Reasonable security safeguards
At minimum: encryption, obfuscation, masking or virtual tokens; access control; logs and monitoring retained for the prescribed period to detect unauthorised access; measures for continued processing after a compromise; and contractual security obligations on Data Processors.
At minimum: encryption, obfuscation, masking or virtual tokens; access control; logs and monitoring retained for the prescribed period to detect unauthorised access; measures for continued processing after a compromise; and contractual security obligations on Data Processors.
Evidence a regulator would accept
- Rule 6 control checklist
- Encryption inventory
- Log retention configuration
- Processor contract clauses
How this product discharges it
Changing this recalculates the readiness score immediately.
- Current
- Partially compliant
- Residual risk
- Medium
- Owner
- Meera Iyer
- Last reviewed
- 28 Apr 2026
- Next review due
- 19 Jan 2027
Open gaps (7)
Gaps raised against this obligation. Closing one moves this clause forward.
- CriticalEight processor contracts lack the prescribed security provisionsGAP-2026-0211 · Vikram Saxena · open
- CriticalUnencrypted personal data columns in three legacy databasesGAP-2026-0212 · Naveen Kulkarni · open
- HighEntitlement certification incomplete for the current quarterGAP-2026-0215 · Meera Iyer · in remediation
- HighBackup restore not tested for the Health Card RegistryGAP-2026-0218 · Sanjay Chauhan · remediated
- MediumTwo directorates below 60% on mandatory security trainingGAP-2026-0220 · Ananya Reddy · verified
- MediumSkill development portal connector failing for 11 daysGAP-2026-0221 · Arjun Malhotra · verified
- HighShadow AI usage detected across 6 unsanctioned servicesGAP-2026-0231 · Vikram Saxena · in remediation
Evidence (10)
Documents indexed against this obligation in the evidence vault.
- Database activity capture — Family ID registryv3.7 · Sunita Khanna · 01 Jul 2026current
- Encryption inventory and key management standardv3.8 · Imran Sethi · 15 May 2026superseded
- Q3 entitlement certification reportv3.5 · Dr. Kavya Menon · 27 Jun 2026current
- Log retention configuration — 400 daysv1.6 · Arjun Malhotra · 22 Feb 2026current
- Detection and response runbookv4.9 · Pallavi Desai · 01 Jun 2026current
- Data Processing Agreement registerv2.5 · Priya Nair · 08 Jan 2026current
- Training completion register — FY 2026-27v2.6 · Sanjay Chauhan · 18 Jun 2026superseded
- Log monitoring review minutes — monthlyv1.6 · Priya Nair · 24 Apr 2026superseded
- Backup and restore test evidencev2.6 · Naveen Kulkarni · 31 Jan 2026expiring
- Immutable audit trail exportv1.0 · Sanjay Chauhan · 21 Feb 2026current
History
- Clause status updated following remediationyesterday06 Aug 2026, 00:30Deepika Joshi
- Clause status updated following remediation4 days ago03 Aug 2026, 17:30Rohit Verma
- Clause status updated following remediation6 days ago01 Aug 2026, 10:30Naveen Kulkarni
- Clause status updated following remediation8 days ago30 Jul 2026, 06:30Vikram Saxena
- Clause status updated following remediation10 days ago28 Jul 2026, 00:30Imran Sethi
- Clause status updated following remediation13 days ago25 Jul 2026, 16:30System
- Position reviewed and recorded3 months ago28 Apr 2026, 11:55Meera Iyer
Related obligations
- S.4Grounds for processing personal dataPartially compliant
- S.7Certain legitimate usesCompliant
- S.8(4)Reasonable security safeguardsPartially compliant
- S.17ExemptionsNot applicable
- R.5Processing for State subsidy, benefit, service, certificate, licence or permitCompliant
- R.15Research, archiving and statistical purposesNot applicable