Regulatory Coverage Overview
Consolidated view of European framework coverage and control implementation
European Framework Coverage
Control Implementation Status
| Control reference | Control description | Framework | Status |
|---|---|---|---|
| GDPR-32 | Security of processing Implement appropriate technical and organizational measures to ensure security of processing | GDPR | Covered |
| GDPR-25 | Data protection by design Implement data protection principles and safeguards into processing activities | GDPR | Covered |
| GDPR-33 | Breach notification Notify supervisory authority of personal data breaches within 72 hours | GDPR | Covered |
| GDPR-35 | Data protection impact assessment Conduct DPIA for processing operations likely to result in high risk | GDPR | Partial coverage |
| GDPR-30 | Records of processing activities Maintain records of all processing activities under controller responsibility | GDPR | Covered |
| GDPR-44 | Cross-border data transfers Ensure appropriate safeguards for transfers of personal data to third countries | GDPR | Partial coverage |
| NIS2-7.1 | Risk management measures Implement policies on risk analysis and information system security | NIS2 | Partial coverage |
| NIS2-8.3 | Incident handling Establish procedures to handle and respond to cybersecurity incidents | NIS2 | Partial coverage |
| NIS2-21.1 | Supply chain security Address security in supplier relationships and supply chain | NIS2 | Covered |
| NIS2-21.3 | Business continuity Implement business continuity and disaster recovery capabilities | NIS2 | Covered |
| NIS2-21.5 | Security awareness training Provide cybersecurity training and awareness programs for personnel | NIS2 | Partial coverage |
| DORA-9 | ICT risk management Establish comprehensive ICT risk management framework covering identification and protection | DORA | Covered |
| DORA-11 | Incident reporting Implement classification and reporting mechanisms for major ICT-related incidents | DORA | Covered |
| DORA-24 | Third-party risk management Manage ICT third-party risk through due diligence and ongoing monitoring | DORA | Partial coverage |
| DORA-25 | Testing and resilience Conduct regular testing of ICT systems, controls, and recovery capabilities | DORA | Covered |
| DORA-28 | ICT service monitoring Monitor performance and availability of critical ICT services | DORA | Covered |
| ISO-A.8.2 | Information classification Classify information in terms of legal requirements, value, and criticality | ISO 27001 | Covered |
| ISO-A.12.1 | Operational procedures Document and maintain operating procedures for information processing facilities | ISO 27001 | Covered |
| ISO-A.18.1 | Compliance with legal requirements Identify and comply with applicable legislation and contractual requirements | ISO 27001 | Covered |
| ISO-A.9.2 | User access provisioning Implement formal user access provisioning process for all system types | ISO 27001 | Covered |
| ISO-A.12.6 | Technical vulnerability management Obtain timely information about technical vulnerabilities and take action | ISO 27001 | Partial coverage |
| ISO-A.17.1 | Business continuity planning Plan, implement, and maintain information security continuity | ISO 27001 | Covered |
| ISO-A.8.10 | Information deletion Delete information stored in systems, devices or media when no longer required | ISO 27002 | Covered |
| ISO-A.8.24 | Data loss prevention Apply data loss prevention measures to detect and prevent unauthorized disclosure | ISO 27002 | Partial coverage |
| ISO-A.5.23 | Information security in cloud services Establish processes for acquisition, use, management and exit from cloud services | ISO 27002 | Covered |
| ISO-A.8.9 | Configuration management Establish and document configuration management for networks, systems and applications | ISO 27002 | Covered |
| CRA-10 | Security by design Design and develop products with cybersecurity as integral component | CRA | Partial coverage |
| CRA-15 | Vulnerability handling Establish process to address and remediate vulnerabilities throughout product lifecycle | CRA | Coverage gap identified |
| CRA-11.1 | Secure development Apply secure coding practices and vulnerability testing during development | CRA | Partial coverage |
| CRA-11.2 | Security documentation Provide security documentation including instructions for secure use and configuration | CRA | Covered |
| CRA-20 | Security update management Implement mechanisms for secure delivery and installation of security updates | CRA | Partial coverage |