
Objective: To avoid breaches of any law, statutory, regulatory or contractual obligations, and of any security requirements.
Control
All relevant statutory, regulatory and contractual requirements and the organization’s approach to meet these requirements shall be explicitly defined, documented, and kept up to date for each information system and the organization.
Control
Appropriate procedures shall be implemented to ensure compliance with legislative, regulatory, and contractual requirements on the use of material in respect of which there may be intellectual property rights and on the use of proprietary software products.
Control
Important records shall be protected from loss, destruction and falsification, in accordance with statutory, regulatory, contractual, and business requirements.
Control
Data protection and privacy shall be ensured as required in relevant legislation, regulations, and, if applicable, contractual clauses.
Control
Users shall be deterred from using information processing facilities for unauthorized purposes.
Control
Cryptographic controls shall be used in compliance with all relevant agreements, laws, and regulations.
© Copyright Castleforce 2007-2012. Web design by Theme Group