Security Controls
SL-01Rule 6 sets out specific measures rather than a general standard: encryption or masking, access control, logs retained and monitored, detection and remediation, backups, and contractual obligations on processors. This is the position against each, control by control.
Weighted across all applicable controls. Partial counts as half, because a control that works in three systems out of five is not a control.
- Compliant
- 3
- Partially compliant
- 4
- Gap
- 1
- Not assessed
- 0
Weakest first — this is the order to fix them in.
Control by control
Change a status inline. Each carries the implementation detail a reviewer will ask about, and the evidence index behind it.
Personal data must be protected by encryption, obfuscation or masking, or by using virtual tokens mapped to it.
How it is implemented
AES-256 at rest on all cloud-hosted stores and TLS 1.3 in transit. Three on-premise legacy databases still hold unencrypted columns; masking is applied at the application layer only.
Evidence
Access to systems holding personal data must be controlled, with least privilege enforced.
How it is implemented
RBAC in place across primary systems, integrated with Entra ID. Quarterly entitlement certification runs, but 46 grants remain uncertified this cycle and 14 are flagged as excessive.
Logs must be retained and monitored to enable detection of unauthorised access, with periodic review.
How it is implemented
Centralised log retention of 400 days across identity, database and DLP telemetry. Weekly review by the SOC; monthly review by the DPO.
Measures must enable detection of unauthorised access, investigation, and remediation to prevent recurrence.
How it is implemented
Behavioural baselines on 1,240 identities; automated session termination and account suspension playbooks; SOC integration with a 15-minute triage target.
Evidence
Reasonable backup and recovery measures must allow processing to continue if data is compromised.
How it is implemented
Nightly backups with a 4-hour RTO and 1-hour RPO for tier-1 systems. Restore testing has not been performed for the Health Card Registry in 14 months.
Evidence
Contracts with Data Processors must include the prescribed reasonable security safeguards.
How it is implemented
18 of 26 processor contracts carry the prescribed clauses. Six pre-date the Rules and two have expired without renewal.
Logs of personal data and of processing must be retained for the period specified in the Rules.
How it is implemented
Immutable, hash-chained audit store with 400-day online retention and 7-year archive.
Evidence
Appropriate provisions must exist to ensure the safeguards are actually observed in practice.
How it is implemented
Policy set published and mandatory training rolled out to 78% of staff. Two directorates have not completed the security deep-dive module.