS-08,MOS-09,MOS-10,MOS-11,MOS-12,MOS-13 to MOS-20 Mobile Security, STA-01, STA-02, STA-03, STA-04, STA-05, STA-06, STA-07, STA-08, STA-09 Supply Chain Management, Transparency and Accountability, TVM-01, TVM-02, TVM-03 Threat and Vulnerability Management

NIST: ID.AM-2: Software platforms and applications within the organization are inventoried, ID.AM-5: Re-

sources (e.g., hardware, devices, data, and software) are prioritized based on their classification, criticality, and business value, PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity, DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed

PCI-DSS: Requirement 2: Do not use vendor-supplied defaults for system passwords and other security param-

eters: 2.4

SO 26 – Interoperability and portability Description

Online market place and cloud providers use standards which allow customers to interface with other digital services and/or if needed to migrate to other providers offering similar services.

Security measures within sophistication levels Mapping

CSA CCM: (IPY-01, IPY-02, IPY-03, IPY-04, IPY-05) - Interoperability & Portability

BSI C5: PI-01, PI-02, PI-03, PI-04, PI-05

CCS: 5.8 Network Monitoring, 5.10 System Monitoring

OCF: IPY-01, IPY-02, IPY-03, IPY-04, IPY-05 Interoperability & Portability

SO 27 – Customer Monitoring and log access Description

The cloud provider grants customers access to relevant transaction and performance logs so customers can investigate issues or security incidents when needed.

Security measures within sophistication levels

1

Mapping

ISO27001: ISO/IEC 27001:2013 A.12.4.1, A.12.4.2, A.12.4.3 & A.12.4.4

CSA CCM: (IVS-01)- Infrastructure & Virtualization Security, (Audit Logging / Intrusion Detection)

BSI C5: RB-13H, RB-14, RB14H, RB-10, RB-11, RB-12, RB-13, RB-15, RB-16H, RB-23

COBIT 5: APO11.04

CCS: 5.8 Network Monitoring, 5.10 System Monitoring

OCF: IVS-01, IVS-02, IVS-03, IVS-04, IVS-05, IVS-06, IVS-07, IVS-08, IVS-09, IVS-10, IVS-11, IVS-12, IVS-13 Infra-

structure & Virtualization Security

NIST: PR.PT-1: Audit/log records are determined, documented, implemented, and reviewed in accordance with

policy, PR.MA-1: Maintenance and repair of organizational assets is performed and logged in a timely manner, with approved and controlled tools

3. Summary

To summarise, the level of sophistication to which security measures are implemented from one organization to another can vary for a multitude of reasons. For instance, this may depend on the industry sector, the size of the company or the time and effort that the management can afford to invest in implementing security measures. From the received feedback for this study, stakeholders should consider the different roles that the DSP’s play in the online environment, and in particular how their level of criticality differs (i.e. lack of availability for a search engine may not pose a significant risk, whereas for a different DSP, this may be more critical). As a result, some security objectives may be prioritized over others and thus the sophistication levels may also differ.

There are high level security objectives, which are interchangeable among all three DSP categories, while a few belong to specific DSP categories. In the following table, the common security objectives for all DSPs are marked with a check mark. If a SO doesn’t belong to a specific DSP category, it is indicated with an xmark.

Finally, we present a summary table below with a mapping of the SOs to the different schemes. If a security objective is covered in one of the schemes below it is marked with a dot. If not, it stays blank.

SECURITY OBJECTIVES ISO27001 CSA CCM BSI C5 COBIT 5 CCS OCF NIST PCI-DSS CES

SECURITY OBJECTIVES ISO27001 CSA CCM BSI C5 COBIT 5 CCS OCF NIST PCI-DSS CES

ENISA

European Union Agency for Network and Information Security Science and Technology Park of Crete (ITE) Vassilika Vouton, 700 13, Heraklion, Greece

Athens Office

1 Vasilissis Sofias Marousi 151 24, Athens, Greece

TP-05-16-077-EN-N

PO Box 1309, 710 01 Heraklion, Greece ISBN: 978-92-9204-203-5 DOI: 10.2824/456345 Tel: +30 28 14 40 9710 info@enisa.europa.eu www.enisa.europa.eu

