Print This Page
Clear Desk Policy
A corporate policy which ensures that sensitive information is not left out in the open for viewing or theft by unauthorized users.
Cloud Controls Matrix (CCM) Data
IS-17 | Information Security | Workspace
Control Specification +-
Policies and procedures shall be established for clearing visible documents containing sensitive data when a workspace is unattended and enforcement of workstation session logout for a period of inactivity.
Architectural Relevance +-
Physical | Network | Compute | App | Data |
---|
True
| False
| False
| False
| True
|
Corp Gov Relevance +-
Cloud Service Delivery Model Applicability +-
SaaS | PaaS | IaaS |
---|
True
| True
| True
|
Supplier Relationship +-
Service Provider | Tenant / Consumer |
---|
True
| True
|
Scope Applicability +-
COBIT 4.1 | HIPAA / HITECH Act | ISO/IEC 27001-2005 |
---|
|
| Clause 5.2.2
A.8.2.2
A.9.1.5
A.11.3.1
A.11.3.2
A.11.3.3
|
NIST SP800-53 R3 | FedRAMP (Final 2012) Low Impact | FedRAMP (Final 2012) Moderate Impact | PCI DSS v2.0 |
---|
AC-11
MP-2
MP-3
MP-4
| NIST SP 800-53 R3 MP-1
NIST SP 800-53 R3 MP-2
| NIST SP 800-53 R3 AC-11
NIST SP 800-53 R3 MP-1
NIST SP 800-53 R3 MP-2
NIST SP 800-53 R3 MP-2 (1)
NIST SP 800-53 R3 MP-3
NIST SP 800-53 R3 MP-4
NIST SP 800-53 R3 MP-4 (1)
|
|
BITS Shared Assessments SIG v6.0 | BITS Shared Assessments SIG v5.0 | GAPP (Aug 2009) |
---|
E.4
| E.1
| 8.2.3
|
Jericho Forum | NERC CIP |
---|
Commandment #5 Commandment #6
Commandment #7
Commandment #11
|
|
Consensus Assessments Initiative Questionnaire (CAIQ) Data
Do your data management policies and procedures address tenant and service level conflicts of interests?
Compliance Mapping +-
COBIT | HIPAA | ISO27001 | SP800_53 |
---|
|
| Clause 5.2.2
A.8.2.2
A.9.1.5
A.11.3.1
A.11.3.2
A.11.3.3
| NIST SP800-53 R3 AC-11
NIST SP800-53 R3 MP-2
NIST SP800-53 R3 MP-3
NIST SP800-53 R3 MP-4
|
FedRAMP | PCI_DSS | BITS | GAPP |
---|
NIST SP800-53 R3 AC-11
NIST SP800-53 R3 AC-11 (1)
NIST SP800-53 R3 MP-2
NIST SP800-53 R3 MP-2 (1)
NIST SP800-53 R3 MP-3
NIST SP800-53 R3 MP-4
NIST SP800-53 R3 MP-4 (1)
|
| AUP v5.0 E.1 SIG v6.0: E.4
| GAPP Ref 8.2.3
|
Model Applicability +-
SaaS | PaaS | IaaS |
---|
True
| True
| True
|
Scope Applicability +-