| 29 |
Cybersecurity strategy review |
ECC-2:2024 |
ECC 1-1-3 |
✅* |
— |
— |
— |
"At planned intervals" |
| 30 |
Cybersecurity policies & procedures review |
ECC-2:2024 |
ECC 1-3-4 |
✅* |
— |
— |
— |
"At planned intervals" |
| 31 |
Cybersecurity roles & responsibilities review |
ECC-2:2024 |
ECC 1-4-2 |
✅* |
— |
— |
— |
"At planned intervals" |
| 32 |
Cybersecurity risk management methodology review |
ECC-2:2024 |
ECC 1-5-4 |
✅* |
— |
— |
— |
"At planned intervals" |
| 33 |
Cybersecurity in IT project management review |
ECC-2:2024 |
ECC 1-6-4 |
✅* |
— |
— |
— |
"Periodically" |
| 34 |
Internal cybersecurity review / self-assessment |
ECC-2:2024 |
ECC 1-8-1 |
✅* |
— |
— |
— |
"Periodically" |
| 35 |
Independent cybersecurity audit |
ECC-2:2024 |
ECC 1-8-2 |
— |
— |
— |
✅* |
"Independently" — no interval stated |
| 36 |
HR cybersecurity requirements review |
ECC-2:2024 |
ECC 1-9-6 |
✅* |
— |
— |
— |
"Periodically" |
| 37 |
Cybersecurity awareness program delivery |
ECC-2:2024 |
ECC 1-10-1/1-10-2 |
✅* |
✅* |
✅* |
✅* |
"Periodically, through multiple channels" |
| 38 |
Specialized cybersecurity training (CS staff, dev, exec) |
ECC-2:2024 |
ECC 1-10-4 |
✅* |
— |
— |
— |
"Periodically" |
| 39 |
Awareness program effectiveness review |
ECC-2:2024 |
ECC 1-10-5 |
— |
— |
— |
✅* |
"Periodically" |
| 40 |
Asset inventory & management review |
ECC-2:2024 |
ECC 2-1-6 |
✅* |
— |
— |
— |
"Periodically" |
| 41 |
User identities & access rights review |
ECC-2:2024 |
ECC 2-2-3.5 |
✅* |
✅* |
✅* |
✅* |
"Periodic review" — no interval |
| 42 |
IAM requirements review |
ECC-2:2024 |
ECC 2-2-4 |
✅* |
— |
— |
— |
"Periodically" |
| 43 |
Information systems & processing facilities protection review |
ECC-2:2024 |
ECC 2-3-4 |
✅* |
— |
— |
— |
"Periodically" |
| 44 |
Email protection review |
ECC-2:2024 |
ECC 2-4-4 |
✅* |
— |
— |
— |
"Periodically" |
| 45 |
Network security management review |
ECC-2:2024 |
ECC 2-5-4 |
✅* |
— |
— |
— |
"Periodically" |
| 46 |
Mobile device & BYOD security review |
ECC-2:2024 |
ECC 2-6-4 |
✅* |
— |
— |
— |
"Periodically" |
| 47 |
Data & information protection review |
ECC-2:2024 |
ECC 2-7-3 |
✅* |
— |
— |
— |
"Periodically" |
| 48 |
Cryptography requirements review |
ECC-2:2024 |
ECC 2-8-4 |
✅* |
— |
— |
— |
"Periodically" |
| 49 |
Backup & recovery management review |
ECC-2:2024 |
ECC 2-9-4 |
✅* |
— |
— |
— |
"Periodically" |
| 50 |
Backup restoration test |
ECC-2:2024 |
ECC 2-9-3 |
✅* |
— |
✅* |
— |
"Periodically" — no interval |
| 51 |
Vulnerability assessment (general IT) |
ECC-2:2024 |
ECC 2-10-3 |
✅* |
✅* |
✅* |
✅* |
"Periodic assessments" — no interval |
| 52 |
Vulnerability management review |
ECC-2:2024 |
ECC 2-10-4 |
— |
— |
— |
✅* |
"Periodically" |
| 53 |
Penetration testing (general IT) |
ECC-2:2024 |
ECC 2-11-3 |
— |
— |
✅* |
— |
"Periodically" — no interval |
| 54 |
Penetration testing requirements review |
ECC-2:2024 |
ECC 2-11-4 |
✅* |
