Mapping Matrix
201 controls × 12 frameworks
fullpartialinf
| ID | Name | SOC 2 | ISO 27001 | NIST 800-53 | AI RMF | EU AI Act | ISO 42001 | CSA CCM | GDPR | OWASP LLM | OWASP Agentic | AI 600-1 | CSA AICM |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AIG-001 | AI Policy | — | — | — | GOVERN 1.1GOVERN 1.2GOVERN 1.4MAP 1.5MAP 1.3GOVERN 4.1 | EU-AI-Art.17.1 | A.2.2A.2.4A.2.3A.9.3 | — | — | — | — | GV-1.1-001GV-1.3-006 | GRC-12GRC-01 |
| AIG-002 | AI Roles and Responsibilities | — | — | PM-23 | GOVERN 2.1GOVERN 2.3GOVERN 3.2MAP 1.2 | EU-AI-Art.26.2 | A.3.2A.4.6 | — | — | — | — | GV-1.5-001GV-3.2-002GV-4.1-003GV-4.2-002MP-1.2-001MG-3.2-007 | GRC-12 |
| AIG-003 | AI System Inventory | — | — | — | GOVERN 1.6MAP 1.4 | EU-AI-Art.6.1EU-AI-Art.6.2EU-AI-Art.6.3EU-AI-Art.49.3EU-AI-Art.52.1EU-AI-Art.49.1 | A.4.2 | — | — | — | — | GV-1.3-001GV-1.6-001GV-1.6-002GV-1.6-003MP-2.2-001 | — |
| AIG-005 | AI Risk Management Process | — | — | — | GOVERN 1.3GOVERN 1.5MANAGE 1.1MANAGE 1.2MANAGE 1.3MANAGE 1.4GOVERN 4.2MEASURE 1.1MEASURE 3.2MANAGE 2.1 | EU-AI-Art.9.1EU-AI-Art.9.2EU-AI-Art.9.4EU-AI-Art.9.3EU-AI-Art.55.2 | A.6.1.2A.6.1.3 | — | — | — | — | GV-1.3-001GV-1.3-005GV-1.3-006GV-4.1-001GV-4.2-002MP-1.1-003MP-4.1-008MS-1.1-005MS-1.1-008MS-1.1-009MS-2.5-006MS-2.6-003MS-3.2-001MG-1.3-001MG-3.1-003MG-4.1-001 | GRC-10GRC-02 |
| AIG-006 | AI Impact Assessment | — | — | — | MAP 5.1MAP 3.2MEASURE 2.12 | EU-AI-Art.9.6EU-AI-Art.26.8EU-AI-Art.6.2EU-AI-Art.27 | A.5.2A.5.3A.5.4A.5.5 | — | — | — | — | GV-4.2-003MP-1.1-002MP-5.1-002MP-5.2-001MS-1.3-002MS-2.6-001MS-2.11-003MS-2.12-001MS-2.12-002MS-2.12-003MS-3.3-001MG-2.2-006 | GRC-10 |
| AIG-007 | AI System Requirements and Design Documentation | — | — | — | MAP 1.1MAP 1.6MAP 2.1MAP 3.3MAP 3.1 | EU-AI-Art.11.1 | A.6.2.2A.6.2.3 | — | — | — | — | MP-1.1-001MP-1.1-002MS-2.12-002 | DSP-24GRC-13 |
| AIG-008 | AI System Verification, Validation and Testing | — | — | — | MEASURE 2.1MEASURE 2.3MEASURE 2.5MEASURE 2.6MEASURE 1.3MEASURE 2.11GOVERN 4.3MEASURE 1.1MEASURE 4.1MEASURE 4.2 | EU-AI-Art.9.5EU-AI-Art.15.1EU-AI-Art.60 | A.6.2.4 | — | — | — | — | GV-1.2-002GV-1.3-002GV-1.5-003GV-3.2-001GV-4.1-002MP-2.1-002MP-2.3-001MP-3.4-004MP-3.4-006MP-4.1-007MP-5.1-005MS-1.3-002MS-1.3-003MS-2.3-001MS-2.3-002MS-2.3-004MS-2.5-001MS-2.11-001MS-2.11-002MS-2.13-001MS-3.3-003 | MDS-07MDS-11 |
| AIG-009 | AI System Deployment and Change Management | — | — | — | MANAGE 1.1MANAGE 4.1MANAGE 4.2 | EU-AI-Art.43.3 | A.6.2.5 | — | — | — | — | GV-1.3-002GV-1.3-007MP-4.1-007MS-2.3-003MS-2.7-008MS-4.2-005MG-1.3-001MG-3.1-001MG-3.1-003 | MDS-05 |
| AIG-010 | AI Model Registry and Versioning | — | — | — | GOVERN 1.6 | EU-AI-Art.11.1 | A.4.3A.6.2.3A.6.2.5A.4.4 | — | — | LLM04 | — | GV-1.6-003GV-6.2-005MS-2.5-002MG-3.2-002 | DSP-23MDS-03MDS-08MDS-09STA-09 |
| AIG-011 | AI System Decommissioning | — | — | — | GOVERN 1.7MANAGE 4.1 | — | — | — | — | — | — | GV-1.7-002MG-2.4-001 | — |
| AIG-012 | Training Data Management and Quality | — | — | — | MAP 2.3 | EU-AI-Art.10.1EU-AI-Art.10.2EU-AI-Art.10.3 | A.7.2A.7.3A.7.4A.7.6 | — | — | LLM05 | — | MP-1.2-002MP-2.3-002MP-4.1-004MP-4.1-005MS-1.1-002MS-1.1-007MS-2.2-001MS-2.6-002MS-2.8-002MS-2.10-003MS-2.11-004MS-2.11-005MG-2.2-004 | DSP-21DSP-23DSP-24GRC-11 |
| AIG-013 | Training Data Provenance | — | — | SR-4 | GOVERN 6.1 | EU-AI-Art.10.2 | A.7.5 | — | GDPR-Art.14.3GDPR-Art.6.1 | LLM04LLM05 | — | GV-1.2-001GV-1.6-003GV-6.1-008MP-2.1-001MP-2.1-002MP-4.1-006MP-4.1-010MS-1.1-001MS-2.5-005MS-2.6-002MS-2.9-002MS-2.11-005MG-2.2-002MG-3.1-004MG-3.2-003MG-4.1-006 | DSP-20 |
| AIG-014 | Special Category Data in Training and Evaluation Datasets | — | — | PT-7 | MEASURE 2.10 | EU-AI-Art.10.4 | — | — | GDPR-Art.5.1aGDPR-Art.9.1GDPR-Art.9.2GDPR-Art.10 | — | — | MP-4.1-005MP-4.1-010MS-2.10-001 | — |
| AIG-015 | AI System Technical Documentation | — | — | SA-5 | MEASURE 2.8 | EU-AI-Art.11.1EU-AI-Art.18.1EU-AI-Art.53.1EU-AI-Art.11.2 | A.6.2.7A.4.4A.4.5 | — | — | — | — | MS-2.5-002MS-2.9-002MG-3.2-002MG-3.2-003 | DSP-20GRC-14MDS-03MDS-04MDS-05 |
| AIG-016 | AI Interaction and Output Disclosure | — | — | — | MEASURE 2.8 | EU-AI-Art.50.1EU-AI-Art.50.2EU-AI-Art.50.4EU-AI-Art.86EU-AI-Art.26.7 | A.8.2 | — | — | — | ASI09 | GV-1.2-001GV-4.3-001GV-5.1-002GV-6.1-003GV-6.1-008MP-2.3-004MP-3.4-001MP-5.1-001MP-5.1-002MP-5.1-003MS-1.1-001MS-1.1-002MS-1.1-007MS-2.2-002MS-2.7-002MS-2.7-003MS-2.7-005MS-2.8-003MS-2.10-002MS-3.3-002MS-4.2-001MG-2.2-003MG-2.2-007MG-3.2-006MS-2.5-004 | IAM-17 |
