
A.18.1.3: Protection of Records
Ensure that records are protected from loss, destruction, falsification, unauthorized access, and unauthorized release.

A.12.1.4: Separation of Development, Testing, and Operational Environments
Implement separation of development, testing, and operational environments to reduce risks from unauthorized access or changes.

A.12.1.3: Capacity Management
Monitor, tune, and review capacity requirements to ensure continuous availability.

A.12.1.2: Change Management
Implement change management procedures to ensure that changes to information processing facilities and systems are controlled.

A.12.1.1: Documented Operating Procedures
Document and maintain operating procedures for information processing facilities.