Operational control
Apply the controls selected in the statement of applicability: access control, encryption, change management, backups.
Supplier control
Evaluate and control the security risks tied to suppliers and data processors, with specific contractual clauses.
Security incident management
Detect, log, respond to and learn from every security incident, within the deadlines GDPR requires when personal data is involved.
What an auditor usually asks for
- Documented access control, encryption and backup controls
- Security clauses in contracts with critical suppliers
- A security incident log with response times
- A breach notification procedure within the legal deadline
How to cover operation in Kimobox
- 1Apply encryption, access control and verified backups on the platform.
- 2Onboard each supplier with their security clauses from the supplier portal.
- 3Log every security incident with its timeline and its closure.
The incident log stays linked to the technical evidence, ready for a breach notification deadline.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
- ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024