← CCPA/CPRA · Business obligations
1798.100(e) & 1798.150 — Reasonable security procedures
Requirement
The business implements reasonable security procedures and practices appropriate to the nature of the personal information to protect it from unauthorised or illegal access, destruction, use, modification or disclosure. Consumers whose non-encrypted and non-redacted personal information is breached as a result of a failure to do so may sue for statutory damages.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(f) | Integrity and confidentiality | encryption-at-rest access-control |
| SOC 2 | CC6.1 | Logical access provisioning and restriction | access-control encryption-at-rest |
| GDPR | Art.29 | Processing under the authority of the controller | access-control |
| GDPR | Art.32 | Security of processing | encryption-at-rest access-control |
| SOC 2 | CC6.2 | Registration and authorisation of new users | access-control |
| ISO 27001 | A.5.3 | Segregation of duties | access-control |
| ISO 27001 | A.5.15 | Access control | access-control |
| ISO 27001 | A.5.18 | Access rights review | access-control |