4

Security Controls

SL-01

Rule 6 sets out specific measures rather than a general standard: encryption or masking, access control, logs retained and monitored, detection and remediation, backups, and contractual obligations on processors. This is the position against each, control by control.

DischargesS.8(4)R.6
Rule 6 position

Weighted across all applicable controls. Partial counts as half, because a control that works in three systems out of five is not a control.

Compliant
3
Partially compliant
4
Gap
1
Not assessed
0
By control area

Weakest first — this is the order to fix them in.

Processor contracts
0%
Encryption & masking
50%
Access control
50%
Backup & continuity
50%
Organisational measures
50%
Logging & retention
100%
Detection & response
100%
Controls assessed
8
Compliant
3
Gaps
1
Review overdue
0

Control by control

Change a status inline. Each carries the implementation detail a reviewer will ask about, and the evidence index behind it.

Rule 6(1)(a)Encryption, obfuscation, masking or virtual tokens

Personal data must be protected by encryption, obfuscation or masking, or by using virtual tokens mapped to it.

How it is implemented

AES-256 at rest on all cloud-hosted stores and TLS 1.3 in transit. Three on-premise legacy databases still hold unencrypted columns; masking is applied at the application layer only.

Partially compliantEncryption & maskingData DiscoveryDatabase Activity Monitoring
Owner Vikram Saxena · verified 29 Jun 2026Next review in 2 months
Rule 6(1)(b)Control over access to computer resources

Access to systems holding personal data must be controlled, with least privilege enforced.

How it is implemented

RBAC in place across primary systems, integrated with Entra ID. Quarterly entitlement certification runs, but 46 grants remain uncertified this cycle and 14 are flagged as excessive.

Partially compliantAccess controlAccess AssuranceData Discovery
Owner Vikram Saxena · verified 16 Jul 2026Next review in 2 months
Rule 6(1)(c)Visibility through logs, monitoring and review

Logs must be retained and monitored to enable detection of unauthorised access, with periodic review.

How it is implemented

Centralised log retention of 400 days across identity, database and DLP telemetry. Weekly review by the SOC; monthly review by the DPO.

CompliantLogging & retentionDatabase Activity MonitoringAccess AssuranceDLP
Owner Rohit Verma · verified 28 Jul 2026Next review in 3 months
Rule 6(1)(d)Detection of unauthorised access and remedial action

Measures must enable detection of unauthorised access, investigation, and remediation to prevent recurrence.

How it is implemented

Behavioural baselines on 1,240 identities; automated session termination and account suspension playbooks; SOC integration with a 15-minute triage target.

CompliantDetection & responseAccess AssuranceDLPDatabase Activity MonitoringAccess Gateway
Owner Rohit Verma · verified 23 Jul 2026Next review in 2 months
Rule 6(1)(e)Backups for continued processing after compromise

Reasonable backup and recovery measures must allow processing to continue if data is compromised.

How it is implemented

Nightly backups with a 4-hour RTO and 1-hour RPO for tier-1 systems. Restore testing has not been performed for the Health Card Registry in 14 months.

Partially compliantBackup & continuity
Owner Vikram Saxena · verified 15 Jun 2026Next review next month
Rule 6(1)(f)Contractual security obligations on Data Processors

Contracts with Data Processors must include the prescribed reasonable security safeguards.

How it is implemented

18 of 26 processor contracts carry the prescribed clauses. Six pre-date the Rules and two have expired without renewal.

GapProcessor contracts
Owner Imran Sethi · verified 07 Jul 2026Next review in 13 days
Rule 6(1)(g)Log and personal data retention for the prescribed period

Logs of personal data and of processing must be retained for the period specified in the Rules.

How it is implemented

Immutable, hash-chained audit store with 400-day online retention and 7-year archive.

CompliantLogging & retentionAudit Trail
Owner Vikram Saxena · verified 19 Jul 2026Next review in 2 months
Rule 6(1)(h)Technical and organisational measures to give effect to safeguards

Appropriate provisions must exist to ensure the safeguards are actually observed in practice.

How it is implemented

Policy set published and mandatory training rolled out to 78% of staff. Two directorates have not completed the security deep-dive module.

Partially compliantOrganisational measuresTraining & Awareness
Owner Meera Iyer · verified 12 Jul 2026Next review in 2 months
Evidences:S.8(4)R.6Several of these controls are provided by the enforcing modules rather than by configuration — which is why their status changes when a module is enabled or disabled.