Arx / docs /CONTROLS.md
umer-wasim's picture
v0.3: phone check (iPhone, Android) as the Space front page, catalog 0.3 (74 checks), shared vulnerability rules, real-CVE training data
6ccf48e verified
|
Raw History Blame Contribute Delete
33.6 kB

Audited controls and data sources

Catalog version 0.3.0 · 74 checks. Generated by tools/build_controls_doc.py — do not edit by hand.

All sources are read-only. Internet is only used by Pending security updates on Windows and macOS, and by the app to refresh the vulnerability bundle. Phones are checked in the browser: a web page cannot read a phone's settings, so results are either detected by the browser or answered by the user (self-reported), and labelled as such.

COMPLIANCE RESULTS (48)

Check Applies to References Rule Windows source Linux source macOS source iPhone source Android source
Minimum password length windows, linux, macos ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) Configured minimum length >= PASSWORD_MIN_LENGTH. secedit export: MinimumPasswordLength PAM pam_pwquality minlen (/etc/security/pwquality.conf, PAM args) pwpolicy -getaccountpolicies (minLength / regex) — —
Password history windows, linux, macos ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) Remembered passwords >= PASSWORD_HISTORY. secedit export: PasswordHistorySize pam_pwhistory remember (PAM args, /etc/security/pwhistory.conf) pwpolicy: policyAttributePasswordHistoryDepth — —
Password expiration windows, linux, macos ISO A.5.17; GDPR Art. 32(1)(b) Passwords expire after 1..PASSWORD_MAX_AGE_DAYS days (0 in the baseline = expiry not required). secedit export: MaximumPasswordAge /etc/login.defs PASS_MAX_DAYS + /etc/shadow per account pwpolicy: policyAttributeExpiresEveryNDays — —
Minimum password age windows, linux, macos ISO A.5.17; GDPR Art. 32(1)(b) Minimum age >= PASSWORD_MIN_AGE_DAYS days. macOS has no such setting (NotApplicable). secedit export: MinimumPasswordAge /etc/login.defs PASS_MIN_DAYS + /etc/shadow per account not available on macOS (NotApplicable) — —
Password complexity windows, linux, macos ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) Complexity enforced (mixed character classes). secedit export: PasswordComplexity pam_pwquality minclass / dcredit-ucredit-lcredit-ocredit pwpolicy: alpha + numeric requirements — —
Account lockout threshold windows, linux, macos ISO A.8.5; GDPR Art. 32(1)(b) Lockout after 1..LOCKOUT_THRESHOLD_MAX failed attempts (0 = never locks). secedit export: LockoutBadCount pam_faillock deny (PAM args, /etc/security/faillock.conf) pwpolicy: policyAttributeMaximumFailedAuthentications — —
Account lockout duration windows, linux, macos ISO A.8.5; GDPR Art. 32(1)(b) Locked for >= LOCKOUT_DURATION_MIN_MINUTES minutes, or until an administrator unlocks. secedit export: LockoutDuration pam_faillock unlock_time pwpolicy: autoEnableInSeconds — —
Lockout observation period windows, linux, macos ISO A.8.5; GDPR Art. 32(1)(b) Failed-attempt counter kept for >= LOCKOUT_OBSERVATION_MIN_MINUTES minutes. secedit export: ResetLockoutCount pam_faillock fail_interval pwpolicy: autoEnableInSeconds (counter resets with lockout) — —
Antivirus / Google Play Protect windows, linux, macos, android ISO A.8.7; GDPR Art. 32(1)(b) An enabled, up-to-date antivirus product is present. Android: Google Play Protect scanning is on. Security Center (root/SecurityCenter2 AntiVirusProduct) systemd services: clamav-daemon, mdatp, falcon-sensor, sentinelone, sophos-spl, esets XProtect version (xprotect version) + running third-party agents — asked: Play Store › your profile picture › Play Protect › Settings (gear icon)
Malware protection service / Apple malware protection service / ClamAV malware protection service / Microsoft Defender Antimalware windows, linux, macos ISO A.8.7; GDPR Art. 32(1)(b) The platform malware protection service is running. Get-MpComputerStatus: AMServiceEnabled, AntivirusEnabled systemctl is-active clamav-daemon / clamd xprotect status + spctl --status (Gatekeeper) — —
Real-time protection windows ISO A.8.7; GDPR Art. 32(1)(b) Defender real-time protection is on. Get-MpComputerStatus: RealTimeProtectionEnabled — — — —
