The following is the domain checklist:
- Does the product documentation contain the possibilities regarding security?
- Does it explicitly state:
- what the strategy is to security, based on aims and treatments
- who the security employees are
- which procedures regarding security must be followed in order to utilize the functionality optimally?
- Are jobs, authorities, and responsibilities in the organization of the information services separated clearly?
- Has a classification of documents been made, consisting of a number of classes of confidentiality?
- Has a limitation (and registration) of the circulation of classified documents to dedicated functionaries been arranged, based on this classification?
- Does a procedure exist for authorization ...