Policy Register

Database security standard

How databases are hardened, how access to them is restricted and logged, and how production data is masked before it reaches test.

How the register reads it

Also calledDB security standard, data masking
FamilyOperations and technology
Document typeStandard. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the secure development policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe head of engineering or the CTO.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, secure development policy, is).
TemplateDatabase security policy.

Which standards require it, and what each expects it to contain

3 requiring clauses, 1 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 8.3 Information access restriction

Restrict access to information and assets per the access control policy.

What the ISO 27002 guidance expects the document to say: Requires access to information and other associated assets to be restricted in accordance with the established topic specific policy on access control.

Evidence an auditor accepts: Evidence access to information is restricted per the access control policy, sampled at the system and data level rather than only at the network level; configuration of the restriction mechanisms, such as application roles, database permissions, file share permissions and cloud storage policies; evidence of restriction on functions as well as data, including read against write against delete and export
Common gap: infrequent or missing access reviews
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.11 Data masking

Use data masking in line with access policy, business need and applicable law.

What the ISO 27002 guidance expects the document to say: Requires data masking to be used in accordance with the topic specific policy on access control, other related topic specific policies and business requirements, taking applicable legislation into account. Supporting material notes the common case of protecting sensitive data used for testing or development.

Evidence an auditor accepts: The rules on masking, pseudonymisation and anonymisation, tied to the access control policy and to applicable legislation; identification of the environments and use cases where masking applies, such as development, testing, training, analytics and support; technical evidence of the masking applied, including the technique and evidence it resists re-identification
Common gap: Masking applied inconsistently across data stores
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.33 Test information

Select, protect and manage test information appropriately.

What the ISO 27002 guidance expects the document to say: Requires test information to be appropriately selected, protected and managed.

Evidence an auditor accepts: Rules on selecting test information, showing preference for synthetic or masked data over production copies; authorisation records where production information is used for testing, including who approved and for how long; evidence of protection of test information equivalent to its classification, including access control and deletion after use
Common gap: Treating test data like production data without classification
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Cryptography policy · Documented operating procedures