| AIG-017 | AI Model Explainability | — | — | — | MEASURE 2.9MAP 2.2 | EU-AI-Art.13.3EU-AI-Art.13.1EU-AI-Art.86 | — | — | GDPR-Art.22 | — | — | GV-4.1-001MS-2.9-001MS-4.2-003MG-3.2-001MG-4.2-003 | GRC-13GRC-14 |
| AIG-018 | AI System Operational Monitoring | — | — | — | MEASURE 2.4MANAGE 4.1MEASURE 3.1 | EU-AI-Art.26.4EU-AI-Art.72 | A.6.2.6 | — | — | — | ASI01ASI10 | GV-6.2-004MP-2.2-002MP-5.2-001MS-2.6-005MS-4.2-002MG-2.2-003MG-3.2-006MG-4.1-002MG-4.1-004MG-4.1-007MG-4.2-001 | MDS-10 |
| AIG-019 | AI Model Performance and Drift Detection | — | — | — | MEASURE 4.3MANAGE 2.2MANAGE 3.2MEASURE 1.2MEASURE 2.13 | EU-AI-Art.15.2 | — | — | — | — | — | MP-4.1-008MS-2.6-003MS-4.2-002MG-2.2-008MG-2.4-004MG-3.2-009MG-4.1-004 | DSP-21MDS-10 |
| AIG-020 | AI System Event Logging | — | — | AU-2AU-3AU-12 | MANAGE 4.3MEASURE 2.4MANAGE 4.1 | EU-AI-Art.12.1EU-AI-Art.16.4EU-AI-Art.26.5EU-AI-Art.21EU-AI-Art.12.2EU-AI-Art.19 | A.6.2.8 | LOG-07 | — | LLM09 | ASI01 | MS-2.8-003MS-4.2-004MG-2.2-007 | LOG-07LOG-15LOG-16 |
| AIG-021 | AI Incident Response and Error Communication | — | — | — | MANAGE 4.3MANAGE 2.3GOVERN 4.3 | EU-AI-Art.26.4EU-AI-Art.73 | A.8.4A.3.3 | — | — | — | — | GV-1.5-001GV-1.5-002GV-2.1-001GV-2.1-002GV-4.3-002GV-6.2-002MG-2.3-001MG-2.4-002MG-2.4-003MG-4.3-001MG-4.3-002MG-4.3-003 | — |
| AIG-022 | Human Oversight of AI Outputs | — | — | — | MAP 3.5GOVERN 3.2MAP 3.4 | EU-AI-Art.14.1EU-AI-Art.14.2EU-AI-Art.26.2EU-AI-Art.14.3EU-AI-Art.5.3 | — | — | GDPR-Art.22 | LLM07 | ASI09 | MP-3.4-005MS-3.3-002MS-4.2-004MG-3.2-008 | GRC-15IAM-17 |
| AIG-023 | AI System Override and Safe-State Mechanisms | — | — | CP-12SI-17 | MANAGE 2.4 | EU-AI-Art.14.2EU-AI-Art.15.2 | — | — | — | — | ASI08ASI10 | GV-1.3-007GV-1.7-001GV-6.2-006MS-2.6-005MG-2.4-002MG-2.4-004 | GRC-15TVM-13 |
| AIG-024 | Prohibited AI Practices | — | — | — | — | EU-AI-Art.5.1aEU-AI-Art.5.1bEU-AI-Art.5.1cEU-AI-Art.5.1dEU-AI-Art.5.1eEU-AI-Art.5.1fEU-AI-Art.5.1gEU-AI-Art.5.1hEU-AI-Art.5.1iEU-AI-Art.5.1jEU-AI-Art.5.1kEU-AI-Art.5.2EU-AI-Art.5.3EU-AI-Art.5.4 | — | — | — | — | — | GV-1.3-004GV-1.4-001GV-1.4-002MP-1.1-004MS-2.6-006MG-2.2-001MG-2.2-005MG-3.2-005 | GRC-09 |
| AIG-025 | AI Fairness and Bias Controls | — | — | — | MEASURE 2.11GOVERN 3.1MAP 1.2 | EU-AI-Art.10.2EU-AI-Art.15.1 | — | — | GDPR-Art.5.1a | — | — | MP-1.2-002MS-1.1-003MS-1.1-006MS-1.3-001MS-2.2-001MS-2.11-001MS-2.11-002MS-2.11-004MS-2.13-001MS-3.3-003MG-2.2-004 | GRC-11 |
| AIG-026 | AI Security and Adversarial Robustness | — | 8.11 | — | MEASURE 2.7MEASURE 2.6MEASURE 2.10 | EU-AI-Art.15.3 | — | — | GDPR-Art.32.1GDPR-Art.25.1 | LLM01LLM02LLM05LLM06LLM08 | ASI06 | GV-1.2-002GV-4.1-002MP-2.3-005MP-4.1-001MP-4.1-009MP-5.1-005MP-5.1-006MS-1.1-008MS-2.2-004MS-2.5-006MS-2.6-007MS-2.7-001MS-2.7-002MS-2.7-004MS-2.7-007MS-2.7-008MS-2.7-009MS-2.8-002MS-2.10-001MS-4.2-001MG-1.3-002MG-2.2-009MG-3.1-002 | DSP-21DSP-22MDS-06MDS-07TVM-04 |
| AIG-027 | AI Output Validation and Confidence Controls | — | — | SI-15 | MEASURE 2.3MANAGE 2.4 | EU-AI-Art.13.3EU-AI-Art.15.1EU-AI-Art.14.2EU-AI-Art.15.4EU-AI-Art.15.5 | A.6.2.4 | — | — | LLM07LLM10 | — | MS-2.6-004MG-2.2-001MG-3.2-008 | AIS-10TVM-13 |
| AIG-028 | Hallucination and Factual Accuracy Controls | — | — | — | MEASURE 2.5MAP 2.2 | EU-AI-Art.15.1EU-AI-Art.13.3EU-AI-Art.15.4EU-AI-Art.15.5 | A.6.2.4 | — | — | LLM07 | — | MP-2.3-001MP-2.3-003MS-1.1-005MS-2.5-003MS-2.5-005MG-4.1-002 | AIS-10 |
| AIG-029 | Prompt Injection Protection | — | — | — | MEASURE 2.7 | EU-AI-Art.15.3 | — | — | — | LLM01 | ASI01ASI06 | GV-3.2-005MP-2.3-005MS-2.7-007 | AIS-09AIS-13AIS-15TVM-04 |
| AIG-031 | AI Misuse, Jailbreak and Abuse Detection | — | — | — | MANAGE 4.1MEASURE 3.3 | EU-AI-Art.15.3EU-AI-Art.9.2EU-AI-Art.5.1iEU-AI-Art.5.1jEU-AI-Art.5.1k | — | — | — | LLM06 | ASI01ASI02ASI10 | GV-1.4-001GV-3.2-003MP-1.1-003MP-1.1-004MP-5.1-001MS-2.6-006MS-2.6-007MS-2.7-007MS-2.8-001MG-2.2-005MG-3.1-004MG-3.2-004MG-3.2-005 | AIS-09AIS-10GRC-09LOG-15LOG-16TVM-13 |
| AIG-032 | Third-Party AI Risk Management | — | — | SR-3 | GOVERN 6.1GOVERN 6.2MANAGE 3.1MANAGE 3.2MAP 4.1MAP 4.2 | EU-AI-Art.25.2EU-AI-Art.25.1 | A.10.2A.10.3 | — | — | LLM04 | ASI04 | GV-4.2-003GV-6.1-004GV-6.1-005GV-6.1-009GV-6.2-001GV-6.2-007MP-5.2-002MS-2.3-001MG-3.1-001MG-3.1-005 | MDS-12 |
