+SOV-4-07 Data exchange monitoring
---+SOV-4-07-C
---+SOV-4-07-SI
|
1. Übersicht
SOV-4-07 Data exchange monitoring
SOV-4-07 Data exchange monitoring
| Bezeichnung |
Standard |
|
SOV-4-07-C
|
Any cloud service derived data, cloud service customer data and account data exchanged between the cloud service provider and third parties MUST always be monitored, controlled and logged. In order to do so, the cloud service provider MUST establish a documented process. The documentation MUST be reviewed and updated regularly, at least once a year. The cloud service provider MUST document what kind of data is exchanged with third parties. This documentation MUST ensure that it is clear which data is flowing to which party and this can also be meaningfully aggregated. The cloud service provider MUST make this documentation available to the cloud service customer. It is acceptable that this is only made available to the customer if they have agreed to keep the information confidential and not publicly disclose it. The cloud service provider MUST clearly define the exchange format and document it as part of the data exchange documentation.
|
|
SOV-4-07-SI
|
In the context of this requirement, a cloud service customer is not considered a third party. An associated company within the same group of companies is classified as a third party.
|
1.1 Referenzen
1.2 Identifizierte Anforderungen
1.2 Related Regulation
2. Identifizierte Anforderungen
Anforderungen
| Source |
Anforderung |
3. Related Regulations
Regulations
| Source |
Regulierung |
|