Skip to content

Security Procedure

What is Security Procedure?

A detailed, step-by-step instruction for performing a specific security task or responding to a particular security event.

Information Security

What the standards actually require on security procedure

Requirements naming security procedure across 6 standards, quoted from the control text.

CCPA/CPRA2 controls

Businesses must maintain records of consumer requests and the businesses response for at least 24 months. The records must include the date of request, nature of request, manner in which it was made, date and nature of response, basis for any denial.

CCR §7100-7102 · Recordkeeping Requirements
COPPA1 control

It is unlawful for a covered operator to collect personal information from a child in a manner that violates the Rule. Generally an operator must: provide notice of what it collects, how it uses it, and its disclosure practices;

COPPA-312.3 · General Requirements: Five Core Obligations

Undertakings establish a written, AMSB-approved information security policy defining principles and rules to protect confidentiality, integrity and availability of information, with roles and responsibilities, communicated to all staff (and relevant service pr...

EIOPA-ICTSG-GL.6 · Information security policy and measures

Internal Revenue Service (IRS) Publication 1075 Tax Information Security Guidelines for Federal + State and Local Agencies + Safeguards for Protecting Federal Tax Returns and Return Information. Most recent revision: Rev. November 2021 (preceded by Rev.

IRSPub1075-Scope-IRC6103-FTI-OfficeOfSafeguards-Rev2021Nov-FederalStateLocalAgencies-Contractors · IRS Publication 1075 Scope + IRC 26 USC 6103 + Federal Tax Information (FTI) Definition + Office of Safeguards Mission + Rev. November 2021 + Federal/State/Local Agencies + Contractors + Subcontractors

Protect supply chain information including shipping documentation, routing plans, customer data, and security procedures from unauthorized access and disclosure.

ISO28001-PI-03 · Information Security in Supply Chain

Identify vulnerabilities and predisposing conditions per NIST SP 800-30 Rev 1 Section 3.2 Step 3 + Appendix F (Vulnerabilities and Predisposing Conditions).

NISTSP30-4 · Vulnerability and Predisposing Condition Identification

Questions people ask about security procedure

What is Security Procedure?
A detailed, step-by-step instruction for performing a specific security task or responding to a particular security event.
Why is Security Procedure important for compliance?
Security Procedure is a key concept in Information Security. Understanding security procedure helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Procedure?
Security Procedure appears in the requirement text of CCPA/CPRA, COPPA, EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600), IRS Publication 1075, ISO 28001:2007 Supply Chain Security Management. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Procedure?
Explore our compliance framework pages to see how security procedure applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Procedure applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.