| AIG-034 | Customer and Deployer Obligations Communication | — | — | — | — | EU-AI-Art.53.2EU-AI-Art.13.2EU-AI-Art.13.3EU-AI-Art.26.1EU-AI-Art.26.8EU-AI-Art.25.2EU-AI-Art.13.1EU-AI-Art.16.2EU-AI-Art.15.5 | A.10.4A.8.2A.8.5A.10.2 | — | — | — | — | GV-2.1-001GV-4.2-001MS-2.8-004MG-4.1-005 | — |
| AIG-036 | AI Quality Management System | — | — | — | — | EU-AI-Art.16.3EU-AI-Art.17.1EU-AI-Art.17.2EU-AI-Art.43.4 | — | — | — | — | — | GV-4.1-003GV-5.1-001MP-4.1-003 | — |
| AIG-037 | AI Regulatory Conformity Assessment and Declaration | — | — | — | — | EU-AI-Art.16.5EU-AI-Art.43.1EU-AI-Art.43.2EU-AI-Art.43.3EU-AI-Art.47EU-AI-Art.48EU-AI-Art.43.4 | — | — | — | — | — | — | — |
| AIG-038 | AI Feedback and Adverse Impact Reporting Channel | — | — | — | GOVERN 5.1GOVERN 5.2MAP 5.2MEASURE 3.3MANAGE 4.2 | EU-AI-Art.86 | A.8.3 | — | — | — | ASI09 | GV-1.3-004GV-3.2-004GV-4.3-003GV-5.1-001MP-4.1-002MP-5.1-004MS-1.1-004MS-1.1-006MS-1.3-001MS-2.7-003MS-2.10-002MS-3.3-005MS-4.2-005MG-2.2-006MG-2.2-008MG-3.2-004MG-4.1-003MG-4.2-001MG-4.3-002 | GRC-15 |
| AIG-039 | Responsible and Intended Use of AI Systems | — | — | — | — | EU-AI-Art.26.1EU-AI-Art.26.3 | A.9.2A.9.3A.9.4 | — | — | — | — | GV-1.4-002GV-3.2-003GV-6.1-007GV-6.1-010MS-4.2-003 | GRC-09HRS-15 |
| AIG-040 | Customer Data Use in Model Training | — | — | — | — | — | A.7.3 | DSP-12DSP-15 | GDPR-Art.6.4GDPR-Art.7GDPR-Art.13.3GDPR-Art.6.1GDPR-Art.5.1b | LLM02 | — | GV-4.2-001MS-2.2-003 | DSP-12DSP-15 |
| AIG-041 | Regulatory Authorised Representative | — | — | — | — | EU-AI-Art.22EU-AI-Art.54 | — | — | — | — | — | — | — |
| AIG-042 | Agentic Tool Permissions and Action Authorisation | — | — | AC-3AC-6AC-6(9)AU-2AU-12 | MANAGE 2.4 | — | A.6.2.8 | IAM-15IAM-05 | — | LLM01LLM03LLM08 | ASI01ASI02ASI03ASI05ASI10 | MS-2.7-001 | IAM-05IAM-15AIS-11IAM-16IAM-18 |
| AIG-043 | AI Non-Conformity Corrective Action and Authority Cooperation | — | — | — | — | EU-AI-Art.16.6EU-AI-Art.20EU-AI-Art.21EU-AI-Art.53.5 | — | — | — | — | — | — | — |
| AIG-044 | Workplace AI Deployment Notification to Workers | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-045 | Deployer Registration in a Public AI Register | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-046 | Fundamental Rights Impact Assessment | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-047 | General-Purpose Model Documentation and Downstream Information | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-048 | Public Training Content Summary | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-049 | Copyright Policy and Rights Reservation Compliance | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-050 | Systemic Risk Framework and Acceptance Determination | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-051 | Model Evaluation Under Standardised Protocols | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-052 | Model Weight and Infrastructure Protection | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-053 | Serious Incident Reporting to the AI Office | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-054 | Safety and Security Model Report | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile | Out of scope for this profile |
| AIG-055 | Training Pipeline Security | — | — | — | — | — | — | — | — | LLM05 | — | — | MDS-01MDS-02 |
| AIG-056 | Agent Memory and Context Integrity | — | — | — | — | — | — | — | — | LLM09 | ASI06 | — | — |
| AIG-057 | Inbound Synthetic Media Detection | — | — | — | — | — | — | — | — | — | ASI09 | MP-2.3-004MS-1.1-002 | — |
| APP-001 | Secure Development Lifecycle Policy | — | 8.258.30 | SA-3SA-15SA-1 | — | — | — | AIS-01AIS-04 | — | — | — | — | AIS-01AIS-04AIS-12 |
| APP-002 | Security Requirements in Design | — | 8.26 | SA-4SA-8SA-11(2) | — | — | — | AIS-02TVM-04 | — | — | — | GV-3.2-005MP-2.2-002MP-5.1-006 | AIS-02TVM-04 |
| APP-003 | Secure Coding Standards | CC8.1 | 8.28 | SA-15SI-11 | — | — | — | AIS-02 | — | LLM10 | — | — | AIS-02 |
| APP-004 | Security Testing in the Development Pipeline | CC8.1 | 8.29 | SA-11SA-11(1) | — | — | — | AIS-05CCC-02 | — | — | ASI05 | — | AIS-12AIS-05CCC-02 |
| APP-005 | Penetration Testing | CC7.1 | — | CA-8CA-8(2)CA-8(1) | — | — | — | TVM-07 | — | — | — | — | TVM-07 |
| APP-007 | Software Supply Chain and Dependency Management | CC6.8 | 8.195.21 | SI-2SA-22SR-4CM-7(8) | — | — | — | AIS-07STA-09 | — | LLM04 | ASI04 | — | AIS-07MDS-12STA-09 |
