v0.3: phone check (iPhone, Android) as the Space front page, catalog 0.3 (74 checks), shared vulnerability rules, real-CVE training data
6ccf48e verified |
Download docs/CONTROLS.md from Devseis/Arx: direct link, hf CLI and curl.
- Browser
- Download file 33.6 kB
-
https://huggingface.co/spaces/Devseis/Arx/resolve/main/docs/CONTROLS.md
- Command line
-
hf download hf://spaces/Devseis/Arx/docs/CONTROLS.md
-
curl -L -o CONTROLS.md https://huggingface.co/spaces/Devseis/Arx/resolve/main/docs/CONTROLS.md
33.6 kB
| # Audited controls and data sources | |
| Catalog version 0.3.0 · 74 checks. Generated by `tools/build_controls_doc.py` — do not edit by hand. | |
| All sources are read-only. Internet is only used by *Pending security updates* on Windows and macOS, and by the app to refresh the vulnerability bundle. | |
| Phones are checked in the browser: a web page cannot read a phone's settings, so results are either detected by the browser or answered by the user (self-reported), and labelled as such. | |
| ## COMPLIANCE RESULTS (48) | |
| | Check | Applies to | References | Rule | Windows source | Linux source | macOS source | iPhone source | Android source | | |
| |---|---|---|---|---|---|---|---|---| | |
| | Minimum password length | windows, linux, macos | ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) | Configured minimum length >= PASSWORD_MIN_LENGTH. | secedit export: MinimumPasswordLength | PAM pam_pwquality minlen (/etc/security/pwquality.conf, PAM args) | pwpolicy -getaccountpolicies (minLength / regex) | — | — | | |
| | Password history | windows, linux, macos | ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) | Remembered passwords >= PASSWORD_HISTORY. | secedit export: PasswordHistorySize | pam_pwhistory remember (PAM args, /etc/security/pwhistory.conf) | pwpolicy: policyAttributePasswordHistoryDepth | — | — | | |
| | Password expiration | windows, linux, macos | ISO A.5.17; GDPR Art. 32(1)(b) | Passwords expire after 1..PASSWORD_MAX_AGE_DAYS days (0 in the baseline = expiry not required). | secedit export: MaximumPasswordAge | /etc/login.defs PASS_MAX_DAYS + /etc/shadow per account | pwpolicy: policyAttributeExpiresEveryNDays | — | — | | |
| | Minimum password age | windows, linux, macos | ISO A.5.17; GDPR Art. 32(1)(b) | Minimum age >= PASSWORD_MIN_AGE_DAYS days. macOS has no such setting (NotApplicable). | secedit export: MinimumPasswordAge | /etc/login.defs PASS_MIN_DAYS + /etc/shadow per account | not available on macOS (NotApplicable) | — | — | | |
| | Password complexity | windows, linux, macos | ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) | Complexity enforced (mixed character classes). | secedit export: PasswordComplexity | pam_pwquality minclass / dcredit-ucredit-lcredit-ocredit | pwpolicy: alpha + numeric requirements | — | — | | |
| | Account lockout threshold | windows, linux, macos | ISO A.8.5; GDPR Art. 32(1)(b) | Lockout after 1..LOCKOUT_THRESHOLD_MAX failed attempts (0 = never locks). | secedit export: LockoutBadCount | pam_faillock deny (PAM args, /etc/security/faillock.conf) | pwpolicy: policyAttributeMaximumFailedAuthentications | — | — | | |
| | Account lockout duration | windows, linux, macos | ISO A.8.5; GDPR Art. 32(1)(b) | Locked for >= LOCKOUT_DURATION_MIN_MINUTES minutes, or until an administrator unlocks. | secedit export: LockoutDuration | pam_faillock unlock_time | pwpolicy: autoEnableInSeconds | — | — | | |
| | Lockout observation period | windows, linux, macos | ISO A.8.5; GDPR Art. 32(1)(b) | Failed-attempt counter kept for >= LOCKOUT_OBSERVATION_MIN_MINUTES minutes. | secedit export: ResetLockoutCount | pam_faillock fail_interval | pwpolicy: autoEnableInSeconds (counter resets with lockout) | — | — | | |