On-access malware protection / On-access protection windows, linux, macos ISO A.8.7; GDPR Art. 32(1)(b) Files are scanned when opened. macOS: NotApplicable unless a third-party scanner provides it. Get-MpComputerStatus: OnAccessProtectionEnabled clamav-clamonacc service / clamonacc process third-party agent only (XProtect has no on-access scan) — —
Tamper protection windows ISO A.8.7; GDPR Art. 32(1)(b) Defender tamper protection is on. Get-MpComputerStatus: IsTamperProtected — — — —
Malware signatures / Malware protection signatures / Security intelligence windows, linux, macos ISO A.8.7; ISO A.8.8; GDPR Art. 32(1)(b) Signatures no older than SIGNATURE_MAX_AGE_DAYS (macOS XProtect: MACOS_XPROTECT_MAX_AGE_DAYS). Get-MpComputerStatus: AntivirusSignatureAge age of /var/lib/clamav/daily.c[lv]d XProtect install date (xprotect version / XProtect.meta.plist) — —
Malware signature updates / Malware security updates linux, macos ISO A.8.7; ISO A.8.8; GDPR Art. 32(1)(b) Automatic signature/security-data updates are enabled. — systemctl is-active clamav-freshclam com.apple.SoftwareUpdate ConfigDataInstall + CriticalUpdateInstall — —
Firewall linux, macos ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) A host firewall is active. — ufw status / firewalld / nft list ruleset / iptables -S socketfilterfw --getglobalstate — —
Firewall inbound policy linux, macos ISO A.8.20; GDPR Art. 32(1)(b) Unsolicited inbound traffic is blocked by default (macOS: firewall on with stealth mode). — ufw default incoming / firewalld zone target / nft input policy socketfilterfw --getstealthmode — —
Firewall outbound policy linux, macos ISO A.8.20; GDPR Art. 32(1)(b) Default outbound policy equals FIREWALL_OUTBOUND. — ufw default outgoing / nft output policy application firewall is inbound-only — —
Domain firewall windows ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) Domain profile enabled. Get-NetFirewallProfile -PolicyStore ActiveStore (Domain) — — — —
Domain inbound windows ISO A.8.20; GDPR Art. 32(1)(b) Domain profile default inbound action is Block. Get-NetFirewallProfile: DefaultInboundAction (Domain) — — — —
Domain outbound windows ISO A.8.20; GDPR Art. 32(1)(b) Domain profile default outbound action equals FIREWALL_OUTBOUND. Get-NetFirewallProfile: DefaultOutboundAction (Domain) — — — —
Private firewall windows ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) Private profile enabled. Get-NetFirewallProfile -PolicyStore ActiveStore (Private) — — — —
Private inbound windows ISO A.8.20; GDPR Art. 32(1)(b) Private profile default inbound action is Block. Get-NetFirewallProfile: DefaultInboundAction (Private) — — — —
Private outbound windows ISO A.8.20; GDPR Art. 32(1)(b) Private profile default outbound action equals FIREWALL_OUTBOUND. Get-NetFirewallProfile: DefaultOutboundAction (Private) — — — —
Public firewall windows ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) Public profile enabled. Get-NetFirewallProfile -PolicyStore ActiveStore (Public) — — — —
Public inbound windows ISO A.8.20; GDPR Art. 32(1)(b) Public profile default inbound action is Block. Get-NetFirewallProfile: DefaultInboundAction (Public) — — — —
Public outbound windows ISO A.8.20; GDPR Art. 32(1)(b) Public profile default outbound action equals FIREWALL_OUTBOUND. Get-NetFirewallProfile: DefaultOutboundAction (Public) — — — —
Screen lock / Passcode windows, linux, macos, ios, android ISO A.8.1; ISO A.7.7; GDPR Art. 32(1)(b) The screen locks when idle (Windows: machine inactivity limit or a password-protected screen saver). Phones: a passcode / PIN / password screen lock is set. InactivityTimeoutSecs policy or users' ScreenSaveActive/ScreenSaverIsSecure (HKU) gsettings org.gnome.desktop.screensaver lock-enabled + session idle-delay (per user) sysadminctl -screenLock status / managed com.apple.screensaver detected: WebAuthn platform authenticator available; otherwise asked; asked: Settings › Face ID & Passcode (or Touch ID & Passcode). If it asks for your passcode before opening, one is set. detected: WebAuthn platform authenticator available; otherwise asked; asked: Settings › Security & privacy › Device unlock › Screen lock (names vary by phone maker)