Fotnoter

  1. Technical guidelines for the implementation of minimum security measures for DSPs
  2. December 2016
  3. Technical guidelines for the implementation of minimum security measures for DSPs
  4. December 2016
  5. Technical guidelines for the implementation of minimum security measures for DSPs
  6. December 2016
  7. Technical guidelines for the implementation of minimum security measures for DSPs
  8. December 2016
  9. Technical guidelines for the implementation of minimum security measures for DSPs
  10. December 2016
  11. https://ec.europa.eu/digital-single-market/en/news/directive-security-network-and-information-systems-nis-directive Preamble 48, Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. Cloud certification schemes Meta Framework, ENISA, 2014, available at https://resilience.enisa.europa.eu/cloudcomputing-certification . Namely: (a) the security of systems and facilities, (b)incident handling, (c) business continuity management, (d) monitoring, auditing and testing, (e) compliance with international standards
  12. Technical guidelines for the implementation of minimum security measures for DSPs
  13. December 2016
  14. Preambles (15), (16) and (17) of the NIS Directive
  15. Technical guidelines for the implementation of minimum security measures for DSPs
  16. December 2016
  17. Technical guidelines for the implementation of minimum security measures for DSPs
  18. December 2016
  19. Figure 1: Terminology explained in a diagram extracted from “Cloud Certification Schemes Meta framework”
  20. Technical guidelines for the implementation of minimum security measures for DSPs
  21. December 2016
  22. Technical guidelines for the implementation of minimum security measures for DSPs
  23. December 2016
  24. SOPHISTICATION LEVEL DESCRIPTION OF SOPHISITICATION LEVELS
  25. -Basic security measures that could be implemented to reach the security objective 1 –Basic -Examples that basic measures are in place -Industry standard security measures to reach the objective and an ad-hoc review of the implementation, following changes or incidents. 2 – Industry standard -Examples of industry standard measures and evidence of reviews of the implementation reacting to changes and/or incidents.
  26. -State of the art (advanced) security measures, and continuous monitoring of implementation, structural review of implementation, taking into account changes, incidents, tests and exercises, to proactively improve the implementation of security measures 3 – State of the art -Examples of state of the art (advanced) implementation, evidence of a structural review process, and evidence of pro-active steps to improve the implementation of security measures.
  27. Technical guidelines for the implementation of minimum security measures for DSPs
  28. December 2016
  29. Technical guidelines for the implementation of minimum security measures for DSPs
  30. December 2016
  31. LEVEL SECURITY MEASURES EXAMPLES
  32.  Set a high level security policy, which is aligned with business objectives and ad-  Documented security policy, including networks, systems dresses the security and continuity of the and services in scope, critical assets supporting them, and communication networks and/or services the security objectives.
  33. provided.  Key personnel are aware of the security policy and its objec-  Make key personnel aware of the security tives (interview). policy.
  34.  Documented information security policy, approved by man-  Set detailed information security policies agement, including applicable laws and regulations, accessifor critical assets and business processes. ble to personnel.  Make all personnel aware of the security  The information security policy is easily accessible to staff.
  35. policy and what it entails for their work.  Personnel are aware of the information security policy and  what it implies for their work (interview). Review the security policy following incidents.  Review comments or change logs for the policy.
  36.  Information security policies are up to date and approved by senior management.  Logs of policy exceptions, approved by the relevant roles. Review the information security policies period-  Documentation of review process, taking into account ically, and take into account significant system changes and past incidents. changes, violations, exceptions, past incidents, o Last planned review has been done according with
  37. past tests/exercises, and incidents affecting the review process. o Records of the management review. other (similar) providers in the sector. o Meeting minutes of review sessions. o Feeds and insights collected from internal security solutions and external databases
  38. These security and continuity requirements come from the risk analysis a DSP should perform (SO 02 – Risk Management)
  39. Technical guidelines for the implementation of minimum security measures for DSPs
  40. December 2016
  41. LEVEL SECURITY MEASURES EXAMPLES
  42.  Create a list of the main risks for security and continuity of the provided communication networks, systems or services, taking into account the main  List of main risks described at a high level, including the underlying threats for critical assets. threat(s) and their potential impact on the security, continuity and  privacy of networks and services. 1 Consider risks which stem from data protection or other sector-specific reg-  Key personnel are aware of the main risks (via interviews, ad hoc ulations or policies into the risk assesstests). ments.  Make key personnel aware of the main risks and how they are mitigated.  Documented risk management methodology and/or tools which  Set up a risk management methodolcontains, at least: 2 ogy and/or tools based on industry o Objectives, roles, and responsibilities; standards. o Scope of the risk management methodology;
  43. Technical guidelines for the implementation of minimum security measures for DSPs
  44. December 2016
  45. o Procedures that supports the risk assessment;  Ensure that key personnel use the risk o Catastrophic but improbable events that could affect to management methodology and tools. the offered services.  Review the risk assessments following  Guidance for personnel on assessing risks. changes, security incidents or data  List of risks and evidence of updates/reviews. breaches.  Review comments or change logs for risk assessments.  Management approval of residual risks.  Ensure residual risks are accepted by management.  Documentation of the review process and updates of the risk management methodology and/or tools. Review the risk management methodology o Last planned review has been done according with the 3 and/or tools, periodically, taking into acreview process. count changes and past incidents. o Records of the management review. o Meeting minutes of review sessions
  46. This objective might be merged with SO 01: ‘Information Security Policy’ in case that the DSP decides to include the management of the security policy into the policy itself.
  47. Technical guidelines for the implementation of minimum security measures for DSPs
  48. December 2016
  49. LEVEL SECURITY MEASURES EXAMPLES
  50.  Assign security roles and responsibilities to personnel. List of security roles (CISO, DPO, business continuity manager, etc.),
  51.  who occupies them and contact information. Make sure the security roles are reachable in case of security incidents.
  52.  Personnel is formally appointed in se-  List of appointments (CISO, DPO, etc.), and description of responcurity roles sibilities and tasks for security roles (CISO, DPO, etc.).  Formal appointment of the key security roles and responsibilities. 2  Make personnel aware of the security  Awareness/dissemination material for personnel explaining seroles in your organization and when curity roles and when/how they should be contacted. they should be contacted.
  53.  Up-to-date documentation of the structure of security role as- Structure of security roles and responsibil- signments and responsibilities. 3 ities is regularly reviewed and revised,  Documentation of review process, taking into account changes based on changes and/or past incidents. and past incidents.
  54. Technical guidelines for the implementation of minimum security measures for DSPs
  55. December 2016
  56. LEVEL SECURITY MEASURES EXAMPLES