| APP-008 | Secrets Management | CC6.1 | 5.17 | IA-5IA-5(7) | — | — | — | IAM-14 | — | LLM08 | — | — | IAM-14 |
| APP-009 | Change Management | CC8.1CC5.2 | 8.32 | CM-3CM-4CM-1CM-9CM-3(4)CM-4(2)CM-3(2) | — | — | — | CCC-01CCC-03CCC-02CCC-08CCC-09CCC-04 | — | — | — | — | CCC-04CCC-08CCC-09CCC-01CCC-02CCC-03 |
| APP-010 | Environment Separation | — | 8.318.33 | CM-5PM-25CM-5(5) | — | — | — | CCC-06AIS-06 | — | — | — | — | AIS-06CCC-06 |
| APP-011 | API Security | CC6.6 | 8.26 | SI-10AC-14SC-6SI-11 | — | — | — | AIS-08 | — | LLM10 | ASI07 | — | AIS-09AIS-08 |
| APP-012 | Software Integrity Verification | CC6.8 | 8.29 | SI-7SA-10CM-14SR-9SI-7(1)SI-7(7)SI-7(5)SI-7(2) | — | — | — | CCC-04 | — | LLM04LLM05 | ASI04 | — | CCC-04MDS-02MDS-08MDS-09MDS-13 |
| APP-013 | Secure System Architecture and Design Principles | — | 8.27 | SA-8CP-12PL-8PM-7SA-24SC-24SI-17SC-7(18) | — | — | — | AIS-04 | — | — | ASI08 | — | AIS-04 |
| APP-014 | Vulnerability Disclosure Programme | — | 8.29 | SI-5RA-5(11) | — | — | — | TVM-01 | — | — | — | — | TVM-01 |
| APP-015 | Processing Integrity | PI1.1PI1.2PI1.3PI1.4PI1.5 | — | SI-15SI-11 | — | — | — | — | — | — | — | — | — |
| APP-016 | Sandboxed Execution of Untrusted Code | — | — | CM-7(6)SC-18 | — | — | — | — | — | — | ASI02ASI05 | MS-2.6-004 | AIS-11AIS-13MDS-13 |
| BCM-001 | Business Continuity Plan | — | 5.29 | CP-2CP-1RA-9CP-2(1)CP-4(1) | — | — | — | BCR-01BCR-03BCR-04BCR-05DCS-18 | — | — | — | — | BCR-03DCS-18BCR-01BCR-04BCR-05 |
| BCM-002 | Disaster Recovery Plan | A1.2 | 5.30 | CP-10CP-10(2) | — | — | — | BCR-09 | GDPR-Art.32.1 | — | — | — | BCR-09 |
| BCM-003 | RTO and RPO Definitions | — | 5.30 | CP-2CP-2(3) | — | — | — | BCR-02BCR-03 | — | — | — | — | BCR-03BCR-02 |
| BCM-004 | Backup Policy and Implementation | A1.2 | 8.13 | CP-6CP-9CP-9(8) | — | — | — | BCR-08 | — | — | — | GV-6.2-005 | BCR-08 |
| BCM-005 | Backup Restoration Testing | A1.3 | 8.13 | CP-4CP-9(1) | — | — | — | BCR-08 | GDPR-Art.32.1 | — | — | — | BCR-08 |
| BCM-006 | BCM and DR Testing | A1.3 | 5.30 | CP-4CP-3 | — | — | — | BCR-06BCR-10 | — | — | — | — | BCR-06BCR-10 |
| BCM-007 | Alternate Processing and Communications | — | 5.30 | CP-7CP-8CP-11SC-37SC-47CP-6(3)CP-7(2)CP-7(1) | — | — | — | BCR-07 | — | — | — | — | BCR-07 |
| BCM-008 | Business Impact Analysis | — | — | CP-2(8)RA-9CP-2 | — | — | — | BCR-02 | — | — | — | MP-2.2-001 | BCR-02 |
| BCM-009 | Backup Immutability and Isolation | — | 8.13 | CP-6(1)CP-9 | — | — | — | BCR-08 | — | — | — | — | BCR-08 |
| BCM-010 | Third-Party and AI Provider Service Continuity | CC9.1 | 5.23 | SA-9 | GOVERN 6.2 | — | A.10.3 | — | — | — | — | GV-6.2-001GV-6.2-006 | MDS-11 |
| DAT-001 | Data Classification Scheme | C1.1 | 5.125.13 | RA-2AC-22 | — | — | — | DSP-04DSP-01DCS-06 | GDPR-Art.5.1c | — | — | GV-6.1-001 | DCS-06DSP-04IAM-16DSP-01 |
| DAT-002 | Information Labelling | — | 5.13 | AC-16SC-16 | — | — | — | DSP-04 | — | — | — | — | DSP-04 |
| DAT-003 | Encryption at Rest | CC6.1 | 8.24 | SC-28SC-13SC-28(1)CP-9(8) | — | — | — | CEK-03CEK-04UEM-08 | GDPR-Art.32.1GDPR-Art.5.1f | — | — | — | CEK-04AIS-14CEK-03UEM-08 |
| DAT-004 | Encryption in Transit | CC6.7 | 5.148.24 | SC-8SC-13SC-17SC-23SC-8(1)AC-17(2)IA-5(2) | — | — | — | CEK-03DSP-10I&S-07IPY-03 | GDPR-Art.32.1GDPR-Art.5.1f | — | ASI07 | — | DSP-10CEK-03IPY-03I&S-07 |
| DAT-005 | Cryptographic Key Management | — | 8.24 | SC-12SC-13IA-7 | — | — | — | CEK-01CEK-04CEK-09CEK-12CEK-13CEK-14CEK-02CEK-05CEK-06CEK-07CEK-10CEK-11CEK-15CEK-16CEK-17CEK-18CEK-19CEK-20CEK-21LOG-11 | GDPR-Art.32.1 | — | — | — | CEK-02CEK-04CEK-05CEK-06CEK-07CEK-11CEK-12CEK-13CEK-14CEK-15CEK-01CEK-09CEK-10CEK-16CEK-17CEK-18CEK-19CEK-20CEK-21LOG-11 |
| DAT-006 | Data Inventory and Records of Processing | C1.1 | — | PM-18CM-13 | — | — | — | DSP-03DSP-05DSP-06 | GDPR-Art.30.1GDPR-Art.30.2GDPR-Art.5.2 | — | — | — | DSP-06DSP-20DSP-03DSP-05 |
| DAT-007 | Data Minimisation and Purpose Limitation | P3.1P4.1 | — | PT-3PT-2 | — | — | — | DSP-12DSP-07 | GDPR-Art.5.1bGDPR-Art.5.1cGDPR-Art.6.4 | — | — | — | DSP-07DSP-12 |
| DAT-008 | Data Retention and Deletion | P4.2C1.2P4.3 | 8.10 | SI-12MP-6SI-21 | — | — | — | DSP-16DSP-02 | GDPR-Art.5.1eGDPR-Art.17 | LLM09 | ASI06 | GV-1.7-002 | DSP-02DSP-16 |
| DAT-009 | Privacy Notice and Transparency | P1.1P6.7 | — | PT-5PM-20 | — | — | — | — | GDPR-Art.13.1GDPR-Art.13.2GDPR-Art.14.1GDPR-Art.5.1aGDPR-Art.14.3GDPR-Art.12.1GDPR-Art.13.3 | — | — | — | — |
