Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Secure transfer of confidential data outside the organization

Critical
High
Normal
Low

The organization has to execute data transfers in public network using encrypted or otherwise protected data transfer connection or procedure, if the data is confidential.

The data transfer also has to be set up in a way where recipient can be identified securely enough before recipient can access any confidential data.

Connected other frameworks and requirements:
A.11.6: Encryption of PII transmitted over public data-transmission networks
ISO 27018

Encryption of public network traffic for application services

Critical
High
Normal
Low

Information included in application services transmitted over public networks must be protected against fraudulent and non-contractual activity and against unauthorized disclosure and alteration.

We use strong encryption and security protocols (eg TLS, IPSEC, SSH) to protect confidential information when it is transmitted over public networks in connection with the IT services we develop.

Connected other frameworks and requirements:
13.2.3: Electronic messaging
ISO 27001
14.1.2: Securing application services on public networks
ISO 27001
14.1.3: Protecting application services transactions
ISO 27001
14.2.5: Secure system engineering principles
ISO 27001
PR.DS-2: Data-in-transit
NIST CSF
No items found.