| | Antivirus / Google Play Protect | windows, linux, macos, android | ISO A.8.7; GDPR Art. 32(1)(b) | An enabled, up-to-date antivirus product is present. Android: Google Play Protect scanning is on. | Security Center (root/SecurityCenter2 AntiVirusProduct) | systemd services: clamav-daemon, mdatp, falcon-sensor, sentinelone, sophos-spl, esets | XProtect version (xprotect version) + running third-party agents | — | asked: Play Store › your profile picture › Play Protect › Settings (gear icon) | | |
| | Malware protection service / Apple malware protection service / ClamAV malware protection service / Microsoft Defender Antimalware | windows, linux, macos | ISO A.8.7; GDPR Art. 32(1)(b) | The platform malware protection service is running. | Get-MpComputerStatus: AMServiceEnabled, AntivirusEnabled | systemctl is-active clamav-daemon / clamd | xprotect status + spctl --status (Gatekeeper) | — | — | | |
| | Real-time protection | windows | ISO A.8.7; GDPR Art. 32(1)(b) | Defender real-time protection is on. | Get-MpComputerStatus: RealTimeProtectionEnabled | — | — | — | — | | |
| | On-access malware protection / On-access protection | windows, linux, macos | ISO A.8.7; GDPR Art. 32(1)(b) | Files are scanned when opened. macOS: NotApplicable unless a third-party scanner provides it. | Get-MpComputerStatus: OnAccessProtectionEnabled | clamav-clamonacc service / clamonacc process | third-party agent only (XProtect has no on-access scan) | — | — | | |
| | Tamper protection | windows | ISO A.8.7; GDPR Art. 32(1)(b) | Defender tamper protection is on. | Get-MpComputerStatus: IsTamperProtected | — | — | — | — | | |
| | Malware signatures / Malware protection signatures / Security intelligence | windows, linux, macos | ISO A.8.7; ISO A.8.8; GDPR Art. 32(1)(b) | Signatures no older than SIGNATURE_MAX_AGE_DAYS (macOS XProtect: MACOS_XPROTECT_MAX_AGE_DAYS). | Get-MpComputerStatus: AntivirusSignatureAge | age of /var/lib/clamav/daily.c[lv]d | XProtect install date (xprotect version / XProtect.meta.plist) | — | — | | |
| | Malware signature updates / Malware security updates | linux, macos | ISO A.8.7; ISO A.8.8; GDPR Art. 32(1)(b) | Automatic signature/security-data updates are enabled. | — | systemctl is-active clamav-freshclam | com.apple.SoftwareUpdate ConfigDataInstall + CriticalUpdateInstall | — | — | | |
| | Firewall | linux, macos | ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) | A host firewall is active. | — | ufw status / firewalld / nft list ruleset / iptables -S | socketfilterfw --getglobalstate | — | — | | |
| | Firewall inbound policy | linux, macos | ISO A.8.20; GDPR Art. 32(1)(b) | Unsolicited inbound traffic is blocked by default (macOS: firewall on with stealth mode). | — | ufw default incoming / firewalld zone target / nft input policy | socketfilterfw --getstealthmode | — | — | | |
| | Firewall outbound policy | linux, macos | ISO A.8.20; GDPR Art. 32(1)(b) | Default outbound policy equals FIREWALL_OUTBOUND. | — | ufw default outgoing / nft output policy | application firewall is inbound-only | — | — | | |
| | Domain firewall | windows | ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) | Domain profile enabled. | Get-NetFirewallProfile -PolicyStore ActiveStore (Domain) | — | — | — | — | | |
| | Domain inbound | windows | ISO A.8.20; GDPR Art. 32(1)(b) | Domain profile default inbound action is Block. | Get-NetFirewallProfile: DefaultInboundAction (Domain) | — | — | — | — | | |
| | Domain outbound | windows | ISO A.8.20; GDPR Art. 32(1)(b) | Domain profile default outbound action equals FIREWALL_OUTBOUND. | Get-NetFirewallProfile: DefaultOutboundAction (Domain) | — | — | — | — | | |
| | Private firewall | windows | ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) | Private profile enabled. | Get-NetFirewallProfile -PolicyStore ActiveStore (Private) | — | — | — | — | | |
| | Private inbound | windows | ISO A.8.20; GDPR Art. 32(1)(b) | Private profile default inbound action is Block. | Get-NetFirewallProfile: DefaultInboundAction (Private) | — | — | — | — | | |
| | Private outbound | windows | ISO A.8.20; GDPR Art. 32(1)(b) | Private profile default outbound action equals FIREWALL_OUTBOUND. | Get-NetFirewallProfile: DefaultOutboundAction (Private) | — | — | — | — | | |
