WEB-04
Client-Facing Web Services
Description
Mechanisms exist to deploy reasonably-expected security controls to protect the confidentiality and availability of client data that is stored, transmitted or processed by the Internet-based service.
Control Question
Does the organization deploy reasonably-expected security controls to protect the confidentiality and availability of client data that is stored, transmitted or processed by the Internet-based service?
Control Metadata
Domain:
Web Security
Validation Cadence:
Annual
