| (a) Data security measures | Where a tested surface returns personal data in a response or carries it in transit, the engagement records what actually came back. A value arriving in a form the design intended to be tokenised or masked is reported as a finding with the exchange attached to it. |
| Verbatim: “appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data”. |
| (b) Access control | The limb testing speaks to most directly. Authorisation across roles and tenants, privilege escalation paths, and reach to personal data by a principal that should have none — each carrying the request and the response that established it. |
| Verbatim: “appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable”. |
| (c) Visibility on access | An engagement is a known set of actions at known times against known targets. Setting what your monitoring raised beside that timeline measures this limb rather than describing it, which is the difference between a safeguards file that asserts visibility and one that shows it. |
| Verbatim: “visibility on the accessing of such personal data, through appropriate logs, monitoring and review”. |
| (d) Continued processing after loss of access | Backup and restore is an operational control rather than a tested surface, and the recoverability question sits outside an engagement. What does fall inside it is exposure of the backup estate an in-scope target reaches — an unauthenticated export route, a store open to a principal that should not hold it. |
| Rule 6(1)(d), on measures for continued processing in the event of loss of access to personal data or otherwise, such as by way of data-backups. |
| (e) Retention of logs and personal data | A retention period is a configuration and a policy decision. What an engagement supplies is the other half of the limb — the detection, investigation and remediation those retained records exist to support, exercised against real activity with a written account of what was done and when. |
| Verbatim: “for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise”. |
| (f) Processor contract terms | Drafting sits with your counsel. Where a processor-operated surface is inside the agreed scope, the engagement tests it on the same terms as your own systems and reports findings against it under the same severity scheme, so the contractual term and the measured state can be read together. |
| Verbatim: “appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards”. |
| (g) Technical and organisational measures | Effective observance is a claim about whether the measures work. A finding that has moved open, fixed, retested and closed — and that was marked closed only because a retest could not reproduce it — is the form evidence for this limb takes. |
| Verbatim: “appropriate technical and organisational measures to ensure effective observance of security safeguards”. |