  57.  Contractual agreements when deal-  List of relevant third party contracts. ing with third parties and customers  List of customer access request. have been established.  Identify selection criteria.  Include security requirements and 1 relevant tasks in contracts with  Documented contractual agreements containing at least: third-parties and customers. o Service description;  Communicate residual risks which o Security measures; might affect the offered services to the customers. o Non-disclosure agreements;
  58. Technical guidelines for the implementation of minimum security measures for DSPs
  59. December 2016
  60. LEVEL SECURITY MEASURES EXAMPLES
  61.  Retain the right to perform second o Roles and responsibilities;
  62. party audits where it is deemed neco Target service levels; essary from a risk perspective. o Contacts and reporting lines;  Responsibilities regarding the maintenance, operation and owner- o The right for second party audits.
  63. ship of assets have been defined.  Explicit security requirements in the contracts with third parties
  64. supplying IT products, IT services, outsourced business processes, helpdesks, call centers, interconnections, shared facilities, et cetera.
  65.  Documented security policy for contracts with third parties.  Set a security policy for contracts  Contracts for third party services contain security requirements, in with third-parties. line with the security policy for procurement.  Ensure that all procurement of ser-  Review comments or change logs of the policy. vices/products from third-parties  Past risk analysis reports. follows the policy.  Residual risks resulting from dependencies on third parties are
  66. 2  Review security policy for third par- listed and mitigated. ties, following incidents or changes.  Documented third parties’ contractual agreements contains special requirements in case of:  Perform risk analysis before entering o Major blackouts; any outsourcing agreement. o Natural catastrophes; o Accidents or other possible emergency situations;  Mitigate residual risks that are not addressed by the third party. o Blackout resistance.
  67.  List of security incidents related to or caused by engagement with  Keep track of security incidents re- third-parties. lated to or caused by third-parties.  Documented results of monitoring activities.  Documented results of auditing activities.  Periodically review and update pol-  Identify the process(es) applied to manage recent changes and con- 3 icy for third parties and reevaluate firm: outsourcing agreements at regular o Adequate warning to all stakeholders is provided; intervals, taking into account past ino Involves relevant personnel; cidents, changes, etc. o Includes procedures for backing-out from failed changes.
  68. Technical guidelines for the implementation of minimum security measures for DSPs
  69. December 2016
  70. LEVEL SECURITY MEASURES EXAMPLES
  71. Check professional references of key personnel (system admin- Documentation of checks of professional refer-
  72. istrators, security officers, guards, et cetera). ences for key personnel.  Policy and procedure for background checks/screenings. Guidance for personnel  Perform background checks/screening for key personnel about when/how to perform background and external contractors, when needed and legally permitchecks/screenings. ted.  Screening records containing at least: 2 o Employment history;  Set up a policy and procedure for background checks. o Verification of the highest educa-  Individuals screening criteria is established and reviewed tion degree received; for organization’s position. o Residency; o Law enforcement records.
  73.  Review and update policy/procedures for background  Review comments or change logs of the pol- 3 checks and reference checks at regular intervals, taking into icy/procedures. account changes and past incidents.  Documented screening requirements.
  74. Technical guidelines for the implementation of minimum security measures for DSPs
  75. December 2016
  76. LEVEL SECURITY MEASURES EXAMPLES
  77.  Records of rescreening process.  The screening process is in line with the defined policies and regulations.  Individuals are rescreened based on a defined list of conditions.
  78. LEVEL SECURITY MEASURES EXAMPLES
  79.  Regularly provide key personnel  Key personnel has followed security trainings and has sufficient with relevant training and material security knowledge (interview). on security issues. 1  Third parties have sufficient security knowledge (interview).  Ensure that third parties are trained and aware of security issues  Implement a program for training,  Personnel have participated in awareness sessions on security
  80. making sure that key personnel topics.
  81. Technical guidelines for the implementation of minimum security measures for DSPs
  82. December 2016
  83. LEVEL SECURITY MEASURES EXAMPLES
  84. have sufficient and up-to-date secu-  Documented program for training on security skills, including, obrity knowledge. jectives for different roles and how to reach it (by e.g. training, awareness raising, etc.).  The program is approved by the  Records of individual awareness activities. management.  Organize trainings and awareness sessions for personnel on security topics important for the organization.  Contents of security training are  Updated security awareness and training program. based on assigned roles and respon-  The last planned review has been done according with the review sibilities and specific requirements process. of the organization and the infor-  Meeting minutes of review sessions. mation system to which personnel  List of contacts with security groups and associations. have authorized access.  Results of tests of the security knowledge of personnel.  Review comments or change logs for the program.  Review and update the training pro-  Results of individual certification process. gram periodically, taking into account changes and past incidents.  Test the security knowledge of per-
  85. sonnel.  Contacts and communication channels with security groups and associations have been established in order to stay up to date with the latest recommended security practices, techniques, and technologies.  Provide to the organization personnel training sessions to obtain recognized security certifications.
  86. Technical guidelines for the implementation of minimum security measures for DSPs
  87. December 2016
  88. LEVEL SECURITY MEASURES EXAMPLES
  89.  Following changes in personnel re-  Evidence that personnel changes have been followed up with voke access rights, badges, equip- revocation of access rights, badges, equipment, et cetera ment, et cetera, if no longer neces-  Evidence that new personnel has been briefed and educated 1 sary or permitted. about policies and procedures in place. Brief and educate new personnel on the policies and procedures in place.  Implement policy/procedures for  Documentation of process for personnel changes, including, repersonnel changes, taking into ac- sponsibilities for managing changes, description of rights of ac- 2 count timely revocation access cess and possession of assets per role, procedures for briefing rights, badges, equipment. and training personnel in new roles.
  90. Technical guidelines for the implementation of minimum security measures for DSPs
  91. December 2016
  92. LEVEL SECURITY MEASURES EXAMPLES
  93.  Evidence that personnel changes have been carried according to  Implement policy/procedures for the process and that access rights have been updated timely (e.g. education and training for personchecklists). nel in new roles.  Periodically check that the pol-  Evidence of checks of access rights etc. icy/procedures are effective. Up to date policy/procedures for managing personnel changes.  Review comments or change logs.  Review and evaluate policy/proce-  Proof of automated process. dures for personnel changes, taking 3 into account changes or past incidents.  Automated process review access permissions that are initiated by personnel changes.
  94. Technical guidelines for the implementation of minimum security measures for DSPs
  95. December 2016
  96. LEVEL SECURITY MEASURES EXAMPLES
  97.  Prevent unauthorized physical ac-  Basic implementation of physical security measures and environcess to facilities and infrastructure mental controls, such as door and cabinet locks, burglar alarm, fire and set up environmental controls, alarms, fire extinguishers, CCTVs, et cetera. to protect against unauthorized ac-  List of personnel with authorized access. cess, burglary, fire, flooding, etc.  List of authorized visitors.  A list of personnel with authorized access to facilities containing infor-  Basic implementation of environmental controls. mation systems and appropriate authorization credentials (e.g., badges, identification cards) is maintained 1 by the organization.