| DAT-010 | Consent Management | P2.1P3.2P6.1 | — | PT-4 | — | EU-AI-Art.60 | — | DSP-08 | GDPR-Art.5.1aGDPR-Art.7 | — | — | MS-2.2-003 | DSP-08 |
| DAT-011 | Data Subject Rights Fulfilment | P5.1P5.2 | — | PM-26 | — | — | — | DSP-11 | GDPR-Art.15GDPR-Art.17GDPR-Art.20GDPR-Art.16GDPR-Art.18GDPR-Art.21.1GDPR-Art.21.2GDPR-Art.22GDPR-Art.12.1GDPR-Art.12.3 | — | — | MG-4.1-006 | DSP-11 |
| DAT-012 | Data Protection by Design and Default | — | — | SA-8SA-17 | — | — | — | DSP-07DSP-08 | GDPR-Art.25.1GDPR-Art.25.2 | — | — | — | DSP-07DSP-08DSP-22 |
| DAT-013 | Data Protection Impact Assessment | — | — | RA-8 | MEASURE 2.10 | EU-AI-Art.26.8EU-AI-Art.27 | — | DSP-09 | GDPR-Art.35.1GDPR-Art.35.7GDPR-Art.35.9GDPR-Art.36 | — | — | — | DSP-09 |
| DAT-015 | Data Transfer Controls | — | 5.14 | — | — | — | — | DSP-10DSP-13 | GDPR-Art.44GDPR-Art.45GDPR-Art.46GDPR-Art.49 | — | — | — | DSP-10DSP-13 |
| DAT-016 | Data Masking and Pseudonymisation | — | 8.118.33 | PM-25SI-19 | — | — | — | DSP-17DSP-15LOG-08 | GDPR-Art.32.1GDPR-Art.5.1f | — | — | MS-2.2-002MS-2.2-004MG-2.2-009 | DSP-15LOG-08DSP-22DSP-17 |
| DAT-017 | Data Leakage Prevention | — | 8.12 | PM-17AC-23AU-13SI-20SI-4(18) | — | — | — | DSP-17 | GDPR-Art.32.1GDPR-Art.5.1f | LLM02 | — | MP-4.1-001MP-4.1-009 | DSP-17 |
| DAT-018 | Data Protection Officer | P8.1 | — | PM-19 | — | — | — | — | GDPR-Art.37GDPR-Art.38GDPR-Art.39 | — | — | — | — |
| DAT-019 | Lawful Basis for Processing | P3.1 | — | PT-2PT-7 | — | — | — | DSP-12 | GDPR-Art.5.1aGDPR-Art.24GDPR-Art.6.1GDPR-Art.9.1GDPR-Art.9.2GDPR-Art.10 | — | — | — | DSP-12 |
| DAT-020 | Accuracy of Personal Data | P5.2P7.1 | — | SI-12PM-22SI-18 | — | — | — | — | GDPR-Art.5.1dGDPR-Art.16 | — | — | — | — |
| DAT-021 | Customer-Managed Encryption Keys | — | — | SC-12 | — | — | — | CEK-08 | — | — | — | — | CEK-08 |
| DAT-022 | Data Residency and Location Transparency | — | — | SA-9(5)CM-12CM-12(1) | — | — | — | DSP-19 | — | — | — | — | DSP-19 |
| DAT-023 | Customer Data Export and Portability | — | — | — | — | — | — | IPY-02IPY-03IPY-01IPY-04 | — | — | — | — | IPY-01IPY-02IPY-03IPY-04 |
| DAT-024 | Special Category and Criminal Conviction Data | P3.2 | — | — | — | — | — | — | GDPR-Art.9.1GDPR-Art.9.2GDPR-Art.10 | — | — | — | — |
| DAT-025 | Automated Decision-Making and Profiling Rights | — | — | — | — | — | — | — | GDPR-Art.22GDPR-Art.13.2GDPR-Art.15 | — | — | — | — |
| DAT-026 | Customer Transition and Switching Execution | — | — | — | — | — | — | — | — | — | — | — | — |
| DAT-027 | Switching Interfaces and Functional Equivalence Support | — | — | — | — | — | — | — | — | — | — | — | — |
| GOV-001 | Information Security Policy | CC5.3CC2.2 | 5.1 | PL-1SC-1SI-1 | — | — | — | GRC-01GRC-03 | GDPR-Art.24 | — | — | — | GRC-03GRC-01 |
| GOV-002 | Information Security Roles and Responsibilities | CC1.3 | 5.2 | PM-2PM-29 | GOVERN 2.1 | — | — | GRC-06 | — | — | — | — | GRC-06 |
| GOV-003 | Management Commitment and Accountability | CC1.2CC1.5 | 5.4 | PM-1 | GOVERN 2.3 | — | — | — | — | — | — | MG-3.2-007 | — |
| GOV-004 | Information Security Programme | CC1.3CC3.1CC5.2 | 5.1 | PM-1PM-3SA-2 | — | — | — | GRC-05 | GDPR-Art.5.1f | — | — | — | GRC-05 |
| GOV-005 | Risk Assessment | CC3.2CC3.4 | 5.1 | RA-3 | — | — | — | GRC-02 | GDPR-Art.32.2 | — | — | — | MDS-06GRC-02 |
| GOV-006 | Risk Management Programme | CC9.1CC3.1 | — | PM-9PM-28RA-1 | GOVERN 1.3MAP 1.5 | — | — | GRC-02 | — | — | — | GV-1.3-005 | GRC-02 |
| GOV-007 | Risk Treatment and Remediation Tracking | CC4.2 | — | PM-4CA-5RA-7 | — | — | — | A&A-06 | — | — | — | MS-2.7-006 | A&A-06 |
| GOV-008 | Fraud Risk Assessment | CC3.3 | 5.3 | PM-12 | — | — | — | — | — | — | — | — | — |
| GOV-009 | Segregation of Duties | CC6.3 | 5.3 | AC-5 | — | — | — | IAM-04 | — | — | — | — | IAM-04IAM-17 |
| GOV-010 | Legal, Regulatory and Contractual Compliance Inventory | — | 5.31 | PL-1 | MAP 4.1 | EU-AI-Art.16.1EU-AI-Art.22EU-AI-Art.54 | — | GRC-07A&A-04 | — | — | — | GV-1.1-001 | A&A-04GRC-07 |
| GOV-011 | Compliance Monitoring and Internal Audit | CC4.1CC4.2 | 5.355.36 | CA-7CA-2 | — | — | — | A&A-03A&A-05 | GDPR-Art.32.1 | — | — | — | A&A-03A&A-05 |
| GOV-012 | Continuous Monitoring Strategy | CC4.1CC4.2CC2.1 | — | PM-31CA-7PM-14SI-6CA-7(4) | — | — | — | A&A-03LOG-01 | — | — | — | MS-2.7-009MG-1.3-002 | A&A-03LOG-01 |
