IDDomainDescription
D1GOVERNANCE AND RISK MANAGEMENTD1 covers the security objectives related to governance and management of network and information security risks
D2HUMAN RESOURCES SECURITYD2 covers the security objectives related to personnel
D3SECURITY OF SYSTEMS AND FACILITIESD3 covers the physical and logical security of network and information systems and facilities
D4OPERATIONS MANAGEMENTD4 covers operational procedures, change management and asset management
D5INCIDENT MANAGEMENTD5 covers detection of, response to, incident reporting, and communication about incidents. Art.2 (42) of EECC defines ‘Security Incident’ as an event having an actual adverse effect on the security of electronic communications networks or services.
D6BUSINESS CONTINUITY MANAGEMENTD6 covers continuity strategies and contingency plans to mitigate major failures and natural or man-made disasters
D7MONITORING, AUDITING AND TESTINGD7 covers monitoring, testing and auditing of network and information systems and facilities
D8THREAT AWARENESSD8 covers security objectives related to threat intelligence and to outreach to end-users for the purpose of sharing the information about major threats to the security of networks and services
Domains