Under active development Content is continuously updated and improved

Article 28.2Article 28.2

>Control Description

The measures referred to in section 1 will have the status of minimum requirements, being expandable at the discretion of the person responsible for security, who may include additional measures, taking into account the state of the technology, the nature of the information processed or the services provided and the risks to which the affected information systems are exposed. The list of selected security measures will be formalized in a document called Declaration of Applicability, signed by the person responsible for security.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.