Screen lock timeout / Auto-Lock / Screen timeout windows, linux, macos, ios, android ISO A.8.1; ISO A.7.7; GDPR Art. 32(1)(b) Idle time before lock (including any grace delay) is 1..SCREEN_LOCK_MAX_SECONDS seconds (baseline: 300 = 5 minutes). Phones: Auto-Lock / screen timeout. InactivityTimeoutSecs policy or users' ScreenSaveTimeOut (HKU) gsettings idle-delay + lock-delay (per user) screen saver idleTime + pmset displaysleep + password delay asked: Settings › Display & Brightness › Auto-Lock asked: Settings › Display › Screen timeout. If there is also 'Lock after screen timeout', it should be Immediately.
Screen lock password requirement windows, linux, macos ISO A.8.1; ISO A.7.7; ISO A.8.5; GDPR Art. 32(1)(b) A password is required to unlock (macOS: within 5 seconds of the screen locking). InactivityTimeoutSecs policy or users' ScreenSaverIsSecure; DisableLockWorkstation gsettings lock-enabled + lockdown disable-lock-screen sysadminctl -screenLock delay / managed askForPassword — —
Passcode strength / Screen lock strength ios, android ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) Passcode / PIN has at least MOBILE_PASSCODE_MIN_DIGITS digits, or is alphanumeric. Android pattern or swipe locks do not comply. — — — asked: The code you type to unlock. Settings › Face ID & Passcode › Change Passcode › Passcode Options shows the choices. asked: Settings › Security & privacy › Device unlock › Screen lock
Operating system integrity / Not jailbroken / Not rooted ios, android ISO A.8.1; ISO A.8.7; ISO A.8.19; GDPR Art. 32(1)(b) The phone is not jailbroken (iOS) or rooted / bootloader-unlocked (Android). — — — asked: Jailbreaking means deliberately modifying iOS to install apps outside Apple's control. If nobody did this on purpose, answer No. asked: Rooting means deliberately giving apps full system access. If nobody did this on purpose, answer No.
App sources restricted / Apps only from the App Store / Install unknown apps blocked ios, android ISO A.8.1; ISO A.8.7; ISO A.8.19; GDPR Art. 32(1)(b) Apps are installed only from the official store (no alternative marketplaces, web distribution or unknown sources). — — — asked: Settings › General › VPN & Device Management lists developer or enterprise profiles. Alternative app marketplaces appear as separate apps. asked: Settings › Apps › Special app access › Install unknown apps. Every app should show 'Not allowed'.
USB debugging off android ISO A.8.1; ISO A.8.19; GDPR Art. 32(1)(b) Developer options / USB debugging are off. — — — — asked: Settings › System › Developer options › USB debugging. If you cannot find Developer options, they are off.
Find and erase a lost device / Find My Device / Find My iPhone ios, android ISO A.5.9; ISO A.8.1; GDPR Art. 32(1)(b); GDPR Art. 32(1)(c) Find My iPhone / Find My Device is on, so a lost phone can be located, locked and erased. — — — asked: Settings › [your name] › Find My › Find My iPhone asked: Settings › Google › All services › Find My Device (called Find Hub on newer phones)
USB storage device access windows, linux, macos ISO A.7.10; ISO A.8.12; GDPR Art. 32(1)(b) Whether USB mass storage devices can connect at all equals USB_DEVICE_ACCESS (allow/deny): driver, device-installation policy, USBGuard or MDM restriction. RemovableStorageDevices Deny_All policy, USBSTOR service Start modprobe usb-storage install rule / blacklist / USBGuard managed com.apple.systemuiserver mount-controls — —
USB storage read windows, linux, macos ISO A.7.10; ISO A.8.12; GDPR Art. 32(1)(b) Effective USB storage read access equals USB_READ (allow/deny). RemovableStorageDevices policies (Deny_All, Deny_Read), USBSTOR Start usb-storage module rules, USBGuard managed mount-controls (deny) — —
USB storage write windows, linux, macos ISO A.7.10; ISO A.8.12; GDPR Art. 32(1)(b) Effective USB storage write access equals USB_WRITE (allow/deny). RemovableStorageDevices Deny_Write, StorageDevicePolicies WriteProtect udev read-only rules, usb-storage rules, USBGuard managed mount-controls (deny / read-only) — —
Approved IT administrator windows, linux, macos ISO A.8.2; ISO A.5.15; GDPR Art. 32(1)(b) At least one account listed in APPROVED_ADMINS is an enabled administrator. Administrators group by SID S-1-5-32-544 (ADSI) + Get-LocalUser getent group sudo/admin/wheel, UID 0 accounts, /etc/sudoers(.d) dscl . -read /Groups/admin GroupMembership — —
