Under active development Content is continuously updated and improved

9.3.19.3.1

>Control Description

+ If required by law, a register of processing activities as defined in Article 30 (1) and/or (2) GDPR (in the latter case only information relating to the order, expressly not other information/details on internal processing) exists and is up to date. - Technical and organizational measures required for processing as required by the information security questionnaire are adequatly implemented for the processing activities - There is a process description / sequence description with defined responsibilities.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.