| | Public firewall | windows | ISO A.8.20; ISO A.8.1; GDPR Art. 32(1)(b) | Public profile enabled. | Get-NetFirewallProfile -PolicyStore ActiveStore (Public) | — | — | — | — | | |
| | Public inbound | windows | ISO A.8.20; GDPR Art. 32(1)(b) | Public profile default inbound action is Block. | Get-NetFirewallProfile: DefaultInboundAction (Public) | — | — | — | — | | |
| | Public outbound | windows | ISO A.8.20; GDPR Art. 32(1)(b) | Public profile default outbound action equals FIREWALL_OUTBOUND. | Get-NetFirewallProfile: DefaultOutboundAction (Public) | — | — | — | — | | |
| | Screen lock / Passcode | windows, linux, macos, ios, android | ISO A.8.1; ISO A.7.7; GDPR Art. 32(1)(b) | The screen locks when idle (Windows: machine inactivity limit or a password-protected screen saver). Phones: a passcode / PIN / password screen lock is set. | InactivityTimeoutSecs policy or users' ScreenSaveActive/ScreenSaverIsSecure (HKU) | gsettings org.gnome.desktop.screensaver lock-enabled + session idle-delay (per user) | sysadminctl -screenLock status / managed com.apple.screensaver | detected: WebAuthn platform authenticator available; otherwise asked; asked: Settings › Face ID & Passcode (or Touch ID & Passcode). If it asks for your passcode before opening, one is set. | detected: WebAuthn platform authenticator available; otherwise asked; asked: Settings › Security & privacy › Device unlock › Screen lock (names vary by phone maker) | | |
| | Screen lock timeout / Auto-Lock / Screen timeout | windows, linux, macos, ios, android | ISO A.8.1; ISO A.7.7; GDPR Art. 32(1)(b) | Idle time before lock (including any grace delay) is 1..SCREEN_LOCK_MAX_SECONDS seconds (baseline: 300 = 5 minutes). Phones: Auto-Lock / screen timeout. | InactivityTimeoutSecs policy or users' ScreenSaveTimeOut (HKU) | gsettings idle-delay + lock-delay (per user) | screen saver idleTime + pmset displaysleep + password delay | asked: Settings › Display & Brightness › Auto-Lock | asked: Settings › Display › Screen timeout. If there is also 'Lock after screen timeout', it should be Immediately. | | |
| | Screen lock password requirement | windows, linux, macos | ISO A.8.1; ISO A.7.7; ISO A.8.5; GDPR Art. 32(1)(b) | A password is required to unlock (macOS: within 5 seconds of the screen locking). | InactivityTimeoutSecs policy or users' ScreenSaverIsSecure; DisableLockWorkstation | gsettings lock-enabled + lockdown disable-lock-screen | sysadminctl -screenLock delay / managed askForPassword | — | — | | |
| | Passcode strength / Screen lock strength | ios, android | ISO A.5.17; ISO A.8.5; GDPR Art. 32(1)(b) | Passcode / PIN has at least MOBILE_PASSCODE_MIN_DIGITS digits, or is alphanumeric. Android pattern or swipe locks do not comply. | — | — | — | asked: The code you type to unlock. Settings › Face ID & Passcode › Change Passcode › Passcode Options shows the choices. | asked: Settings › Security & privacy › Device unlock › Screen lock | | |
| | Operating system integrity / Not jailbroken / Not rooted | ios, android | ISO A.8.1; ISO A.8.7; ISO A.8.19; GDPR Art. 32(1)(b) | The phone is not jailbroken (iOS) or rooted / bootloader-unlocked (Android). | — | — | — | asked: Jailbreaking means deliberately modifying iOS to install apps outside Apple's control. If nobody did this on purpose, answer No. | asked: Rooting means deliberately giving apps full system access. If nobody did this on purpose, answer No. | | |
| | App sources restricted / Apps only from the App Store / Install unknown apps blocked | ios, android | ISO A.8.1; ISO A.8.7; ISO A.8.19; GDPR Art. 32(1)(b) | Apps are installed only from the official store (no alternative marketplaces, web distribution or unknown sources). | — | — | — | asked: Settings › General › VPN & Device Management lists developer or enterprise profiles. Alternative app marketplaces appear as separate apps. | asked: Settings › Apps › Special app access › Install unknown apps. Every app should show 'Not allowed'. | | |