Unauthorized employee administrator accounts / Unauthorized employee local administrator accounts windows, linux, macos ISO A.8.2; ISO A.5.18; GDPR Art. 32(1)(b) No administrator accounts other than APPROVED_ADMINS (and the disabled built-in Administrator on Windows). Administrators group by SID S-1-5-32-544 (ADSI) + Get-LocalUser getent group sudo/admin/wheel, UID 0 accounts, /etc/sudoers(.d) dscl . -read /Groups/admin GroupMembership — —
BitLocker windows ISO A.8.24; ISO A.8.1; GDPR Art. 32(1)(a) BitLocker is turned on for the system drive. Get-BitLockerVolume (system drive): VolumeStatus — — — —
Encryption / Data protection (encryption) / Device encryption windows, linux, macos, ios, android ISO A.8.24; ISO A.8.1; GDPR Art. 32(1)(a) The system disk is fully encrypted (BitLocker / LUKS / FileVault). Phones: iOS data protection is on when a passcode is set; Android 10+ encrypts by default. Get-BitLockerVolume: VolumeStatus, EncryptionPercentage findmnt / + lsblk (crypt device under /) fdesetup status derived: on when a passcode is set (iOS data protection) detected: Android 10+ encrypts by default
Disk encryption protection / BitLocker protection windows, linux, macos ISO A.8.24; GDPR Art. 32(1)(a) Encryption protection is active (not suspended or in progress) with a strong cipher. Get-BitLockerVolume: ProtectionStatus, EncryptionMethod cryptsetup status (type, cipher, key size) fdesetup status (no encryption in progress) — —
Disk encryption recovery / BitLocker recovery windows, linux, macos ISO A.8.24; ISO A.8.13; GDPR Art. 32(1)(a); GDPR Art. 32(1)(c) A recovery key or second unlock method exists. Get-BitLockerVolume: KeyProtector (RecoveryPassword) cryptsetup luksDump (key slots, tokens) fdesetup haspersonalrecoverykey / hasinstitutionalrecoverykey — —
Signed-in user account type windows, linux, macos ISO A.8.2; ISO A.5.15; GDPR Art. 32(1)(b) The everyday signed-in user is a Standard account (not an administrator), unless listed in APPROVED_ADMINS. signed-in user (Win32_ComputerSystem) vs Administrators group session users (loginctl) vs sudo/admin/wheel console user (stat /dev/console) + dsmemberutil checkmembership — —
Pending security updates / Android security update / iOS security updates windows, linux, macos, ios, android ISO A.8.8; GDPR Art. 32(1)(b); GDPR Art. 32(1)(d) Security updates offered by the OS vendor but not yet installed <= MAX_PENDING_SECURITY_UPDATES. Phones: iOS is at the latest security release known to the vulnerability data; Android security patch level is at most MOBILE_PATCH_MAX_AGE_DAYS old. Windows Update Agent API (Microsoft.Update.Session search) - needs internet apt-get -s upgrade (security) / dnf updateinfo --security - uses local package lists softwareupdate -l - needs internet detected: iOS version vs newest fixed release in the signed phone bundle asked: Settings › About phone › Android version › Android security update (or Settings › Security & privacy › Updates)
Outdated third-party applications / App updates windows, linux, macos, ios, android ISO A.8.8; ISO A.8.19; GDPR Art. 32(1)(b) Installed third-party applications with a newer version available <= MAX_OUTDATED_APPS (Windows: winget; macOS: app versions; Linux: snap/flatpak and packages). Phones: automatic app updates are on. winget upgrade apt upgradable, snap refresh --list, flatpak updates brew outdated (Homebrew; App Store apps not covered) asked: Settings › App Store › App Updates asked: Play Store › your profile picture › Settings › Network preferences › Auto-update apps
Known vulnerabilities in installed software / Known vulnerabilities in iOS windows, linux, macos, ios ISO A.8.8; GDPR Art. 32(1)(b) Installed software versions matched against an offline copy of the OSV/NVD vulnerability data: critical or high vulnerabilities <= MAX_CRITICAL_HIGH_VULNERABILITIES. iOS: the iOS version is matched against NVD iOS/iPadOS records. installed programs (machine and per-user uninstall registry) matched by the app against the signed offline bundle (NVD ranges, CISA KEV, EPSS) dpkg/rpm package list (with source packages) matched by the app against the signed offline bundle (OSV: Ubuntu, Debian, RHEL, AlmaLinux, Rocky) app bundle versions (/Applications, ~/Applications) matched by the app against the signed offline bundle (NVD ranges, CISA KEV, EPSS) detected: iOS version matched against NVD iOS/iPadOS records in the signed phone bundle —

