BSI C5 (Germany): the evidence behind every control
121 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
C5: Asset Management
AM-01Asset Inventory moderateAM-02Acceptable Use and Safe Handling of Assets Policy easyAM-03Commissioning of Hardware moderateAM-04Decommissioning of Hardware moderateAM-05Commitment to Permissible Use, Safe Handling and Return of Assets hardAM-06Asset Classification and Labelling moderateC5: Business Continuity Management
BCM-01Top management responsibility hardBCM-02Business impact analysis policies and instructions hardBCM-03Planning business continuity hardBCM-04Verification, updating and testing of the business continuity hardC5: Compliance
COM-01Identification of applicable legal, regulatory, self-imposed or contractual requirements hardCOM-02Policy for planning and conducting audits moderateCOM-03Internal audits of the information security management system hardCOM-04Information on information security performance and management assessment of the ISMS hardC5: Communication Security
COS-01Technical safeguards easyCOS-02Security requirements for connections in the Cloud Service Provider's network moderateCOS-03Monitoring of connections in the Cloud Service Provider's network hardCOS-04Cross-network access hardCOS-05Networks for administration easyCOS-06Segregation of data traffic in jointly used network environments moderateCOS-07Documentation of the network topology hardCOS-08Policies for data transmission hardC5: Cryptography and Key Management
CRY-01Policy for the use of encryption procedures and key management hardCRY-02Encryption of data for transmission (transport encryption) easyCRY-03Encryption of sensitive data for storage hardCRY-04Secure key management hardC5: Procurement, Development and Modification of Information Systems
DEV-01Policies for the development/procurement of information systems hardDEV-02Outsourcing of the development hardDEV-03Policies for changes to information systems hardDEV-04Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools hardDEV-05Risk assessment, categorisation and prioritisation of changes hardDEV-06Testing changes moderateDEV-07Logging of changes easyDEV-08Version Control hardDEV-09Approvals for provision in the production environment moderateDEV-10Separation of environments hardC5: Human Resources
HR-01Verification of qualification and trustworthiness moderateHR-02Employment terms and conditions hardHR-03Security training and awareness programme easyHR-04Disciplinary measures hardHR-05Responsibilities in the event of termination or change of employment moderateHR-06Confidentiality agreements hardC5: Identity and Access Management
IDM-01Policy for user accounts and access rights hardIDM-02Granting and change of user accounts and access rights easyIDM-03Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins moderateIDM-04Withdraw or adjust access rights as the task area changes moderateIDM-05Regular review of access rights moderateIDM-06Privileged access rights moderateIDM-07Access to cloud customer data moderateIDM-08Confidentiality of authentication information hardIDM-09Authentication mechanisms hardC5: Dealing with Investigation Requests from Government Agencies
INQ-01Legal Assessment of Investigative Inquiries moderateINQ-02Informing Cloud Customers about Investigation Requests moderateINQ-03Conditions for Access to or Disclosure of Data in Investigation Requests moderateINQ-04Limiting Access to or Disclosure of Data in Investigation Requests hardC5: Organisation of Information Security
OIS-01Information Security Management System (ISMS) hardOIS-02Information Security Policy hardOIS-03Interfaces and Dependencies hardOIS-04Segregation of Duties moderateOIS-05Contact with Relevant Government Agencies and Interest Groups moderateOIS-06Risk Management Policy moderateOIS-07Application of the Risk Management Policy hardC5: Operations
OPS-01Capacity Management - Planning hardOPS-02Capacity Management - Monitoring moderateOPS-03Capacity Management - Controlling of Resources hardOPS-04Protection Against Malware - Concept moderateOPS-05Protection Against Malware - Implementation easyOPS-06Data Backup and Recovery - Concept hardOPS-07Data Backup and Recovery - Monitoring easyOPS-08Data Backup and Recovery - Regular Testing moderateOPS-09Data Backup and Recovery - Storage moderateOPS-10Logging and Monitoring - Concept moderateOPS-11Logging and Monitoring - Metadata Management Concept hardOPS-12Logging and Monitoring - Access, Storage and Deletion easyOPS-13Logging and Monitoring - Identification of Events easyOPS-14Logging and Monitoring - Storage of the Logging Data easyOPS-15Logging and Monitoring - Accountability moderateOPS-16Logging and Monitoring - Configuration easyOPS-17Logging and Monitoring - Availability of the Monitoring Software easyOPS-18Managing Vulnerabilities, Malfunctions and Errors - Concept hardOPS-19Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests hardOPS-20Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures hardOPS-21Involvement of Cloud Customers in the Event of Incidents hardOPS-22Testing and Documentation of known Vulnerabilities easyOPS-23Managing Vulnerabilities, Malfunctions and Errors - System Hardening easyOPS-24Separation of Datasets in the Cloud Infrastructure easyC5: Portability and Interoperability
PI-01Documentation and safety of input and output interfaces moderatePI-02Contractual agreements for the provision of data hardPI-03Secure deletion of data hardC5: Physical Security
PS-01Physical Security and Environmental Control Requirements hardPS-02Redundancy model hardPS-03Perimeter Protection hardPS-04Physical site access control easyPS-05Protection from fire and smoke hardPS-06Protection against interruptions caused by power failures and other such risks hardPS-07Surveillance of operational and environmental parameters easyC5: Product Safety and Security
PSS-01Guidelines and Recommendations for Cloud Customers moderatePSS-02Identification of Vulnerabilities of the Cloud Service easyPSS-03Online Register of Known Vulnerabilities hardPSS-04Error handling and Logging Mechanisms easyPSS-05Authentication Mechanisms moderatePSS-06Session Management moderatePSS-07Confidentiality of Authentication Information moderatePSS-08Roles and Rights Concept hardPSS-09Authorisation Mechanisms hardPSS-10Software Defined Networking easyPSS-11Images for Virtual Machines and Containers hardPSS-12Locations of Data Processing and Storage moderateC5: Security Incident Management
SIM-01Policy for security incident management hardSIM-02Processing of security incidents moderateSIM-03Documentation and reporting of security incidents hardSIM-04Duty of the users to report security incidents to a central body hardSIM-05Evaluation and learning process hardC5: Security Policies and Instructions
SP-01Documentation, communication and provision of policies and instructions moderateSP-02Review and Approval of Policies and Instructions hardSP-03Exceptions from Existing Policies and Instructions hardC5: Control and Monitoring of Service Providers and Suppliers
SSO-01Policies and instructions for controlling and monitoring third parties moderateSSO-02Risk assessment of service providers and suppliers hardSSO-03Directory of service providers and suppliers moderateSSO-04Monitoring of compliance with requirements moderateSSO-05Exit strategy for the receipt of benefits hard