| | USB debugging off | android | ISO A.8.1; ISO A.8.19; GDPR Art. 32(1)(b) | Developer options / USB debugging are off. | — | — | — | — | asked: Settings › System › Developer options › USB debugging. If you cannot find Developer options, they are off. | | |
| | Find and erase a lost device / Find My Device / Find My iPhone | ios, android | ISO A.5.9; ISO A.8.1; GDPR Art. 32(1)(b); GDPR Art. 32(1)(c) | Find My iPhone / Find My Device is on, so a lost phone can be located, locked and erased. | — | — | — | asked: Settings › [your name] › Find My › Find My iPhone | asked: Settings › Google › All services › Find My Device (called Find Hub on newer phones) | | |
| | USB storage device access | windows, linux, macos | ISO A.7.10; ISO A.8.12; GDPR Art. 32(1)(b) | Whether USB mass storage devices can connect at all equals USB_DEVICE_ACCESS (allow/deny): driver, device-installation policy, USBGuard or MDM restriction. | RemovableStorageDevices Deny_All policy, USBSTOR service Start | modprobe usb-storage install rule / blacklist / USBGuard | managed com.apple.systemuiserver mount-controls | — | — | | |
| | USB storage read | windows, linux, macos | ISO A.7.10; ISO A.8.12; GDPR Art. 32(1)(b) | Effective USB storage read access equals USB_READ (allow/deny). | RemovableStorageDevices policies (Deny_All, Deny_Read), USBSTOR Start | usb-storage module rules, USBGuard | managed mount-controls (deny) | — | — | | |
| | USB storage write | windows, linux, macos | ISO A.7.10; ISO A.8.12; GDPR Art. 32(1)(b) | Effective USB storage write access equals USB_WRITE (allow/deny). | RemovableStorageDevices Deny_Write, StorageDevicePolicies WriteProtect | udev read-only rules, usb-storage rules, USBGuard | managed mount-controls (deny / read-only) | — | — | | |
| | Approved IT administrator | windows, linux, macos | ISO A.8.2; ISO A.5.15; GDPR Art. 32(1)(b) | At least one account listed in APPROVED_ADMINS is an enabled administrator. | Administrators group by SID S-1-5-32-544 (ADSI) + Get-LocalUser | getent group sudo/admin/wheel, UID 0 accounts, /etc/sudoers(.d) | dscl . -read /Groups/admin GroupMembership | — | — | | |
| | Unauthorized employee administrator accounts / Unauthorized employee local administrator accounts | windows, linux, macos | ISO A.8.2; ISO A.5.18; GDPR Art. 32(1)(b) | No administrator accounts other than APPROVED_ADMINS (and the disabled built-in Administrator on Windows). | Administrators group by SID S-1-5-32-544 (ADSI) + Get-LocalUser | getent group sudo/admin/wheel, UID 0 accounts, /etc/sudoers(.d) | dscl . -read /Groups/admin GroupMembership | — | — | | |
| | BitLocker | windows | ISO A.8.24; ISO A.8.1; GDPR Art. 32(1)(a) | BitLocker is turned on for the system drive. | Get-BitLockerVolume (system drive): VolumeStatus | — | — | — | — | | |
| | Encryption / Data protection (encryption) / Device encryption | windows, linux, macos, ios, android | ISO A.8.24; ISO A.8.1; GDPR Art. 32(1)(a) | The system disk is fully encrypted (BitLocker / LUKS / FileVault). Phones: iOS data protection is on when a passcode is set; Android 10+ encrypts by default. | Get-BitLockerVolume: VolumeStatus, EncryptionPercentage | findmnt / + lsblk (crypt device under /) | fdesetup status | derived: on when a passcode is set (iOS data protection) | detected: Android 10+ encrypts by default | | |
| | Disk encryption protection / BitLocker protection | windows, linux, macos | ISO A.8.24; GDPR Art. 32(1)(a) | Encryption protection is active (not suspended or in progress) with a strong cipher. | Get-BitLockerVolume: ProtectionStatus, EncryptionMethod | cryptsetup status (type, cipher, key size) | fdesetup status (no encryption in progress) | — | — | | |
