Operations and technology
How the technology is run: cryptography, backup, logging, change, vulnerabilities, configuration, endpoints, networks, cloud and the rules written into the software the organisation builds.
Policy types in this family
26- API security standard standard
The authentication, authorisation, rate limiting, input validation and logging rules every interface the organisation exposes must meet. Required by ISO 27001; owner the head of engineering or the CTO. - Backup policy policy
What is backed up, how often, where the copies are kept, how they are protected and how restoration is tested. Required by ISO 27001, ISO 27701, DORA, NIS2; owner the head of IT operations. - Bring your own device policy policy
The conditions under which a personally owned device may reach organisational data, and what the organisation may do to it. Required by ISO 27001; owner the head of IT operations. - Certificate management policy policy
How certificates are requested, issued, inventoried, renewed before expiry and revoked, and which authorities are trusted. Required by ISO 27001; owner the head of IT operations. - Change management procedure procedure
How changes to systems are requested, assessed, approved, tested, deployed and rolled back, and who may approve an emergency change. Required by ISO 27001, DORA; owner the head of IT operations. - Cloud security policy policy
How cloud services are selected, configured, used and left: the shared responsibility, the data location, the exit, the accounts. Required by ISO 27001, DORA; owner the information security lead (CISO or ISMS manager). - Configuration management policy policy
The secure baseline for each class of system, how it is applied, checked for drift and changed. Required by ISO 27001, NIS2; owner the head of IT operations. - Container and orchestration security standard standard
The rules for building, scanning, signing and running container images and for the platform that schedules them. Required by ISO 27001; owner the head of engineering or the CTO. - Cryptography policy policy
Where encryption is required, which algorithms and key lengths are allowed, and how keys are managed through their life. Required by ISO 27001, ISO 27701, DORA, NIS2; owner the information security lead (CISO or ISMS manager). - Database security standard standard
How databases are hardened, how access to them is restricted and logged, and how production data is masked before it reaches test. Required by ISO 27001; owner the head of engineering or the CTO. - Documented operating procedures procedure
The step-by-step instructions for operating each system and process, available to the people who run them. Required by ISO 27001, DORA; owner the head of IT operations. - Email and messaging policy policy
How email and messaging may be used, what may be sent by them, how they are protected and filtered, and how long they are kept. Required by ISO 27001; owner the head of IT operations. - Endpoint device policy policy
How laptops, desktops and other user devices are built, protected against malware, encrypted, monitored and recovered. Required by ISO 27001, ISO 27701, NIS2; owner the head of IT operations. - Environmental security standard standard
How equipment is protected from fire, water, power failure and other environmental threats, and how the utilities that support it are kept. Required by ISO 27001; owner facilities or office management, with the information security lead. - Key management policy policy
How keys are generated, stored, distributed, rotated, revoked and destroyed, and who holds custody. Required by ISO 27001; owner the head of IT operations. - Logging and monitoring standard standard
Which events are logged on which systems, how long logs are kept, who may read and alter them, and what is monitored and alerted. Required by ISO 27001, ISO 27701, ISO 42001, DORA; owner the head of IT operations. - Mobile device policy policy
How phones and tablets that reach organisational data are enrolled, protected, wiped and separated from personal use. Required by ISO 27001; owner the head of IT operations. - Network security policy policy
How networks are designed, segmented, filtered and monitored, which services are exposed and how remote connections are made. Required by ISO 27001, NIS2; owner the head of IT operations. - Patch management policy policy
The deadlines for applying security updates by severity and system class, the testing before them and the exceptions process. Required by ISO 27001; owner the head of IT operations. - Physical security policy policy
How premises and secure areas are defined, entered, monitored and protected, including visitors, deliveries and working in secure areas. Required by ISO 27001, NIS2; owner facilities or office management, with the information security lead. - Secure development policy policy
The rules for building and changing software: requirements, design, coding, testing, environments and the review before release. Required by ISO 27001, ISO 27701, NIS2; owner the head of engineering or the CTO. - Security testing and penetration testing policy policy
How and how often systems are tested by attack, by whom, under what rules of engagement, and how findings are tracked to closure. Required by ISO 27001, DORA, NIS2; owner the information security lead (CISO or ISMS manager). - Threat intelligence procedure procedure
How information about threats is collected, analysed and turned into changes to controls, and who receives it. Required by ISO 27001; owner the information security lead (CISO or ISMS manager). - Vulnerability management policy policy
How vulnerabilities are found, scored, fixed within a deadline set by severity, tracked and, where reported from outside, received. Required by ISO 27001, DORA, NIS2; owner the head of IT operations. - Wireless network standard standard
How wireless networks are authenticated, encrypted, separated from the wired estate and offered to guests. Required by ISO 27001; owner the head of IT operations. - Zero trust architecture standard standard
The architectural principles for verifying every request explicitly, granting least privilege and assuming breach, and where they are applied. Required by ISO 27001; owner the head of engineering or the CTO.
What reaches this family
| ISO 27001 | Expects: backup policy, change management procedure, cloud security policy, configuration management policy, cryptography policy, documented operating procedures, endpoint device policy, logging and monitoring standard, network security policy, physical security policy, secure development policy, vulnerability management policy. Requires, by clause: ISO 27001 8.26, ISO 27001 8.13, ISO 27001 8.1, ISO 27001 6.7, ISO 27001 8.24, ISO 27001 8.32, ISO 27001 5.23, ISO 27001 8.9, ISO 27001 8.3, ISO 27001 8.11, ISO 27001 8.33, ISO 27001 5.37, ISO 27001 5.14, ISO 27001 8.23, ISO 27001 8.7, ISO 27001 7.5, ISO 27001 8.15, ISO 27001 8.16, ISO 27001 8.20, ISO 27001 8.21, ISO 27001 8.22, ISO 27001 8.8, ISO 27001 7.1, ISO 27001 7.2, ISO 27001 7.4, ISO 27001 8.25, ISO 27001 8.28, ISO 27001 8.29, ISO 27001 5.7, ISO 27001 8.27. |
|---|---|
| ISO 27701 | Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.3.24, ISO 27701 A.3.26, ISO 27701 A.3.22, ISO 27701 A.3.25, ISO 27701 A.3.27. |
| ISO 42001 | Expects: no document of this family on its gap list. Requires, by clause: ISO 42001 A.6.2.8. |
| DORA | Expects: backup policy, logging and monitoring standard, security testing and penetration testing policy. Requires, by clause: DORA Art. 12, DORA Art. 9, DORA Art. 28, DORA Art. 10, DORA Art. 24, DORA Art. 25. |
| NIS2 | Expects: backup policy, cryptography policy, secure development policy, vulnerability management policy. Requires, by clause: NIS2 Art. 21(2)(c), NIS2 Art. 21(2)(e), NIS2 Art. 21(2)(h), NIS2 Art. 21(2)(g), NIS2 Art. 21(2)(j), NIS2 Art. 21(2)(a), NIS2 Art. 21(2)(f). |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register