๐ผ 36a change management โinformation security is addressed as part of the change management process and the information asset inventory is updated; | | 7 | 8 | |
๐ผ 36b configuration management โthe configuration of information assets minimises vulnerabilities and is defined, assessed, registered, maintained, including when new vulnerabilities and threats are discovered, and applied consistently; | | 1 | 1 | |
๐ผ 36c deployment and environment management โdevelopment, test and production environments are appropriately segregated and enforce segregation of duties; | | 2 | 2 | |
๐ผ 36d access management controls โonly authorised users, software and hardware are able to access information assets (refer to Attachment B for further guidance); | | 13 | 13 | |
๐ผ 36e hardware and software asset controls โappropriate authorisation to prevent security compromises from unauthorised hardware and software assets; | | 15 | 15 | |
๐ผ 36f network design โ to ensure authorised network traffic flows and to reduce the impact of security compromises; | | 28 | 29 | |
๐ผ 36g vulnerability management controls โ which identify and address information security vulnerabilities in a timely manner; | | 11 | 11 | |
๐ผ 36h patch management controls โ to manage the assessment and application of patches and other updates that address known vulnerabilities in a timely manner; | | 5 | 5 | |
๐ผ 36i service level management mechanisms โ to monitor, manage and align information security with business objectives; | | 2 | 2 | |
๐ผ 36j monitoring controls โ for timely detection of compromises to information security; | | 9 | 11 | |
๐ผ 36k response controls โ to manage information security incidents and feedback mechanisms to address control deficiencies; | | 10 | 10 | |
๐ผ 36l capacity and performance management controls โ to ensure that availability is not compromised by current or projected business volumes; | | | | |
๐ผ 36m service provider management controls โ to ensure that a regulated entityโs information security requirements are met. | | | | |