  98.  Visitors are authenticated before authorizing access to the facility.  Data center environmental conditions (e.g., water, power, temperature and humidity controls) shall be secured, monitored, maintained, and tested to ensure protection from unauthorized interception or damage.  Implement a policy for physical se-  Documented policy for physical security measures and environcurity measures and environmental mental controls, including description of facilities and systems in controls. scope.  Documented procedure with the specific steps to take in case of  Document procedure for emergency emergency. cases  Physical and environmental controls, like electronic control of en-  A designated official within the or- trance and audit trail, segmentation of spaces according to authorganisation to review and approve ization levels, automated fire extinguishers with halocarbon gases, the list of personnel with authorized et cetera. access has been identified.  Records of visitors’ access to the facility.  Documented description of monitoring equipment.  Visitors are escorted as required ac-
  99. cording to security policies and procedures.  Visitor’s access records to the facility are maintained by the organisation.  The Physical access to the premises is monitored by the organisation.  Industry standard implementation of physical and environmental controls.  Evaluate the effectiveness of physi-  Up to date policy for physical security measures and environmencal and environmental controls peri- tal controls. 3 odically.  Documentation about evaluation of environmental control, review comments or change logs.  Proof of different versions of physical access records.
  100. Technical guidelines for the implementation of minimum security measures for DSPs
  101. December 2016
  102. LEVEL SECURITY MEASURES EXAMPLES
  103.  Documented defined period of retention.  Review and update the policy for  List with different access zones. physical security measures and environmental controls taking into account changes and past incidents.  Physical access records are kept and stored in case of an audit or investigation.  Physical access records are retained as dictated by applicable regulations or based on an organization-defined period by approved policy.  Separate facilities into different zones according to their contents.
  104. Technical guidelines for the implementation of minimum security measures for DSPs
  105. December 2016
  106. LEVEL SECURITY MEASURES EXAMPLES
  107. Ensure security of supplies, such as elec- Security of supplies is protected in a basic way, for example, backup
  108. tric power, fuel or HVC. power and/or backup fuel is available  Implement a policy for security of  Documented policy to protect critical supplies such as electrical critical supplies, such as electrical power, fuel, etc., describing different types of supplies, and the sepower, fuel, etc. curity measures protecting the supplies.  Evidence of industry standard measures to protect the security of 2  Implement industry standard secusupplies, such as for example, passive cooling, automatic restart afrity measures to protect supplies ter power interruption, battery backup power, diesel generators, and supporting facilities. backup fuel, etc.
  109.  Advanced security measures to pro- Advanced implementation controls to protect security of supplies, such tect supplies. as active cooling, UP, hot standby power generators, sufficient fuel delivery SLA, SLAs with fuel delivery companies, redundant cooling and  Review and update policy and pro- 3 power backup systems. cedures to secure supplies regularly, taking into account changes and past incidents.
  110. Technical guidelines for the implementation of minimum security measures for DSPs
  111. December 2016
  112. LEVEL SECURITY MEASURES EXAMPLES
  113.  Users and systems have unique ID’s  Access logs show unique identifiers for users and systems when and are authenticated before ac- granted or denied access. cessing services or systems.  Overview of authentication and access control methods for sys-  Implement (logical) access control tems and users.
  114. mechanism for network and infor-  Documented methods of access control containing at least: mation systems to allow only authorized use. o Authentication type; o Authorization schema.  Implement policy for protecting ac-  Access control policy including description of roles, groups, access cess to network and information rights, procedures for granting and revoking access. systems, addressing for example  Different types of authentication mechanisms for different types roles, rights, responsibilities and of access, e.g. Single-Sign-On, two-factor authentication, multi-facprocedures for assigning and revok- tor authentication, etc, (including remote and WiFi mechanisms) ing access rights.  Log of access control policy violations and exceptions, approved by the security officer.  Based on the results of risk analysis,  List of authorized users who can access to security functions. choose the relevant authentication  Logs from privileged accounts’ usage. mechanisms which are deemed rel-  Network isolation and implementation of segmented network seevant to different types of access. curity zones that limit the impact of a malware incident  Monitor access to network and in-  Segregation of duties control matrix. formation systems, have a process  Access control matrix. for approving exceptions and regis-
  115. tering access violations.  Security functions are restricted to the least amount of users necessary to ensure the security of the information system.  Track and monitor privileged accounts by validating their creation, use of specific authentication methods and regular reviews.  Segment information access within network and information systems based on security requirements.  Evaluate the effectiveness of access  Reports of (security) tests of access control mechanisms.
  116. control policies and procedures and
  117. Technical guidelines for the implementation of minimum security measures for DSPs
  118. December 2016
  119. LEVEL SECURITY MEASURES EXAMPLES
  120. implement cross checks on access  Tools for detection of anomalous usage of systems or anomalous control mechanisms. behaviour of systems (such as intrusion detection/prevention and anomaly detection systems).  Access control policy and access  Logs of intrusion detection /prevention and anomaly detection control mechanisms are reviewed systems. and when needed revised.  Updates of access control policy, review comments or change logs.  Restrictions in the number of con-  Real-time logging and recording of unsuccessful login attempts; current sessions are defined and im-  Real-time alerting when the number of defined consecutive invalid plemented by the organization. access attempts is exceeded.
  121. Of either known or unknown attacks or both.
  122. Technical guidelines for the implementation of minimum security measures for DSPs
  123. December 2016
  124. LEVEL SECURITY MEASURES EXAMPLES
  125.  Make sure software of network and  Software and data in network and information systems is proinformation systems is not tam- tected using prevention, input controls, firewalls, encryption and pered with or altered, for instance signing. by using input controls.  Security critical data is protected using protection mechanisms  Protect security critical data (like like separate storage, encryption, hashing, etc. 1 passwords, shared secrets, private  Malware detection systems are present, and up to date. keys, etc.) from being disclosed or tampered with.  Records of recent updates of malware protection mechanisms.  Take measures against malicious  Records of periodical scans. software on (internal) network and information systems.  Implement industry standard secu-  Documentation about how the protection of software and data in rity measures, providing defense-in- network and information system is implemented. depth and protection against tam-  Documented alternative countermeasures such as: pering and altering of systems. o Securing of all physical and logical data interfaces; o Network isolation and implementation of segmented  The malware protection mechanetwork security zones that limit the impact of a malnisms are centrally managed. ware incident;  There are mechanisms which pre- o Comprehensive system hardening measures to minimize vent users from circumventing mal- the risk of malware incidents. ware protection capabilities.  Tools for detection of anomalous usage of systems or anomalous behaviour of systems (such as intrusion detection/prevention 2  Spam protection mechanisms are and anomaly detection systems). employed at system entry points  Logs of intrusion detection/prevention and anomaly detection such as workstations, servers, or systems. mobile computing devices on the  Documented description of centrally management tools. network.  Documented spam protection mechanism.  Use of whitelisting solutions, which restrict the execution of nonapproved software and code.  Interactive access to critical systems is performed using hardened hosts which have built in controls to inhibit phishing attacks, lateral movement, and persistent compromise.
