| Risk management and policies | Assessment of the status against the requirements, linked evidence and recorded decisions. | Audit and risk assessment, an optimisation and migration plan, implementation and documentation. |
| Access control and multi-factor protection | Roles, permissions and traceability of who changed what and when. | Identity management, multi-factor authentication, access segmentation and 802.1X for wireless networks. |
| Network and perimeter security | Asset register and the measures linked to it. | Firewalls and traffic filtering, secure remote access and VPN, building network infrastructure. |
| Continuity and recovery | Tasks with an owner and a deadline, test protocols as evidence. | Backups and a recovery plan, recovery testing and documenting the result. |
| Monitoring and incident response | Status of the open work and a history of actions. | Proactive monitoring, a centralised event log and response within agreed deadlines. |
| Servers, virtualisation and cloud | The context of the requirement and the evidence attached to it. | Virtualisation and server solutions, private cloud, data centre colocation and hosting services. |