+AM-11 Transfer of Hardware
---+AM-11.01B
---+AM-11.02B
---+AM-11.03B
|
1. Übersicht
AM-11 Transfer of Hardware
-
| Bezeichnung |
Standard |
|
AM-11.01B
|
Based on a risk assessment (cf. OIS-07), the cloud service provider ensures the secure and controlled transfer of hardware objects used in the cloud service production environment to an offsite or alternate location.
|
|
AM-11.02B
|
The transfer of hardware is authorised by designated personnel.
Authorisation ensures that hardware object transfers, whether internal or external, are controlled, traceable, and compliant with organisational policies. This is particularly important for assets containing sensitive data or used in production environments. The process typically includes:
1. Verification of asset ownership and classification;
2. Assessment of associated risks;
3. Documentation of the transfer request and approval; and
4. Confirmation of secure handling during transit.
|
|
AM-11.03B
|
The cloud service provider ensures that all transfers of hardware objects used in the cloud service production environment are conducted using secure, documented methods designed to prevent unauthorised access, tampering, data leakage, or loss during transit. These methods include physical protection, chain-of-custody tracking, and verification upon receipt.
|
1.1 Referenzen
1.2 Identifizierte Anforderungen
1.2 Related Regulation
2. Identifizierte Anforderungen
Anforderungen
| Source |
Anforderung |
3. Related Regulations
Regulations
| Source |
Regulierung |
|