Dictionary
Every question family the register recognises
38 families in nine groups. Each carries its trigger phrases, the anchor clause per framework, the evidence an assessor expects and an example question that places itself.
- Access provisioning and reviewAccess and identity
- Assessing your own suppliersThird parties and subprocessors
- Background checksPeople and HR security
- Backup and disaster recoveryIncident and continuity
- Breach historyNeeds a person
- Business continuity planIncident and continuity
- Cardholder data and PCI DSSData protection and encryption
- Confidentiality terms and leaversPeople and HR security
- Customer referencesNeeds a person
- Cyber insuranceNeeds a person
- Data location and transfersData protection and encryption
- Data processing agreementPrivacy and data subject rights
- Data retention and secure deletionData protection and encryption
- Data subject requestsPrivacy and data subject rights
- Encryption at restData protection and encryption
- Encryption in transitData protection and encryption
- Financial statementsNeeds a person
- Health information and business associate termsPrivacy and data subject rights
- Incident response planIncident and continuity
- Independent audit and certificationGovernance and policy
- Information security policyGovernance and policy
- Lawful basis, consent and privacy noticePrivacy and data subject rights
- Litigation and regulatory actionNeeds a person
- Logging and monitoringOperations, logging and vulnerability
- Malware protection and endpointsOperations, logging and vulnerability
- Multi-factor authenticationAccess and identity
- Network security and segmentationOperations, logging and vulnerability
- Notifying the customer of an incidentIncident and continuity
- Password policyAccess and identity
- Penetration testingOperations, logging and vulnerability
- Physical securityOperations, logging and vulnerability
- Privileged accessAccess and identity
- Risk assessmentGovernance and policy
- Secure development and changeOperations, logging and vulnerability
- Security awareness trainingPeople and HR security
- Security roles and a named security leadGovernance and policy
- Subcontractors and subprocessorsThird parties and subprocessors
- Vulnerability and patch managementOperations, logging and vulnerability