| GOV-013 | Exception and Requirement Determination Register | — | 5.1 | PM-9 | — | — | — | GRC-04CCC-08 | — | — | — | GV-1.6-002 | CCC-08GRC-04 |
| GOV-014 | Asset Inventory | — | 5.9 | PM-5RA-9SA-15(3)CM-8(1) | — | — | — | GRC-05DCS-06 | — | — | — | — | DCS-06GRC-05 |
| GOV-015 | Intellectual Property Rights Management | — | 5.32 | CM-10 | GOVERN 6.1 | EU-AI-Art.53.3 | — | — | — | — | — | GV-6.1-001MP-4.1-002MP-4.1-006MS-2.8-001 | — |
| GOV-016 | Records and Information Governance | — | 5.33 | AU-11 | — | — | — | SEF-09 | GDPR-Art.30.1GDPR-Art.30.2 | — | — | GV-1.5-003 | SEF-09 |
| GOV-018 | Threat Intelligence Programme | CC3.4 | 5.65.7 | PM-15PM-16AU-13RA-10 | — | — | — | GRC-08TVM-10 | — | — | — | MS-3.2-001MG-4.1-001 | TVM-10GRC-08 |
| GOV-019 | Information Security in Project Management | CC5.1 | 5.8 | PL-2 | — | — | — | — | — | — | — | — | — |
| GOV-020 | Independent Security Review | — | 5.35 | CA-1CA-2CA-2(1)CA-7(1) | MEASURE 1.3 | — | — | A&A-03A&A-02 | — | — | — | GV-3.2-001 | A&A-02A&A-03 |
| GOV-021 | Audit and Assurance Policy | — | 8.34 | CA-1 | — | — | — | A&A-01 | — | — | — | — | A&A-01 |
| GOV-022 | Privacy Programme and Data Protection Policy | — | 5.34 | PM-18PM-19PM-23PM-26PM-27PT-1 | — | — | — | DSP-01 | GDPR-Art.24GDPR-Art.5.2 | — | — | — | DSP-01 |
| GOV-023 | Security Measures Performance Measurement | CC4.1CC2.1 | — | PM-6AT-6PM-27 | — | — | — | GRC-02AIS-03DCS-17TVM-12 | — | — | — | MS-2.7-004 | AIS-03TVM-12DCS-17GRC-02 |
| GOV-024 | Documented Operating Procedures | — | 5.37 | PL-2SA-5 | — | — | — | GRC-03 | — | — | — | — | GRC-03 |
| GOV-028 | Regulatory Cooperation and Supervisory Access | — | — | — | — | EU-AI-Art.21 | — | — | — | — | — | — | — |
| HRS-001 | Personnel Security Policy | — | 6.2 | PS-1AT-1 | — | — | — | HRS-09 | — | — | — | — | HRS-09 |
| HRS-002 | Pre-Employment Background Screening | CC1.4 | 6.1 | PS-3PS-2SA-21IA-12IA-12(2)IA-12(3)IA-12(5)PS-3(3) | — | — | — | HRS-01 | — | — | — | — | HRS-01 |
| HRS-003 | Employment Agreements and Security Obligations | — | 6.26.6 | PL-4PS-6 | — | — | — | HRS-07HRS-08HRS-10 | — | — | — | — | HRS-07HRS-08HRS-10 |
| HRS-004 | Security Awareness Training | CC2.2 | 6.3 | AT-2AT-4AT-1AT-2(2)AT-2(3) | GOVERN 2.2 | EU-AI-Art.4 | — | HRS-11HRS-12HRS-13 | — | — | — | — | HRS-11HRS-13HRS-12 |
| HRS-005 | Role-Based Security Training | CC1.4 | 6.3 | AT-3AT-4PM-13 | — | EU-AI-Art.4 | — | HRS-12 | — | — | — | — | HRS-14HRS-12 |
| HRS-006 | Disciplinary Process for Security Violations | CC1.5 | 6.4 | PS-8 | — | — | — | HRS-09 | — | — | — | — | HRS-09 |
| HRS-007 | Termination and Access Revocation | CC6.2 | 5.116.5 | PS-4PS-5PS-7AC-2(13) | — | — | — | HRS-06HRS-05 | — | — | — | — | HRS-05HRS-06 |
| HRS-008 | Remote Working Security | CC6.6 | 6.7 | PS-4PE-17 | — | — | — | HRS-04 | — | — | — | — | HRS-04 |
| HRS-009 | Security Event Reporting Channel | CC2.2 | 6.8 | AT-2 | — | — | A.3.3 | HRS-13 | — | — | — | GV-2.1-005 | HRS-13 |
| HRS-010 | Personnel Roles and Security Responsibilities | — | 5.2 | PS-2PS-9 | — | — | — | HRS-09 | — | — | — | — | HRS-09 |
| HRS-011 | Acceptable Use of Information Assets | CC1.1 | 5.107.7 | PL-4AC-22SC-43AC-20AC-20(1)PL-4(1) | — | — | — | HRS-02HRS-13HRS-03 | — | — | — | GV-6.1-010 | HRS-13HRS-15HRS-02HRS-03 |
| HRS-012 | Insider Threat Programme | CC3.3 | 5.3 | PM-12 | — | — | — | — | — | — | — | — | — |
| HRS-013 | AI Literacy and Role-Based AI Training | — | — | — | GOVERN 2.2MAP 3.4 | EU-AI-Art.4EU-AI-Art.26.2EU-AI-Art.14.2 | A.4.6 | — | — | — | ASI09 | GV-2.1-003MP-3.4-001MP-3.4-002MP-3.4-003MP-3.4-004MS-2.6-001MS-3.3-004MG-4.1-007 | HRS-14 |
| IAM-001 | Access Control Policy | CC6.1CC5.2 | 5.15 | AC-1IA-1 | — | — | — | IAM-01 | — | — | — | — | IAM-01 |
| IAM-002 | Identity Inventory and Unique Identifiers | — | 5.16 | IA-4IA-2IA-2(5)AC-2(9) | — | — | — | IAM-03IAM-12 | — | — | — | — | IAM-03IAM-12 |
| IAM-003 | User Account Lifecycle Management | CC6.2 | 5.18 | AC-2IA-12AC-2(1)AC-2(2)AC-2(3)AC-2(4)IA-13AC-2(11) | — | — | — | IAM-06IAM-07 | — | — | — | — | IAM-07IAM-06 |
| IAM-004 | Access Review and Recertification | — | 5.18 | AC-2AC-6(7)CM-5(5) | — | — | — | IAM-08 | — | — | — | — | IAM-08 |
| IAM-005 | Least Privilege and Need-to-Know Enforcement | CC6.3 | 8.3 | AC-6AC-3 | — | — | — | IAM-05 | — | LLM03 | ASI03 | — | IAM-05AIS-14DSP-23IAM-16IAM-18 |