| | Disk encryption recovery / BitLocker recovery | windows, linux, macos | ISO A.8.24; ISO A.8.13; GDPR Art. 32(1)(a); GDPR Art. 32(1)(c) | A recovery key or second unlock method exists. | Get-BitLockerVolume: KeyProtector (RecoveryPassword) | cryptsetup luksDump (key slots, tokens) | fdesetup haspersonalrecoverykey / hasinstitutionalrecoverykey | — | — | | |
| | Signed-in user account type | windows, linux, macos | ISO A.8.2; ISO A.5.15; GDPR Art. 32(1)(b) | The everyday signed-in user is a Standard account (not an administrator), unless listed in APPROVED_ADMINS. | signed-in user (Win32_ComputerSystem) vs Administrators group | session users (loginctl) vs sudo/admin/wheel | console user (stat /dev/console) + dsmemberutil checkmembership | — | — | | |
| | Pending security updates / Android security update / iOS security updates | windows, linux, macos, ios, android | ISO A.8.8; GDPR Art. 32(1)(b); GDPR Art. 32(1)(d) | Security updates offered by the OS vendor but not yet installed <= MAX_PENDING_SECURITY_UPDATES. Phones: iOS is at the latest security release known to the vulnerability data; Android security patch level is at most MOBILE_PATCH_MAX_AGE_DAYS old. | Windows Update Agent API (Microsoft.Update.Session search) - needs internet | apt-get -s upgrade (security) / dnf updateinfo --security - uses local package lists | softwareupdate -l - needs internet | detected: iOS version vs newest fixed release in the signed phone bundle | asked: Settings › About phone › Android version › Android security update (or Settings › Security & privacy › Updates) | | |
| | Outdated third-party applications / App updates | windows, linux, macos, ios, android | ISO A.8.8; ISO A.8.19; GDPR Art. 32(1)(b) | Installed third-party applications with a newer version available <= MAX_OUTDATED_APPS (Windows: winget; macOS: app versions; Linux: snap/flatpak and packages). Phones: automatic app updates are on. | winget upgrade | apt upgradable, snap refresh --list, flatpak updates | brew outdated (Homebrew; App Store apps not covered) | asked: Settings › App Store › App Updates | asked: Play Store › your profile picture › Settings › Network preferences › Auto-update apps | | |
| | Known vulnerabilities in installed software / Known vulnerabilities in iOS | windows, linux, macos, ios | ISO A.8.8; GDPR Art. 32(1)(b) | Installed software versions matched against an offline copy of the OSV/NVD vulnerability data: critical or high vulnerabilities <= MAX_CRITICAL_HIGH_VULNERABILITIES. iOS: the iOS version is matched against NVD iOS/iPadOS records. | installed programs (machine and per-user uninstall registry) matched by the app against the signed offline bundle (NVD ranges, CISA KEV, EPSS) | dpkg/rpm package list (with source packages) matched by the app against the signed offline bundle (OSV: Ubuntu, Debian, RHEL, AlmaLinux, Rocky) | app bundle versions (/Applications, ~/Applications) matched by the app against the signed offline bundle (NVD ranges, CISA KEV, EPSS) | detected: iOS version matched against NVD iOS/iPadOS records in the signed phone bundle | — | | |
| ## GDPR TECHNICAL CONTROLS (13) | |
| | Check | Applies to | References | Rule | Windows source | Linux source | macOS source | iPhone source | Android source | | |
| |---|---|---|---|---|---|---|---|---| | |
| | Automatic security updates / Automatic iOS updates / Automatic system updates | windows, linux, macos, ios, android | ISO A.8.8; GDPR Art. 32(1)(b) | Security updates are downloaded and installed automatically. | WindowsUpdate\AU policy (NoAutoUpdate, AUOptions), wuauserv start type | apt-config Unattended-Upgrade / dnf-automatic timer | com.apple.SoftwareUpdate AutomaticCheck/Download/Install keys | asked: Settings › General › Software Update › Automatic Updates | asked: Settings › System › Software updates (names vary: 'Auto download over Wi-Fi', 'Automatic system updates') | | |
| | Security updates installed recently | windows, linux, macos | ISO A.8.8; GDPR Art. 32(1)(b); GDPR Art. 32(1)(d) | Last successful update/package change within UPDATES_MAX_AGE_DAYS days. | Windows Update history (COM) or Get-HotFix | /var/log/apt/history.log / rpm -qa --last | /Library/Receipts/InstallHistory.plist (softwareupdated) | — | — | | |