  126.  Sophisticated controls to protect in-  Sophisticated controls to protect integrity of systems, such as tegrity of systems. code signing, tripwire, et cetera.  Documentation of process for checking logs of anomaly and in- 3  Evaluate and review the effectivetrusion detection/prevention systems. ness of measures to protect integrity of systems.
  127. Technical guidelines for the implementation of minimum security measures for DSPs
  128. December 2016
  129. LEVEL SECURITY MEASURES EXAMPLES
  130. Set up operational procedures and as- Documentation of operational procedures and responsibilities for key 1 sign responsibilities for operation of network and information systems. critical systems. Implement a policy for operation of Documented policy for operation of critical systems, including an oversystems to make sure all critical sys- view of network and information systems in scope. 2 tems are operated and managed in line with predefined procedures.
  131. Technical guidelines for the implementation of minimum security measures for DSPs
  132. December 2016
  133. LEVEL SECURITY MEASURES EXAMPLES
  134. Review and update the policy/proce- Updated policy/procedures for critical systems, review comments dures for operation of critical systems, and/or change logs. 3 taking into account incidents and/or changes.
  135. LEVEL SECURITY MEASURES EXAMPLES
  136.  Follow predefined procedures when  Documentation of change management procedures for critical making changes to critical systems, systems. according to licensing agreements  Documentation of a customer update on significant changes 1  Inform the customer of significant changes to critical systems which affect the offered services.  Implement and test policy/proce-  Documentation of change management policy/procedures in- 2 dures for change management, to cluding, systems subject to the policy, objectives, roll back procemake sure that changes of critical dures, etc.
  137. Technical guidelines for the implementation of minimum security measures for DSPs
  138. December 2016
  139. LEVEL SECURITY MEASURES EXAMPLES
  140. systems are always done following a  For each change, a report is available describing the steps and predefined way. the result of the change  Document change management procedures, and record for each change the steps of the followed procedure. Review and update change management Up to date change management procedures, review comments 3 procedures regularly, taking into ac- and/or change logs. count changes and past incidents.
  141. Technical guidelines for the implementation of minimum security measures for DSPs
  142. December 2016
  143. LEVEL SECURITY MEASURES EXAMPLES
  144.  A secure baseline configuration of  Documented secure baseline configuration containing at least: components and information syso Essential capabilities of operation; tems is developed, documented and maintained. o Restricted use of functions;
  145.  Manage critical assets e.g. software, o Security by default; hardware, information and configuo Ports, protocols and/or services allowed. rations of critical systems.  List of critical assets and critical systems.
  146. Implement policy/procedures for asset  Documented policy/procedures for asset management, including management and configuration control. roles and responsibilities, the assets and configurations that are subject to the policy, the objectives of asset management  An asset inventory or inventories, containing critical assets, their
  147. owners and the dependency between assets.  A configuration control inventory or inventories, containing configurations of critical systems.
  148.  Review and update the asset man-  Up to date asset management policy/procedures, review comagement policy regularly, based on ments and/or change logs. changes and past incidents.  Documented results of the review activities.  Documented and approved exceptions to the configuration base-  Review regularly the list with configline containing the alternative controls in place to ensure the urations and the list with critical asconfidentiality, availability and integrity of the information sys- 3 sets based, based on changes and tem. past incidents.  Documented secure baseline configuration for development and  A secure baseline configuration for test environments. development and test environments is managed separately from the operational baseline configuration.
  149. Technical guidelines for the implementation of minimum security measures for DSPs
  150. December 2016
  151. LEVEL SECURITY MEASURES EXAMPLES
  152.  Set up processes or systems for inci-  Past incidents were detected and timely forwarded to the approdent detection and response. priate people, including customers.  Make sure personnel is available  Personnel is aware of how to deal with incidents and when to es- 1 and prepared to manage and handle calate. incidents.  Inventory of major incidents and per incident, impact, cause, actions taken, and lessons learnt.  Implement industry standard sys-  Incident detection systems and procedures, such as Security Incitems and procedures for incident dent and Event Management (SIEM) tools, security helpdesk for 2 detection and response. personnel and customers, reports and advisories from Computer Emergency Response Teams (CERTs), tools to spot anomalies, et cetera.
  153. Technical guidelines for the implementation of minimum security measures for DSPs
  154. December 2016
  155. LEVEL SECURITY MEASURES EXAMPLES
  156.  Policy/procedures for incident detection and response, including,  Implement systems and procedures types of incidents that could occur, objectives, roles and responfor registering and forwarding incisibilities, detailed description, per incident type, how to manage dents timely to the appropriate the incident, when to escalate to senior management (CISO e.g.), people. et cetera.  Management commitment with the incident response program.  Records of individual training activities.  Description of the incident handling capability containing at least the following procedures: o Preparation; o Detection; o Analysis; o Containment; o Mitigation; o Recovery.
  157.  Investigate major incidents and  Individual reports of the handling of major incidents. draft final incident reports, includ-  Up to date documentation of incident detection and response ing actions taken and recommenda- systems and processes. tions to mitigate and reduce time to  Documentation of review of the incident detection and response react to any future occurrence of processes, maximum response times, review comments, and/or this type of incident or data breach. change logs.  Records of cyber exercises.  Review systems and processes for 3 incident detection and response regularly and update them taking into account changes and past incidents.  Regular cyber exercises and related results to test the incident response effectiveness are scheduled and documented.
  158. Technical guidelines for the implementation of minimum security measures for DSPs
  159. December 2016
  160. LEVEL SECURITY MEASURES EXAMPLES
  161. Communicate and report about on-go-  List of authorities contacts containing at least: ing or past incidents to third parties, cuso National and international agencies together with structomers, and/or government authorities, tures for co-operation for the protection of critical infrawhen necessary. structures; 1 o National and international CERT organizations; o Disaster control organizations and disaster-relief teams; o Documented communication channels.  Evidence of past communications and incident reporting. Implement policy and procedures for  Documented policy and procedures for communicating and report- 2 communicating and reporting about inci- ing about incidents, describing reasons/motivations for communidents. cating or reporting (business reasons, legal reasons etc.), the type