| IAM-007 | Privileged Access Management | — | 8.28.18 | AC-6AU-14AC-6(1)AC-6(2)AC-6(5)AC-6(9)AC-6(10)SI-4(20)AC-2(7) | — | — | — | IAM-09IAM-10IAM-11 | — | — | — | — | IAM-09IAM-10IAM-11 |
| IAM-008 | Multi-Factor Authentication | CC6.1 | 8.5 | IA-2IA-2(1)IA-2(2)IA-2(8)IA-10IA-2(6) | — | — | — | IAM-13 | — | — | — | — | IAM-13 |
| IAM-009 | Authentication Information Management | — | 5.17 | IA-5IA-6IA-5(1)IA-8(2)IA-5(6) | — | — | — | IAM-02IAM-14 | — | — | — | — | IAM-14IAM-02 |
| IAM-010 | Service Account and Non-Human Identity Management | — | 5.16 | IA-9IA-8IA-3 | — | — | — | IAM-03DCS-09 | — | LLM03 | ASI03ASI07 | — | DCS-09IAM-03 |
| IAM-011 | Remote Access Controls | CC6.6 | 8.5 | AC-17MA-4AC-17(1)AC-17(3)AC-17(4)SC-7(7) | — | — | — | — | — | — | — | — | — |
| IAM-012 | Session Management | — | 8.5 | AC-12AC-11IA-11AC-10SC-10SC-23AC-2(5) | — | — | — | — | — | — | — | — | — |
| IAM-013 | Logon Failure and Account Lockout | — | 8.5 | AC-7 | — | — | — | IAM-13 | — | — | — | — | IAM-13 |
| IAM-014 | Access to Source Code and Development Assets | — | 8.4 | AC-3CM-5(1) | — | — | — | IAM-05CCC-04 | — | — | — | — | CCC-04IAM-05AIS-12 |
| IAM-015 | Role-Based Access Control | CC6.3 | 5.15 | AC-24AC-2(7)AC-6(1) | — | — | — | IAM-15 | — | — | — | — | IAM-15 |
| IAM-016 | Dedicated Administration Systems | — | — | SC-2 | — | — | — | — | — | — | — | — | — |
| INC-001 | Incident Response Plan | — | 5.24 | IR-1IR-8IR-4(1)IR-6(1)IR-7(1) | — | — | — | SEF-01SEF-03SEF-02 | — | — | — | GV-2.1-002GV-6.2-003 | SEF-03SEF-01SEF-02 |
| INC-002 | Incident Detection and Triage | CC7.4CC7.3 | 5.25 | IR-4IR-5 | — | — | — | SEF-06 | — | — | — | — | SEF-06 |
| INC-003 | Incident Classification and Escalation | CC7.3 | — | IR-4IR-6 | — | — | — | SEF-07 | — | — | — | GV-4.3-002 | SEF-07 |
| INC-004 | Incident Containment and Eradication | CC7.4CC7.5 | 5.26 | IR-4IR-9IR-9(3)IR-9(4) | — | — | — | SEF-07 | — | — | — | MG-2.4-003 | SEF-07 |
| INC-005 | Incident Reporting and Regulatory Notification | P6.6P6.5 | — | IR-6IR-6(3) | — | EU-AI-Art.26.4EU-AI-Art.73 | — | SEF-08 | GDPR-Art.33.5GDPR-Art.34.3GDPR-Art.33.1GDPR-Art.33.3GDPR-Art.34.1GDPR-Art.33.2 | — | — | MG-2.3-001MG-4.3-003 | SEF-08 |
| INC-006 | Customer Incident and Cyber Threat Notification | P6.5P6.6 | — | — | — | — | — | SEF-08 | GDPR-Art.34.1GDPR-Art.33.2 | — | — | — | SEF-08 |
| INC-007 | Evidence Collection and Preservation | — | 5.28 | IR-4 | — | — | — | SEF-09 | GDPR-Art.33.5 | — | — | — | SEF-09 |
| INC-008 | Post-Incident Review | CC7.5 | 5.27 | IR-4 | — | — | — | SEF-09 | — | — | — | GV-1.5-002MS-2.7-006MG-4.2-002MG-4.3-001 | SEF-09 |
| INC-009 | Incident Response Training and Testing | — | — | IR-2IR-3CP-3PM-14IR-3(2)IR-9(2) | — | — | — | SEF-04SEF-05 | — | — | — | GV-2.1-003GV-6.2-003MG-4.2-002 | SEF-04SEF-05 |
| INC-010 | External Contact and Communication Points | — | 5.5 | IR-6IR-7 | — | EU-AI-Art.20EU-AI-Art.21EU-AI-Art.5.4 | — | SEF-10 | — | — | — | — | SEF-10 |
| INF-002 | Configuration Baseline and Hardening | CC6.1CC7.1 | 8.9 | CM-2CM-6CM-7CM-1CM-9PL-9SC-34SI-14CM-7(1)CM-2(3)CM-2(2)CM-6(1)SI-4(22) | — | — | — | I&S-01I&S-04CCC-06CCC-07CCC-04 | — | — | — | — | CCC-04CCC-07CCC-06I&S-01I&S-04 |
| INF-003 | System Component Inventory | CC6.1 | — | CM-8CA-9CM-8(3)CM-8(1) | — | — | — | DCS-07 | — | — | — | — | DCS-07 |
| INF-004 | Network Segmentation | — | 8.22 | SC-7SC-32AC-4AC-4(21)SC-7(21) | — | — | — | I&S-05I&S-06 | — | — | — | — | I&S-05I&S-06 |
| INF-005 | Secure Network Architecture and Defence | — | 8.208.218.23 | SC-5SC-7SC-35AC-4CA-3CA-9PL-8SC-7(3)SC-7(4)SC-7(5)SC-7(8)SI-4(1) | — | — | — | I&S-03I&S-08I&S-09 | — | — | — | — | I&S-08I&S-03I&S-09 |
| INF-007 | Vulnerability Management | — | 8.8 | RA-5SI-2RA-5(2)RA-5(5)RA-5(4)RA-5(3)SI-2(3) | — | — | — | TVM-01TVM-03TVM-08TVM-09TVM-11TVM-12 | — | — | — | — | TVM-01TVM-03TVM-08TVM-09TVM-12MDS-02MDS-13TVM-11 |
| INF-008 | Patch Management | — | 8.8 | SI-2SI-2(2) | — | — | — | TVM-05TVM-06 | — | — | — | — | TVM-06TVM-05 |
| INF-009 | Malware and Endpoint Protection | — | 8.78.18.19 | SI-3CM-11SC-18SC-44SI-8CM-7(2)CM-7(5)SI-8(2)SC-7(12)SI-4(23) | — | — | — | UEM-05UEM-09UEM-10TVM-02 | — | — | — | — | TVM-02UEM-09UEM-10UEM-05 |
| INF-012 | Capacity and Performance Management | A1.1 | 8.6 | SC-5AU-4SC-6 | — | — | — | I&S-02 | — | LLM06 | — | MS-2.12-003 | I&S-02 |
| INF-013 | Infrastructure Redundancy | A1.2 | 8.14 | SC-36SI-13CP-7(1)CP-8(2) | — | EU-AI-Art.15.2 | — | BCR-11DCS-18 | — | — | — | — | BCR-11DCS-18MDS-11 |