| | Supported operating system version | windows, linux, macos, ios, android | ISO A.8.8; GDPR Art. 32(1)(b) | The OS version still receives security updates (minimums in the baseline). Phones: IOS_MIN_MAJOR / ANDROID_MIN_MAJOR. | Win32_OperatingSystem BuildNumber vs WINDOWS_MIN_BUILD | /etc/os-release VERSION_ID vs baseline minimum | sw_vers -productVersion vs MACOS_MIN_MAJOR | detected: OS version (Safari version on iOS 26+, client hints on Android), confirmed by the user | detected: OS version (Safari version on iOS 26+, client hints on Android), confirmed by the user | | |
| | Security event logging | windows, linux, macos | ISO A.8.15; GDPR Art. 32(1)(d); GDPR Art. 33 | Logon and account-change events are recorded (Windows audit policy, Linux auditd, macOS unified log). | auditpol /backup (Logon, User Account Management) + legacy audit policy | systemctl is-active auditd, journal persistence | logd running (unified logging) | — | — | | |
| | Time synchronisation / Date & time set automatically | windows, linux, macos, ios, android | ISO A.8.17; GDPR Art. 33 | The clock is synchronised from a time server. | W32Time Parameters Type + service start type | timedatectl NTP / chronyd / ntpd | systemsetup -getusingnetworktime (needs root) | asked: Settings › General › Date & Time | asked: Settings › System › Date & time | | |
| | Backup configured / Google backup / iCloud Backup | windows, linux, macos, ios, android | ISO A.8.13; GDPR Art. 32(1)(c) | A backup solution is configured for user data. | OneDrive KFM policy, File History config, backup agent services | Timeshift config, Deja Dup (gsettings), restic/borg timers | tmutil destinationinfo, backup agent processes | asked: Settings › [your name] › iCloud › iCloud Backup | asked: Settings › Google › Backup (or Settings › System › Backup; Samsung: Accounts and backup) | | |
| | Recent backup | windows, linux, macos | ISO A.8.13; GDPR Art. 32(1)(c) | Last backup within BACKUP_MAX_AGE_DAYS days (Pending when the date cannot be read). | not readable for most tools (Pending) | Timeshift snapshot names, Deja Dup last-backup | tmutil latestbackup | — | — | | |
| | Removable media encryption | windows, linux, macos | ISO A.7.10; ISO A.8.24; GDPR Art. 32(1)(a); GDPR Art. 34 | Data cannot be written to unencrypted removable drives. | FVE RDVDenyWriteAccess (BitLocker To Go) or USB write denied | USB write denied | USB write denied | — | — | | |
| | Guest account disabled | windows, linux, macos | ISO A.5.16; ISO A.8.5; GDPR Art. 32(1)(b) | No enabled guest login. | Get-LocalUser (SID -501): Enabled | LightDM allow-guest, 'guest' account shell | com.apple.loginwindow GuestEnabled, SMB AllowGuestAccess | — | — | | |
| | Remote access services restricted | windows, linux, macos | ISO A.8.20; ISO A.6.7; GDPR Art. 32(1)(b) | Only remote access services listed in APPROVED_REMOTE_SERVICES are enabled. | fDenyTSConnections (RDP), sshd/WinRM/TeamViewer/AnyDesk/chromoting services, non-admin SMB shares | ssh/xrdp/vnc/samba/teamviewer/anydesk/chrome-remote-desktop | launchctl print-disabled (sshd, screensharing, smbd, chromoting), ARDAgent/TeamViewer/AnyDesk | — | — | | |
| | Diagnostic data minimised / Analytics sharing minimised / Usage & diagnostics sharing minimised | windows, linux, macos, ios, android | ISO A.5.34; GDPR Art. 5(1)(c); GDPR Art. 25 | OS diagnostic/usage data sharing is at the minimum level. | DataCollection AllowTelemetry (policy / Settings) | popularity-contest, whoopsie | DiagnosticMessagesHistory AutoSubmit, ThirdPartyDataSubmit | asked: Settings › Privacy & Security › Analytics & Improvements | asked: Settings › Google › All services › Usage & diagnostics (also check the phone maker's diagnostics option) | | |