  162. Technical guidelines for the implementation of minimum security measures for DSPs
  163. December 2016
  164. LEVEL SECURITY MEASURES EXAMPLES
  165. of incidents in scope, the required content of communications, notifications or reports, the channels to be used, and the roles responsible for communicating, notifying and reporting.  Templates for incident reporting and communication.
  166.  Evaluate past communications and  List of incident reports and past communications about incidents reporting about incidents.  Up to date incident response and communication policy, review 3 comments, and/or change logs.  Review and update the reporting and communication plans, based on changes or past incidents.
  167. Technical guidelines for the implementation of minimum security measures for DSPs
  168. December 2016
  169. LEVEL SECURITY MEASURES EXAMPLES
  170. Implement a service continuity strategy for the com-  Documented service continuity strategy, inmunications networks and/or services provided. cluding recovery time objectives for key services and processes.
  171.  Management commitment with the continuity strategy.  Implement contingency plans for critical systems.  Contingency plans for critical systems, including clear steps and procedures for com-  Monitor activation and execution of contingency mon threats, triggers for activation, steps plans, registering successful and failed recovery and recovery time objectives. times.  Decision process for activating contingency
  172. plans.  Logs of activation and execution of contingency plans, including decisions taken, steps followed, final recovery time.
  173.  Review and revise service continuity strategy peri-  Up to date continuity strategy and continodically. gency plans, review comments, and/or change logs.  Review and revise contingency plans, based on  Documented results of the continuity of oppast incidents and changes. erations test activities.  The continuity of operations plan is tested and up-  Records of individual training activities. 3 dated on a regular basis.
  174.  Personnel involved in the continuity operations plan are trained in their roles and responsibilities with respect to the information system and receive refresher training on an organization-defined frequency.
  175. Technical guidelines for the implementation of minimum security measures for DSPs
  176. December 2016
  177. LEVEL SECURITY MEASURES EXAMPLES
  178. Prepare for recovery and restoration of services fol- Measures are in place for dealing with disasters, such as 1 lowing disasters. failover sites in other regions, backups of critical data to remote locations, et cetera.  Implement policy/procedures for deploying disas-  Documented policy/procedures for deploying disaster recovery capabilities. ter recovery capabilities, including list of natural and/or major disasters that could affect the services,  Implement industry standard disaster recovery caand a list of disaster recovery capabilities (either pabilities or be assured they are available from those available internally or provided by third par- 2 third parties (such as national emergency netties). works).  Industry standard implementation of disaster capabilities, such as mobile equipment, mobile sites, failover sites, et cetera.
  179. At the basic sophistication level this objective could be merged with SO 17: ‘Business continuity’ into one. Backup solutions should be disconnected from live systems because some forms of ransomware might encrypt backups attached to the system.
  180. Technical guidelines for the implementation of minimum security measures for DSPs
  181. December 2016
  182. LEVEL SECURITY MEASURES EXAMPLES
  183.  Advanced implementation controls for disaster re-  Advanced implementation controls for disaster recovery capabilities to mitigate natural and/major covery capabilities, such as full redundancy and failodisasters. ver mechanisms to handle natural and/or major disasters.  Review and update disaster recovery capabilities regularly, taking into account changes, past inci-  Data centre infrastructure/design is designed for 3 dents, and results of tests and exercises. availability, auto failover, and resiliency to maintain service to customers.  Updated documentation of disaster recovery capabilities in place, review comments and/or change logs.
  184. LEVEL SECURITY MEASURES EXAMPLES
  185. Implement monitoring and logging of critical systems. Logs and monitoring reports of critical network and infor-
  186. mation systems.
  187. Technical guidelines for the implementation of minimum security measures for DSPs
  188. December 2016
  189. LEVEL SECURITY MEASURES EXAMPLES
  190.  Implement policy for logging and monitoring of  List of auditable events. critical systems.  Audit records containing at least: o Date and time of the event;  Set up tools for monitoring critical systems. o Component of the information system  Set up tools to collect and store logs critical sys- where the event concurred; tems. o Type of event; o User/subject identity; o Outcome of the event.
  191.  Documented policy for monitoring and logging, including minimum monitoring and logging requirements, retention period, and the overall objectives of storing monitoring data and logs.  Tools for monitoring systems and collecting logs.  List of monitoring data and log files, in line with the policy.
  192.  Set up tools for automated collection and analysis  Tools to facilitate structural recording and analysis of of monitoring data and logs. monitoring and logs.  Updated documentation of monitoring and logging 3  Review and update logging and monitoring polpolicy/procedures, review comments, and/or change icy/procedures, taking into account changes and logs. past incidents.
  193. Technical guidelines for the implementation of minimum security measures for DSPs
  194. December 2016
  195. LEVEL SECURITY MEASURES EXAMPLES
  196.  Test networks and information systems before  Test reports of the network and information sysusing them or connecting them to existing sys- tems, including tests after big changes or the introtems. duction of new systems.
  197.  The installation or de-installation of patches is  Checks for latest patches done in an ad hoc manner.  Implement policy/procedures for testing net-  Policy/procedures for testing networks and inforwork and information systems. mation systems, including when tests must be carried out, test plans, test cases, test report templates.  Implement tools for automated testing.  Documented testing activities containing at least:  The installation or de-installation of patches is o Objectives, roles, and responsibilities; 2 done periodically in an organized manner. o Scope of the plan; o Detailed results of the execution of the plan; o Frequency of the test.  Approved documented actions applying patches.
  198.  Review and update the policy/procedures for  List of test reports. testing, taking into account changes and past  Updated policy/procedures for testing networks and incidents. information systems, review comments, and/or change log.  The installation or de-installation of patches is 3 reviewed to ensure the adequately implementation of the defined actions.  Exceptions to defined actions and approved mitigating actions are identified and documented.
  199. Technical guidelines for the implementation of minimum security measures for DSPs
  200. December 2016
  201. LEVEL SECURITY MEASURES EXAMPLES
  202.  Ensure critical systems undergo security scans  Reports from past security scans and security tests. and security testing regularly, particularly  Documented vulnerability scans reports. when new systems are introduced and follow-
  203. ing changes.  Vulnerabilities are monitored and assessed.  Implement policy/procedures for security as-  Documented policy/procedures for security assesssessments and security testing. ments and security testing, including, which assets, in what circumstances, the type of security assess-  A single point of contact and communication ments and tests, frequency, approved parties (interchannels for information security related is- 2 nal or external), confidentiality levels for assessment sues with manufacturers or vendors have and test results and the objectives security assessbeen identified. ments and tests.  List of manufactures single point of contact.
