CIAO Essential · Level 2
Grants the full set of sub-policies across all nine domains.
Sub-Policies
CAO-100 Governance
- CAO-110 Information Governance Policy
- CAO-120 Board Charter
- CAO-130 Data Governance Policy
- CAO-140 Corporate Governance Policy
- CAO-150 Technology Governance Policy
- CAO-160 Quality Management Policy
- CAO-170 Remuneration Policy
- CAO-190 Security Governance Policy
CAO-200 Audit and Risk
CAO-300 Privacy
- CAO-310 Consent Management Policy
- CAO-320 Data Subject Rights Policy
- CAO-330 Privacy by Design Policy
- CAO-340 Information Classification Policy
- CAO-350 Information Transfer Policy
- CAO-360 Records Management Policy
- CAO-370 Data Protection and Privacy Policy
CAO-400 Cybersecurity
- CAO-410 Access Control Policy
- CAO-420 Network Security Policy
- CAO-430 Cryptography and Data Encryption Policy
- CAO-450 Operations Security Policy
- CAO-460 Threat and Vulnerability Management Policy
- CAO-470 Incident Response Policy
- CAO-480 Secure Software Development Policy
- CAO-490 People and Physical Security Policy
CAO-500 Emerging Technology Governance
- CAO-510 AI Policy
- CAO-520 AI Risk Management Policy
- CAO-530 AI Transparency and Explainability Policy
- CAO-540 AI Data Governance Policy
CAO-600 Technology Platform Operations
- CAO-610 Operational Resilience Policy
- CAO-620 Business Continuity and Disaster Recovery Policy
- CAO-630 Configuration, Change and Asset Management Policy
- CAO-640 Service Management Policy
CAO-700 Supply Chain
CAO-800 Regulatory Compliance
CAO-900 Sustainability
Featured Control Areas
A taster of the Professional layer — the two most standards-dense control areas in each sub-policy:
CAO-100 Governance
- CAO-121 Board Composition and Independence
- CAO-122 Succession and Evaluation
- CAO-141 Board Leadership and Accountability
- CAO-142 Governance Roles and Responsibilities
- CAO-145 Transparency and Disclosure
- CAO-151 IT Strategy and Value
- CAO-152 IT Oversight and Conformance
- CAO-161 Quality Management System
- CAO-171 Remuneration Governance
- CAO-192 Information Security Governance
CAO-200 Audit and Risk
- CAO-211 Risk Governance and Appetite
- CAO-212 Risk Identification and Assessment
- CAO-221 Audit Oversight
- CAO-222 Conformance and Independent Review
CAO-300 Privacy
- CAO-311 Privacy Notice and Transparency
- CAO-312 Obtaining Consent
- CAO-321 Right of Access
- CAO-322 Rectification and Erasure
- CAO-331 Privacy by Design and Default
- CAO-341 Information Classification
- CAO-342 Information Labelling
- CAO-351 Information Transfer
- CAO-361 Records of Processing
- CAO-362 Records Retention and Documentation
- CAO-371 Lawful Basis for Processing
- CAO-372 Data Minimisation and Limitation
CAO-400 Cybersecurity
- CAO-411 Access Control Governance
- CAO-413 Authentication
- CAO-421 Network Security Management
- CAO-424 Cloud Network Security
- CAO-431 Cryptographic Controls
- CAO-438 Data Security Management
- CAO-451 Operating Procedures
- CAO-455 Security Monitoring and Detection
- CAO-461 Malware Protection
- CAO-462 Technical Vulnerability Management
- CAO-471 Incident Management Planning
- CAO-473 Incident Response
- CAO-481 Secure Development Lifecycle
- CAO-482 Secure Coding
- CAO-491 Human Resources Security
- CAO-492 Security Awareness and Training
CAO-500 Emerging Technology Governance
- CAO-511 AI Governance
- CAO-512 Human Oversight
- CAO-521 AI Risk and Impact
- CAO-531 AI Transparency
- CAO-541 AI Data and Fairness
CAO-600 Technology Platform Operations
- CAO-611 Availability and Capacity
- CAO-612 Operational Resilience
- CAO-621 Business Continuity Management
- CAO-622 Disaster Recovery
- CAO-631 Configuration and Change Management
- CAO-632 Asset Management
- CAO-641 Incident and Request Management
- CAO-643 Service Level Management
CAO-700 Supply Chain
CAO-800 Regulatory Compliance
CAO-900 Sustainability
- CAO-911 Ethics and Corporate Citizenship
- CAO-922 Materiality and Strategy
- CAO-923 Sustainability Statement Preparation
- CAO-931 Climate Change
- CAO-935 Resource Use and Circular Economy
- CAO-941 Own Workforce
- CAO-943 Affected Communities
Unlock CIAO Professional
Grants the full sub-sub-policy detail beneath every sub-policy — the organisational control areas and their objectives.
View membership options ↗