GDPR TECHNICAL CONTROLS (13)

Check Applies to References Rule Windows source Linux source macOS source iPhone source Android source
Automatic security updates / Automatic iOS updates / Automatic system updates windows, linux, macos, ios, android ISO A.8.8; GDPR Art. 32(1)(b) Security updates are downloaded and installed automatically. WindowsUpdate\AU policy (NoAutoUpdate, AUOptions), wuauserv start type apt-config Unattended-Upgrade / dnf-automatic timer com.apple.SoftwareUpdate AutomaticCheck/Download/Install keys asked: Settings › General › Software Update › Automatic Updates asked: Settings › System › Software updates (names vary: 'Auto download over Wi-Fi', 'Automatic system updates')
Security updates installed recently windows, linux, macos ISO A.8.8; GDPR Art. 32(1)(b); GDPR Art. 32(1)(d) Last successful update/package change within UPDATES_MAX_AGE_DAYS days. Windows Update history (COM) or Get-HotFix /var/log/apt/history.log / rpm -qa --last /Library/Receipts/InstallHistory.plist (softwareupdated) — —
Supported operating system version windows, linux, macos, ios, android ISO A.8.8; GDPR Art. 32(1)(b) The OS version still receives security updates (minimums in the baseline). Phones: IOS_MIN_MAJOR / ANDROID_MIN_MAJOR. Win32_OperatingSystem BuildNumber vs WINDOWS_MIN_BUILD /etc/os-release VERSION_ID vs baseline minimum sw_vers -productVersion vs MACOS_MIN_MAJOR detected: OS version (Safari version on iOS 26+, client hints on Android), confirmed by the user detected: OS version (Safari version on iOS 26+, client hints on Android), confirmed by the user
Security event logging windows, linux, macos ISO A.8.15; GDPR Art. 32(1)(d); GDPR Art. 33 Logon and account-change events are recorded (Windows audit policy, Linux auditd, macOS unified log). auditpol /backup (Logon, User Account Management) + legacy audit policy systemctl is-active auditd, journal persistence logd running (unified logging) — —
Time synchronisation / Date & time set automatically windows, linux, macos, ios, android ISO A.8.17; GDPR Art. 33 The clock is synchronised from a time server. W32Time Parameters Type + service start type timedatectl NTP / chronyd / ntpd systemsetup -getusingnetworktime (needs root) asked: Settings › General › Date & Time asked: Settings › System › Date & time
Backup configured / Google backup / iCloud Backup windows, linux, macos, ios, android ISO A.8.13; GDPR Art. 32(1)(c) A backup solution is configured for user data. OneDrive KFM policy, File History config, backup agent services Timeshift config, Deja Dup (gsettings), restic/borg timers tmutil destinationinfo, backup agent processes asked: Settings › [your name] › iCloud › iCloud Backup asked: Settings › Google › Backup (or Settings › System › Backup; Samsung: Accounts and backup)
Recent backup windows, linux, macos ISO A.8.13; GDPR Art. 32(1)(c) Last backup within BACKUP_MAX_AGE_DAYS days (Pending when the date cannot be read). not readable for most tools (Pending) Timeshift snapshot names, Deja Dup last-backup tmutil latestbackup — —
Removable media encryption windows, linux, macos ISO A.7.10; ISO A.8.24; GDPR Art. 32(1)(a); GDPR Art. 34 Data cannot be written to unencrypted removable drives. FVE RDVDenyWriteAccess (BitLocker To Go) or USB write denied USB write denied USB write denied — —
Guest account disabled windows, linux, macos ISO A.5.16; ISO A.8.5; GDPR Art. 32(1)(b) No enabled guest login. Get-LocalUser (SID -501): Enabled LightDM allow-guest, 'guest' account shell com.apple.loginwindow GuestEnabled, SMB AllowGuestAccess — —
Remote access services restricted windows, linux, macos ISO A.8.20; ISO A.6.7; GDPR Art. 32(1)(b) Only remote access services listed in APPROVED_REMOTE_SERVICES are enabled. fDenyTSConnections (RDP), sshd/WinRM/TeamViewer/AnyDesk/chromoting services, non-admin SMB shares ssh/xrdp/vnc/samba/teamviewer/anydesk/chrome-remote-desktop launchctl print-disabled (sshd, screensharing, smbd, chromoting), ARDAgent/TeamViewer/AnyDesk — —
Diagnostic data minimised / Analytics sharing minimised / Usage & diagnostics sharing minimised windows, linux, macos, ios, android ISO A.5.34; GDPR Art. 5(1)(c); GDPR Art. 25 OS diagnostic/usage data sharing is at the minimum level. DataCollection AllowTelemetry (policy / Settings) popularity-contest, whoopsie DiagnosticMessagesHistory AutoSubmit, ThirdPartyDataSubmit asked: Settings › Privacy & Security › Analytics & Improvements asked: Settings › Google › All services › Usage & diagnostics (also check the phone maker's diagnostics option)
Notification content hidden on the lock screen / Notification previews hidden when locked / Sensitive notifications hidden when locked ios, android ISO A.7.7; ISO A.8.1; GDPR Art. 5(1)(f); GDPR Art. 32(1)(b) Message and email previews are not shown on the locked screen. — — — asked: Settings › Notifications › Show Previews asked: Settings › Notifications › Notifications on lock screen (or Settings › Privacy)
Personal data discovery windows, linux, macos ISO A.5.34; ISO A.5.12; GDPR Art. 5(1)(c); GDPR Art. 5(1)(e); GDPR Art. 30 Opt-in scan of user folders for personal data patterns (counts and paths only). Not implemented in stage 1: NotApplicable. planned opt-in scan planned opt-in scan planned opt-in scan — —