  204. Technical guidelines for the implementation of minimum security measures for DSPs
  205. December 2016
  206. LEVEL SECURITY MEASURES EXAMPLES
  207.  Evaluate the effectiveness of policy/proce-  List of reports about security assessments and secudures for security assessments and security rity tests. testing.  Reports of follow up actions on assessments and test results.  Review and update policy/procedures for se-  Up to date policy/procedures for security assesscurity assessments and security testing, taking ments and security testing, review comments, 3 into account changes and past incidents. and/or change log.  Information obtained from the vulnerability  Records of vulnerabilities information sharing. scanning process is shared with designated personnel throughout the organization and authorities to help eliminate similar vulnerabilities in other information systems.
  208. Technical guidelines for the implementation of minimum security measures for DSPs
  209. December 2016
  210. LEVEL SECURITY MEASURES EXAMPLES
  211. Monitor compliance to standards and legal re- Reports describing the result of compliance monitoring.
  212. quirements. Implement policy/procedures for compliance mon-  Documented policy/procedures for monitoring comitoring and auditing. pliance and auditing, including what (assets, processes, infrastructure), frequency, guidelines who should carry out audits (in- or external), relevant security policies that are subject to compliance moni- 2 toring and auditing, the objectives and high level approach of compliance monitoring and auditing, templates for audit reports.  Detailed monitoring and audit plans, including long term high level objectives and planning.
  213.  Evaluate the policy/procedures for compliance  List of all compliance and audit reports and auditing. o Root cause analysis to the compliance and audit reports.  Perform deviation root cause analysis.  Remediation plans for critical assets. 3  Build remediation plans for critical assets.  Updated policy/procedures for compliance and auditing, review comments, and/or change logs.  Review and update the policy/procedures for compliance and auditing, taking into account changes and past incidents.
  214. Technical guidelines for the implementation of minimum security measures for DSPs
  215. December 2016
  216. LEVEL SECURITY MEASURES EXAMPLES
  217.  Identify the most critical data taking into ac-  The access control, sharing, copying, transmittal and count relevant business needs and legal obli- distribution of confidential and restricted data are gations (e.g. with regard to the processing of defined personal data).  Safeguards to protect the secrecy of secret (private)  Retain the critical data for a certain period de- key(s) are in place pending on the type of data and its criticality  Limited or ad hoc processes exist to protect elec-  Implement cryptographic mechanisms to pro- tronic media tect the confidentiality and integrity of infor-  Evidence from regular reviews of devices/storage 1 mation stored on digital media during media to examine that data is removed or securely transport outside of controlled areas and in overwritten prior to disposal. transit when moving within and between company data locations.  Implement cryptographic mechanisms such as digital signatures and hashes to detect unauthorized changes to critical data at rest.  Implement mechanisms for the secure disposal of the data after their lawful use.  Classify all data according to a classification  Data retention policy exists and is complete scheme which takes into account data’s value,  Formal standard to govern protection of electronic legal requirements, sensitivity, and criticality transportable media is in place. Encryption enforced to the organization. on electronic media identified with confidential in-  Use of removable media is prohibited unless formation. strictly required.  Evidence for the existence of mechanisms which  Ensure the confidentiality and integrity of data support in ensuring confidentiality and integrity of at rest according to the classification scheme. the data at rest such as cryptographic mechanisms, 2 file share scanning, secure offline storage, removal  Establish a policy around confidentiality and of sensitive data from storage media etc. according integrity of data at rest and make all personnel to the classification scheme. to whom it is relevant, are aware of the policy and procedure and what it implies for their  Evidence of the existence of a mechanism (either work. manual or automated) for the establishment and management of cryptographic keys (only if cryptog-  Set detailed cryptographic key establishment raphy has been implemented). and management policies and procedures for data at rest (only if cryptography has been implemented).
  218. The term ‘data at rest’ is extensively used to collectively describe different types of data formats such as databases, office data and data stored in various types of storage media.
  219. Technical guidelines for the implementation of minimum security measures for DSPs
  220. December 2016
  221. LEVEL SECURITY MEASURES EXAMPLES
  222.  A set of best practice procedures are in place  Obtain evidence of written authorization to dispose for the secure disposal of physical assets. of equipment from department Head. A disposal form should be completed.  Classify all assets according to the classifica-  Labelling of information of information is reviewed tion scheme. on a regular basis  Implement information labelling and handling  The data retention policy is supported by a compreprocedures in accordance with the classificahensive data retention schedule, which contains the tion scheme retention period for each type of data used by the  The data retention policy considers the value organization of data over time and the data retention laws  Reports of the data retention policy and configurathe organization may be subject to. tion which ensure that they are in line with require-  Strong controls are in place surrounding con- ments and good practices nection of media devices.  Technology infrastructure automatically encrypts  Use automated key management mechanisms. and protects electronic transportable media in the environment.  Review of confidentiality and integrity of data at rest policy.  Portable media standards are reviewed at least annually and on an ad hoc basis for any new technol-  Disposal of assets at the most opportune time ogy or threats. in line with company objectives, strategy and the data retention policy, using the most ap-  Evidence that the public-key encryption and secret 3 key of user and cipher-text are based on the subpropriate methods. ject’s attributes.  Documentation of review process, taking into account changes and past incidents. Review the policy on a regular basis  Personnel are aware of the confidentiality and integrity of the data at rest policy and procedures and what it implies for their work (interview). Review comments or change logs for the policy and/or procedure.  Evidence of secure key generation, use, storage and destruction of data.  Rationale for disposal of assets and the methods used is provided. Review of physical asset inventory. All devices leaving the controlled environment must be purged of data using disk wiping utilities or degassing methods (reformatting is not enough)
  223. Technical guidelines for the implementation of minimum security measures for DSPs
  224. December 2016
  225. Customer interface is considered a powerful tool offered by the DSPs to the customers as a means to enhance customer’s control on his own data in the cloud.
  226. Technical guidelines for the implementation of minimum security measures for DSPs
  227. December 2016
  228. LEVEL SECURITY MEASURES EXAMPLES
  229.  Set a high level security policy for keeping the  Documented security policy, including networks and cloud and online market interfaces secure services in scope, critical assets supporting them, and the security objectives.  Make key personnel aware of the security policy.  Key personnel are aware of the security policy and
  230. its objectives (interview).  Enable secure channels for data transmission (e.g. TLS2.0)  At least one secure channel is enabled.  Use unique identifiers to identify users  All customers are assigned to a unique identifier.