— |
— |
— |
"Periodically" |
| 55 |
Security event logs & SIEM configuration review |
ECC-2:2024 |
ECC 2-12-4 |
— |
✅* |
— |
— |
"Periodically" |
| 56 |
Incident response plan review |
ECC-2:2024 |
ECC 2-13-4 |
✅* |
— |
— |
— |
"Periodically" |
| 57 |
Incident response tabletop / simulation exercise |
ECC-2:2024 |
ECC 2-13-3 |
— |
✅* |
— |
— |
"Periodically" |
| 58 |
Physical security review |
ECC-2:2024 |
ECC 2-14-4 |
✅* |
— |
— |
— |
"Periodically" |
| 59 |
Web application security review |
ECC-2:2024 |
ECC 2-15-4 |
— |
— |
✅* |
— |
"Periodically" |
| 60 |
BCP / DR plan review |
ECC-2:2024 |
ECC 3-1-4 |
✅* |
— |
— |
— |
"Periodically" |
| 61 |
BCP / DR exercise / simulation |
ECC-2:2024 |
ECC 3-1-3 |
— |
— |
— |
✅* |
"Periodically" |
| 62 |
Third-party cybersecurity requirements review |
ECC-2:2024 |
ECC 4-1-4 |
— |
✅* |
— |
— |
"Periodically" |
| 63 |
Critical systems penetration testing |
CSCC-1:2019 |
CSCC 2-11 |
— |
— |
✅* |
— |
"Periodically" — no interval |
| 64 |
Critical systems stress / capacity test |
CSCC-1:2019 |
CSCC 3-1 |
— |
— |
— |
✅* |
Implied periodically |
| 65 |
HR screening for critical system personnel |
CSCC-1:2019 |
CSCC 1-9 |
✅* |
— |
— |
— |
"Periodically" |
| 66 |
Source code security review (before release) |
CSCC-1:2019 |
CSCC 2-16 |
✅* |
✅* |
✅* |
✅* |
"Before each release" |
| 67 |
OT/ICS cybersecurity awareness & training |
OTCC-1:2022 |
OTCC 1-8 |
✅* |
— |
— |
— |
"Periodically" |
| 68 |
OT/ICS asset inventory review |
OTCC-1:2022 |
OTCC 2-1-2 |
✅* |
✅* |
✅* |
✅* |
"Periodically" |
| 69 |
OT/ICS backup execution |
OTCC-1:2022 |
OTCC 2-8-1-3 |
✅* |
✅* |
✅* |
✅* |
"Periodically per classification" |
| 70 |
OT/ICS IR simulation exercise (tabletop) |
OTCC-1:2022 |
OTCC 2-12-1-7 |
— |
— |
✅* |
— |
"Periodically" |
| 71 |
OT/ICS physical security simulation exercise |
OTCC-1:2022 |
OTCC 2-13-1-9 |
— |
— |
— |
✅* |
"Periodically" |
| 72 |
OT/ICS BCP / DRP test |
OTCC-1:2022 |
OTCC 3-1-1-6 |
— |
— |
— |
✅* |
"Periodic testing and simulation" |
| 73 |
OT/ICS third-party cybersecurity assessment |
OTCC-1:2022 |
OTCC 4-1-1-4 |
— |
✅* |
— |
— |
"Periodic assessment" |
| 74 |
CCC cloud incident response capability test (CSP) |
CCC-1:2020 |
CCC 2-12-P-1-3 |
— |
— |
✅* |
— |
"Periodically" |
| 75 |
CCC cloud event logs & audit trail review (CSP) |
CCC-1:2020 |
CCC 2-11-P-1-6 |
✅* |
✅* |
✅* |
✅* |
"Periodically" |
| 76 |
CCC key management review (CSP & CST) |
CCC-1:2020 |
CCC 2-15-P-4/T-4 |
✅* |
— |
— |
— |
"Periodically" |
| 77 |
CCC change management review (CSP) |
CCC-1:2020 |
CCC 1-5-P-4 |
✅* |
— |
— |
— |
"Periodically" |
| 78 |
CCC personnel screening — cloud access roles (CSP) |
CCC-1:2020 |
CCC 1-4-P-1-2 |
✅* |
— |
— |
— |
"Periodically" |
| 79 |
Social media account security review |
OSMACC |
OSMACC |
✅* |
— |
— |
— |
"Periodically" |
| 80 |
Social media usage policy review |
OSMACC |
OSMACC |
✅* |
— |
— |
— |
"Periodically" |