graphgrc

SCF - CPL-01.2 - Compliance Scope

Mechanisms exist to document and validate the scope of cybersecurity & data privacy controls that are determined to meet statutory, regulatory and/or contractual compliance obligations.

Mapped framework controls

ISO 27001

Control questions

Does the organization document and validate the scope of cybersecurity & data privacy controls that are determined to meet statutory, regulatory and/or contractual compliance obligations?