EU AI ACT CONTROLS (5)

Check Applies to References Rule Windows source Linux source macOS source iPhone source Android source
AI software inventory windows, linux, macos, ios, android ISO A.5.9; GDPR Art. 30; AI Act Art. 26 AI apps, local AI services and local model folders are listed (Compliant = inventory taken). uninstall registry + Store apps (AI apps), port 11434, model folders, Claude Code CLI AI CLIs, snaps, flatpaks, /opt apps, port 11434, model folders /Applications AI apps, AI CLIs, port 11434, model folders asked: AI apps installed (checklist); classified by the auditor model asked: AI apps installed (checklist); classified by the auditor model
Unapproved AI tools (shadow AI) windows, linux, macos, ios, android ISO A.5.9; ISO A.8.19; GDPR Art. 28; GDPR Art. 44; AI Act Art. 26 Every AI tool found is listed in APPROVED_AI_TOOLS. AI inventory vs APPROVED_AI_TOOLS AI inventory vs APPROVED_AI_TOOLS AI inventory vs APPROVED_AI_TOOLS asked: AI apps installed (checklist); classified by the auditor model asked: AI apps installed (checklist); classified by the auditor model
AI system risk classification windows, linux, macos, ios, android ISO A.5.9; AI Act Art. 5; AI Act Art. 6; AI Act Annex III Each AI tool found is classified (prohibited / high-risk / limited / minimal). Done by the auditor model: Pending in the collector output, NotApplicable when no AI tool is found. AI inventory, classified by the model AI inventory, classified by the model AI inventory, classified by the model asked: AI apps installed (checklist); classified by the auditor model asked: AI apps installed (checklist); classified by the auditor model
Operating system AI features restricted / AI assistant access restricted / Apple Intelligence external integrations restricted / Windows Recall / Copilot data analysis disabled windows, linux, macos, ios, android ISO A.5.34; GDPR Art. 5(1)(c); GDPR Art. 25; AI Act Art. 26 OS-level AI features that capture or send user data are disabled by policy. NotApplicable where the OS has none. Phones: external AI integrations (ChatGPT in Apple Intelligence, assistant access to screen content) are off unless approved. WindowsAI policies (DisableAIDataAnalysis, AllowRecallEnablement), Recall optional feature none built in (NotApplicable) managed com.apple.applicationaccess allowExternalIntelligenceIntegrations (Apple silicon) asked: Settings › Apple Intelligence & Siri › ChatGPT (only on iPhones that support Apple Intelligence) asked: Gemini app › your profile picture › Settings › 'Screen context' / 'Use screen context' (other assistants have similar options)
AI usage log retention windows, linux, macos, ios, android ISO A.8.15; AI Act Art. 26(6) Logs kept >= 6 months if a high-risk AI system is used. Pending until classification; NotApplicable when no AI tool is found. depends on AI classification depends on AI classification depends on AI classification asked: AI apps installed (checklist); classified by the auditor model asked: AI apps installed (checklist); classified by the auditor model