| INF-014 | Clock Synchronisation | — | 8.17 | SC-45AU-8SC-45(1) | — | — | — | LOG-06 | — | — | — | — | LOG-06 |
| INF-015 | Multi-Tenant and Workload Isolation | — | — | SC-2SC-3SC-4SC-39SC-50SI-16SC-49 | — | — | — | — | — | LLM09 | ASI06 | — | AIS-14 |
| INF-016 | Domain, DNS and Routing Security | — | — | SC-20SC-21SC-22 | — | — | — | — | — | — | — | — | — |
| INF-017 | Managed Endpoint Baseline | CC6.5 | 7.97.107.148.1 | AC-11AC-11(1)AC-19AC-19(5)AC-20(2)CM-7(9)MP-7SC-41SR-12 | — | — | — | UEM-01UEM-02UEM-03UEM-04UEM-06UEM-07UEM-08UEM-11UEM-12UEM-13DCS-02 | — | — | — | — | UEM-03UEM-04UEM-06UEM-07UEM-11UEM-13DCS-02UEM-01UEM-02UEM-08UEM-12 |
| INF-018 | Physical Access and Environmental Protection | CC6.4 | 7.17.27.37.47.57.67.87.117.12 | PE-2PE-3PE-6PE-6(1)PE-8PE-13PE-13(1)PE-13(2)PE-14 | — | — | — | DCS-01DCS-04DCS-08DCS-10LOG-13DCS-11DCS-14DCS-12DCS-13DCS-15DCS-16 | — | — | — | — | DCS-01DCS-04DCS-08DCS-12DCS-13DCS-14DCS-15DCS-16DCS-10DCS-11LOG-13 |
| MON-001 | Audit Log Scope and Generation | — | 8.15 | AU-2AU-3AU-12AU-1AU-3(1) | — | EU-AI-Art.12.1 | — | LOG-07LOG-09LOG-12LOG-13 | — | — | — | — | LOG-07LOG-09LOG-12LOG-13 |
| MON-002 | Log Integrity and Protection | — | — | AU-9AU-5AU-10AU-9(2)AU-9(4)AU-9(3) | — | — | — | LOG-02LOG-04LOG-10 | — | — | ASI10 | — | LOG-02LOG-04LOG-10 |
| MON-003 | Log Retention | — | — | AU-11 | — | EU-AI-Art.16.4EU-AI-Art.26.5EU-AI-Art.19 | — | LOG-02 | — | — | — | — | LOG-02 |
| MON-004 | Centralised Log Management | CC7.1 | — | AU-6CA-7AU-5AU-7AU-6(1)AU-6(3)AU-7(1)SI-4(1)SI-4(16) | — | — | — | LOG-01LOG-03LOG-14 | — | — | — | — | LOG-01LOG-03LOG-14 |
| MON-005 | Security Monitoring and Alerting | CC7.2 | 8.16 | SI-4AU-6RA-10SC-26SI-4(2)SI-4(4)SI-4(5)AC-2(12) | — | — | — | LOG-03LOG-05LOG-14 | — | — | ASI08 | — | LOG-05LOG-15LOG-16LOG-03LOG-14 |
| MON-008 | Detection Content Lifecycle | — | 8.16 | SI-4AU-6 | — | — | — | LOG-05 | — | — | — | — | LOG-05 |
| MON-009 | Log Access Control and Sensitive Data in Logs | — | — | AU-9(4)AU-9 | — | — | — | LOG-04LOG-08 | — | LLM02 | — | — | LOG-04LOG-08 |
| MON-010 | Availability and SLO Monitoring with Status Communication | A1.2CC7.2 | 8.16 | — | — | — | — | — | — | — | — | — | — |
| VND-001 | Vendor Risk Assessment and Due Diligence | CC9.2 | 5.195.21 | SR-6SR-2SR-3PM-30SR-1SR-9SA-1SR-5SR-2(1)RA-3(1)SA-9(1) | GOVERN 6.1 | — | — | STA-10STA-16STA-01STA-08STA-09 | GDPR-Art.28.1 | — | — | GV-6.1-005GV-6.1-007MG-3.1-002 | STA-01STA-08STA-10STA-16STA-09 |
| VND-002 | Security Requirements in Vendor Contracts | P6.4 | 5.208.30 | SR-3SR-11CA-3SA-9SR-5SR-8CP-7(3)SA-4(1)SA-4(2)SA-4(9)SA-9(2) | — | EU-AI-Art.25.2 | — | STA-11STA-12 | GDPR-Art.28.3GDPR-Art.33.2 | — | — | GV-6.1-004GV-6.1-006GV-6.2-007 | STA-11STA-12 |
| VND-003 | Sub-Processor Management | — | — | — | — | — | A.10.2 | DSP-13DSP-14 | GDPR-Art.28.2GDPR-Art.29 | — | — | — | DSP-13DSP-14 |
| VND-004 | Cloud Service Provider Security Management | — | 5.23 | SR-2AU-16SA-9CA-2(3) | GOVERN 6.1 | — | — | STA-11IPY-04 | — | — | — | — | IPY-04STA-11 |
| VND-006 | Vendor Monitoring and Performance Review | CC9.2 | 5.22 | SR-6SA-9CA-2(3) | MANAGE 3.1 | — | — | STA-12STA-13STA-14STA-15 | — | — | — | GV-6.1-003GV-6.1-009GV-6.2-002GV-6.2-004MP-5.2-002 | STA-14STA-12STA-13STA-15 |
| VND-007 | Vendor Access Controls | CC9.2 | 5.195.20 | SR-7MA-5 | — | — | — | UEM-14 | GDPR-Art.29 | — | — | — | UEM-14 |
| VND-008 | Vendor Offboarding | — | 5.225.23 | — | — | — | — | DSP-16DSP-02 | GDPR-Art.28.3 | — | — | — | DSP-02DSP-16 |
| VND-010 | Third-Party Data Disclosure Controls | P6.2P6.4P6.1P6.3 | — | AC-21PM-21 | — | — | — | DSP-10 | GDPR-Art.5.1bGDPR-Art.44 | — | — | — | DSP-10 |
| VND-011 | Shared Responsibility Model and Customer Security Communication | CC2.3 | — | — | — | — | — | STA-02STA-03STA-04STA-05STA-06STA-07CCC-05 | — | — | — | MG-4.1-005 | CCC-05STA-04STA-06STA-07STA-02STA-03STA-05 |
| VND-012 | Government and Law Enforcement Data Request Handling | — | — | — | — | — | — | DSP-18 | GDPR-Art.29 | — | — | — | DSP-18 |
| VND-013 | Regulatory and Exit Terms in Customer Agreements | — | — | — | — | — | — | — | — | — | — | — | — |
| VND-014 | Customer and Regulator Audit and Inspection Rights | — | — | — | — | — | — | — | — | — | — | — | — |
| VND-015 | Subcontractor Disclosure and Change Approval | — | — | — | — | — | — | — | — | — | — | — | — |