  231.  Set detailed security policies for data security  Documented security policies, approved by manageto include protection of customer administra- ment, including applicable law and regulations, action interfaces (TLS2.0, 2-Factor authentica- cessible to personnel. tion) etc.  Personnel are aware of the security policy and what it implies for their work (interview). 2  Make all personnel aware of the security pol-  Review comments or change logs for the policy. icy and what it implies for their work.  Review the security policy following incidents.
  232.  Implement 2-Factor authentication
  233.  Review the security policy periodically, and  Security policies are up to date and approved by sentake into account violations, exceptions, past ior management. incidents, past tests/exercises, and incidents  Logs of policy exceptions, approved by the relevant 3 affecting other (similar) providers in the sec- roles. tor.  Documentation of review process, taking into account changes and past incidents.
  234. Technical guidelines for the implementation of minimum security measures for DSPs
  235. December 2016
  236. LEVEL SECURITY MEASURES EXAMPLES
  237. Establish guidelines for maintaining software secu-  Documented guidelines, to ensure that software serity curity is maintained. 1  Key personnel are aware of the guidelines and its objectives (interview).
  238.  Implement a defined set of security measures  Evidence of the test results to secure development to secure development environments, includ- environments, including measures for protecting test ing measures for protecting test data. data are maintained. 2  Evidence of the software testing methods chosen for  Depending on the type of requirement include a particular test scenario and explanation of this. software testing methods (e.g. black-box, adhoc testing).
  239. In case that software development is outsourced the DSP should take provisions to include Software Lifecycle Agreements (SLA) as an essential part of the procurement process. Although patching has been already described under SO 13: ‘Change Management’, one can include it under this objective as well.
  240. Technical guidelines for the implementation of minimum security measures for DSPs
  241. December 2016
  242. LEVEL SECURITY MEASURES EXAMPLES
  243.  Evidence of separated environments for develop-  Keep separated environments for development, testing and production. ment purposes, testing purposes and production.  Security by design is tested at various stages of  Test results of each phase of the SDLC are mainthe SDLC prior to Go-live utilizing independent tained and are up to date. Test results are maintools and a self-service testing platform tained and approved by senior management throughout SDLC.  Documented evidence of the review process of the patch development process, security training for 3  Results of application assessments are used to software developments and secure by design softregularly enhance developer training and the ware configurations SDLC process.  Evidence that a software testing method is chosen at  each stage of the software development lifecycle
  244. Technical guidelines for the implementation of minimum security measures for DSPs
  245. December 2016
  246. LEVEL SECURITY MEASURES EXAMPLES
  247. Implement processes and procedures which allow  Use of HTML/XML which allow users to integrate difcustomers to interact with services and/or if ferent services and to (more easily) migrate from 1 needed to migrate to other providers offering simi- one provider to another lar services, in an easy and basic way  Use of OVF standard format for virtual machines
  248. Implement industry standard security measures,  Use of SAML/XACML that acts as an interface to which promote interoperability and portability, in- manage the provision of identification and user aucluding fall-back procedures (for example in the thentication between user and provider case of cloud computing services).  Documentation about how the protection and integ- 2 rity of infrastructure & virtualization security is maintained.  Information on the fallback procedures is explicitly described.  State of the art controls exist and are a crucial aspect  Set up state of the art controls to facilitate into mitigate security related risks for customers teroperability & portability.  Where applicable, tools for detection of anomalous  Evaluate and review the effectiveness of in- 3 usage or risks associated is used, which allows the teroperability & portability measures. option for customer to plan in advance the interoperability & portability measures.
  249. Technical guidelines for the implementation of minimum security measures for DSPs
  250. December 2016
  251. LEVEL SECURITY MEASURES EXAMPLES
  252.  Separate the logging information between the  Logs and monitoring reports available to customer different customers. concerning his data.
  253.  Implement monitoring and logging of customer data.  Implement policy for logging and monitoring  Documented policy for monitoring and logging, inof customer data depending on the type of cluding minimum monitoring and logging requireservice. ments, retention period, and the overall objectives of storing monitoring customer data and logs.  Set up tools for customer to monitor this data 2  Tools for monitoring systems and collecting cus-  Set up tools to collect and store logs of cus- tomer data logs. tomer data.  List of monitoring customer data and log files, in line with the policy.
  254.  Set up tools for automated collection and  Tools to facilitate structural recording and analysis of analysis of monitoring data and logs. monitoring and logs of customer data.  Updated documentation of monitoring and logging 3  Review and update logging and monitoring policy/procedures, review comments, and/or change policy/procedures, taking into account logs. changes and past incidents.
  255. Technical guidelines for the implementation of minimum security measures for DSPs
  256. December 2016
  257. SECURITY OBJECTIVES CLOUD PROVID- ONLINE MARKET ONLINE SEARCH EN- ERS PLACES GINES
  258. SO 01 - Information security policy    SO 02 – Risk Management    SO 03 – Security Roles    SO 04 – Third party management    SO 05 – Background checks    SO 06 – Security knowledge and training    SO 07 – Personnel changes    SO 08 – Physical and environmental security    SO 09 – Security of supporting utilities    SO 10 – Access control to network and information sys-    tems SO 11 – Integrity of network components and information    systems SO 12 – Operating procedures    SO 13 – Change management    SO 14 – Asset management    SO 15 – Security incident detection & Response    SO 16 – Security incident reporting    SO 17 – Business continuity    SO 18 – Disaster recovery capabilities    SO 19 – Monitoring and logging    SO 20 – System tests   
  259. Technical guidelines for the implementation of minimum security measures for DSPs
  260. December 2016
  261. SO 21 – Security assessments   
  262. SO 22 – Compliance   
  263. SO 23 –Security of data at rest   
  264. SO 24 –Interface security   
  265. SO 25 –Software security   
  266. SO 26 – Interoperability and portability   
  267. SO 27 – Customer Monitoring and log access   
  268. SO1 Information Security Pol-        icy SO2 Risk management        SO3 Security roles        SO 04 Security in supplier re-        lationships SO 05 Background checks        SO 06 Security knowledge         and training SO 07 Personnel changes        SO 08 Physical and environ-        mental security SO 09 Security of supporting     utilities SO 10 Access control to network and information sys-          tems SO 11 Integrity of network        and information systems SO 12 Operating procedures     SO 13 Change management          SO 14 Asset management          SO 15 Security incident detec-         tion & response SO 16 Security incident re-         porting SO 17 Business continuity       
  269. Including CES+
  270. Technical guidelines for the implementation of minimum security measures for DSPs
  271. December 2016
  272. SO 18 Disaster recovery capa-         bilities SO 19 Monitoring and logging         policies SO 20 System tests        SO 21 Security assessments        SO 22 Compliance      SO 23 Security of data at rest          SO 24 Interface security       SO 25 - Software security       SO 26 Interoperability and     portability SO 27 Customer monitoring          and log access