10.1Cryptographic controls
12.1Operational procedures and responsibilities
12.2Protection from malware
12.4Logging and monitoring
12.5Control of operational software
12.6Technical vulnerability management
12.7Information systems audit considerations
13.1Network security management
14.1Security requirements of information systems
14.2Security in development and support processes
15.2Supplier service delivery management
16.1Management of information security incidents and improvements
17.1Information security continuity
18.1Compliance with legal and contractual requirements
18.2Information security reviews
4.2Supplier relationships in cloud services
5.1Management direction for information security
6.2Mobile devices and teleworking
8.1Responsibility for assets
8.2Information classification
9.1Business requirements of access control
9.2User access management
9.4System and application access control
15.1Information security in supplier relationships
4.4Managing information security risks in cloud services