ORGANISATIONAL CONTROLS (8)

Check Applies to References Rule Windows source Linux source macOS source iPhone source Android source
Record of processing activities windows, linux, macos, ios, android ISO A.5.34; GDPR Art. 30 Answer yes = Compliant, no/partial = Non-Compliant, n/a = NotApplicable, unanswered = Pending. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
Data protection impact assessment windows, linux, macos, ios, android ISO A.5.34; GDPR Art. 35 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
Breach response procedure windows, linux, macos, ios, android ISO A.5.24; ISO A.5.26; GDPR Art. 33; GDPR Art. 34 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
Data processing agreements windows, linux, macos, ios, android ISO A.5.20; GDPR Art. 28 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
AI register windows, linux, macos, ios, android ISO A.5.9; AI Act Art. 26 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
AI literacy training windows, linux, macos, ios, android ISO A.6.3; AI Act Art. 4 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
Human oversight for high-risk AI windows, linux, macos, ios, android AI Act Art. 14; AI Act Art. 26 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link
AI transparency to users windows, linux, macos, ios, android AI Act Art. 50 As above. organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation) organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link

Reference titles

ISO/IEC 27001:2022 Annex A: A.5.9 Inventory of information and other associated assets; A.5.12 Classification of information; A.5.15 Access control; A.5.16 Identity management; A.5.17 Authentication information; A.5.18 Access rights; A.5.20 Addressing information security within supplier agreements; A.5.24 Information security incident management planning and preparation; A.5.26 Response to information security incidents; A.5.34 Privacy and protection of PII; A.6.3 Information security awareness, education and training; A.6.7 Remote working; A.7.7 Clear desk and clear screen; A.7.10 Storage media; A.8.1 User endpoint devices; A.8.2 Privileged access rights; A.8.5 Secure authentication; A.8.7 Protection against malware; A.8.8 Management of technical vulnerabilities; A.8.12 Data leakage prevention; A.8.13 Information backup; A.8.15 Logging; A.8.17 Clock synchronization; A.8.19 Installation of software on operational systems; A.8.20 Networks security; A.8.24 Use of cryptography

GDPR: Art. 5(1)(c) Data minimisation; Art. 5(1)(e) Storage limitation; Art. 5(1)(f) Integrity and confidentiality; Art. 25 Data protection by design and by default; Art. 28 Processor; Art. 30 Records of processing activities; Art. 32(1)(a) Security of processing: pseudonymisation and encryption; Art. 32(1)(b) Security of processing: confidentiality, integrity, availability and resilience; Art. 32(1)(c) Security of processing: restore availability and access after an incident; Art. 32(1)(d) Security of processing: regular testing and evaluation; Art. 33 Notification of a personal data breach to the supervisory authority; Art. 34 Communication of a personal data breach to the data subject; Art. 35 Data protection impact assessment; Art. 44 General principle for transfers

EU AI Act: Art. 4 AI literacy; Art. 5 Prohibited AI practices; Art. 6 Classification rules for high-risk AI systems; Art. 14 Human oversight; Art. 26 Obligations of deployers of high-risk AI systems; Art. 26(6) Deployers: keep automatically generated logs for at least six months; Art. 50 Transparency obligations for providers and deployers of certain AI systems; Annex III High-risk AI systems referred to in Article 6(2)