Skip to content

Latest commit

 

History

History
104 lines (73 loc) · 2.7 KB

ss584.adoc

File metadata and controls

104 lines (73 loc) · 2.7 KB

Management oversight of information security

General

The Cloud Service Provider’s management and board of directors shall be responsible for the following requirements and audit procedures.

The Cloud Service Provider’s management and board of directors shall be responsible for the following requirements and audit procedures

Level 1 requirements and audit procedures

The Cloud Service Provider’s management and board of directors shall

  1. Managing information security risks related to people, process, technology and governance.

  2. Oversight of the effective implementation of the technology controls.

  3. Oversight of risk management practices.

  1. Determine that the responsibilities of management and board of directors in managing and overseeing information security risks are documented and communicated.

  2. Inspect documents such as meeting minutes and committee charter to identify the participants involved in the meeting or committee, their respective job functions and the reporting relationship.

  3. Determine whether the management and board of directors meet regularly, at an appropriate and monitored frequency.

  4. Determine whether the information security function is headed by a Chief Information Security Officer (CISO) or similar function.

Level 2 requirements and audit procedures

The requirements and audit procedures are the same as those in Level 1.

Level 3 requirements and audit procedures

The requirements are the same as those in Level 2.

The audit procedures are those in Level 1 and the following:

  1. Verify risks have been reviewed, understood, and addressed (i.e. including a cost benefit analysis) by management and the board.

I recommend this.

This is the object of the recommendation:

Object Value

Mission

Accomplished

As for the measurement targets,

The measurement target shall be measured as:

\$r/1 = 0\$
  1. We take a measurement

  2. The measurement is consistent with the formula above

    1. If the measurement is not consistent with the formula above, then the verification has failed