| | Notification content hidden on the lock screen / Notification previews hidden when locked / Sensitive notifications hidden when locked | ios, android | ISO A.7.7; ISO A.8.1; GDPR Art. 5(1)(f); GDPR Art. 32(1)(b) | Message and email previews are not shown on the locked screen. | — | — | — | asked: Settings › Notifications › Show Previews | asked: Settings › Notifications › Notifications on lock screen (or Settings › Privacy) | | |
| | Personal data discovery | windows, linux, macos | ISO A.5.34; ISO A.5.12; GDPR Art. 5(1)(c); GDPR Art. 5(1)(e); GDPR Art. 30 | Opt-in scan of user folders for personal data patterns (counts and paths only). Not implemented in stage 1: NotApplicable. | planned opt-in scan | planned opt-in scan | planned opt-in scan | — | — | | |
| ## EU AI ACT CONTROLS (5) | |
| | Check | Applies to | References | Rule | Windows source | Linux source | macOS source | iPhone source | Android source | | |
| |---|---|---|---|---|---|---|---|---| | |
| | AI software inventory | windows, linux, macos, ios, android | ISO A.5.9; GDPR Art. 30; AI Act Art. 26 | AI apps, local AI services and local model folders are listed (Compliant = inventory taken). | uninstall registry + Store apps (AI apps), port 11434, model folders, Claude Code CLI | AI CLIs, snaps, flatpaks, /opt apps, port 11434, model folders | /Applications AI apps, AI CLIs, port 11434, model folders | asked: AI apps installed (checklist); classified by the auditor model | asked: AI apps installed (checklist); classified by the auditor model | | |
| | Unapproved AI tools (shadow AI) | windows, linux, macos, ios, android | ISO A.5.9; ISO A.8.19; GDPR Art. 28; GDPR Art. 44; AI Act Art. 26 | Every AI tool found is listed in APPROVED_AI_TOOLS. | AI inventory vs APPROVED_AI_TOOLS | AI inventory vs APPROVED_AI_TOOLS | AI inventory vs APPROVED_AI_TOOLS | asked: AI apps installed (checklist); classified by the auditor model | asked: AI apps installed (checklist); classified by the auditor model | | |
| | AI system risk classification | windows, linux, macos, ios, android | ISO A.5.9; AI Act Art. 5; AI Act Art. 6; AI Act Annex III | Each AI tool found is classified (prohibited / high-risk / limited / minimal). Done by the auditor model: Pending in the collector output, NotApplicable when no AI tool is found. | AI inventory, classified by the model | AI inventory, classified by the model | AI inventory, classified by the model | asked: AI apps installed (checklist); classified by the auditor model | asked: AI apps installed (checklist); classified by the auditor model | | |
| | Operating system AI features restricted / AI assistant access restricted / Apple Intelligence external integrations restricted / Windows Recall / Copilot data analysis disabled | windows, linux, macos, ios, android | ISO A.5.34; GDPR Art. 5(1)(c); GDPR Art. 25; AI Act Art. 26 | OS-level AI features that capture or send user data are disabled by policy. NotApplicable where the OS has none. Phones: external AI integrations (ChatGPT in Apple Intelligence, assistant access to screen content) are off unless approved. | WindowsAI policies (DisableAIDataAnalysis, AllowRecallEnablement), Recall optional feature | none built in (NotApplicable) | managed com.apple.applicationaccess allowExternalIntelligenceIntegrations (Apple silicon) | asked: Settings › Apple Intelligence & Siri › ChatGPT (only on iPhones that support Apple Intelligence) | asked: Gemini app › your profile picture › Settings › 'Screen context' / 'Use screen context' (other assistants have similar options) | | |
| | AI usage log retention | windows, linux, macos, ios, android | ISO A.8.15; AI Act Art. 26(6) | Logs kept >= 6 months if a high-risk AI system is used. Pending until classification; NotApplicable when no AI tool is found. | depends on AI classification | depends on AI classification | depends on AI classification | asked: AI apps installed (checklist); classified by the auditor model | asked: AI apps installed (checklist); classified by the auditor model | | |
| ## ORGANISATIONAL CONTROLS (8) | |
| | Check | Applies to | References | Rule | Windows source | Linux source | macOS source | iPhone source | Android source | | |
| |---|---|---|---|---|---|---|---|---| | |
| | Record of processing activities | windows, linux, macos, ios, android | ISO A.5.34; GDPR Art. 30 | Answer yes = Compliant, no/partial = Non-Compliant, n/a = NotApplicable, unanswered = Pending. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | Data protection impact assessment | windows, linux, macos, ios, android | ISO A.5.34; GDPR Art. 35 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | Breach response procedure | windows, linux, macos, ios, android | ISO A.5.24; ISO A.5.26; GDPR Art. 33; GDPR Art. 34 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | Data processing agreements | windows, linux, macos, ios, android | ISO A.5.20; GDPR Art. 28 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | AI register | windows, linux, macos, ios, android | ISO A.5.9; AI Act Art. 26 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | AI literacy training | windows, linux, macos, ios, android | ISO A.6.3; AI Act Art. 4 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | Human oversight for high-risk AI | windows, linux, macos, ios, android | AI Act Art. 14; AI Act Art. 26 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| | AI transparency to users | windows, linux, macos, ios, android | AI Act Art. 50 | As above. | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation) | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | organisational.conf (answered once by the organisation); Pending in a phone check unless passed in the link | | |
| ## Reference titles | |
| **ISO/IEC 27001:2022 Annex A:** A.5.9 Inventory of information and other associated assets; A.5.12 Classification of information; A.5.15 Access control; A.5.16 Identity management; A.5.17 Authentication information; A.5.18 Access rights; A.5.20 Addressing information security within supplier agreements; A.5.24 Information security incident management planning and preparation; A.5.26 Response to information security incidents; A.5.34 Privacy and protection of PII; A.6.3 Information security awareness, education and training; A.6.7 Remote working; A.7.7 Clear desk and clear screen; A.7.10 Storage media; A.8.1 User endpoint devices; A.8.2 Privileged access rights; A.8.5 Secure authentication; A.8.7 Protection against malware; A.8.8 Management of technical vulnerabilities; A.8.12 Data leakage prevention; A.8.13 Information backup; A.8.15 Logging; A.8.17 Clock synchronization; A.8.19 Installation of software on operational systems; A.8.20 Networks security; A.8.24 Use of cryptography | |
| **GDPR:** Art. 5(1)(c) Data minimisation; Art. 5(1)(e) Storage limitation; Art. 5(1)(f) Integrity and confidentiality; Art. 25 Data protection by design and by default; Art. 28 Processor; Art. 30 Records of processing activities; Art. 32(1)(a) Security of processing: pseudonymisation and encryption; Art. 32(1)(b) Security of processing: confidentiality, integrity, availability and resilience; Art. 32(1)(c) Security of processing: restore availability and access after an incident; Art. 32(1)(d) Security of processing: regular testing and evaluation; Art. 33 Notification of a personal data breach to the supervisory authority; Art. 34 Communication of a personal data breach to the data subject; Art. 35 Data protection impact assessment; Art. 44 General principle for transfers | |
| **EU AI Act:** Art. 4 AI literacy; Art. 5 Prohibited AI practices; Art. 6 Classification rules for high-risk AI systems; Art. 14 Human oversight; Art. 26 Obligations of deployers of high-risk AI systems; Art. 26(6) Deployers: keep automatically generated logs for at least six months; Art. 50 Transparency obligations for providers and deployers of certain AI systems; Annex III High-risk AI systems referred to in Article 6(2) | |