OBL-17: Prescribed Security Safeguard Controls (Rule 6)
Implements continuous security monitoring, encryption, and audit log safeguards under Rule 6.
Statutory scope: Rule 6 (safeguard detail) · Assigned to Security / service owner · Systems: Consent Ledger & Policy Decision Point (SYS-010); SIEM & Security Telemetry Store (SYS-012)
Recommended interface: Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.
Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.
Governance & Architecture
Verification Specification & Workpaper
proposed per-row review/acceptance specification; not a claim of executed statutory coverage
populated hypothetical decision/specimen; not actual enterprise execution
Canonical Statutory Grounding
Source references verified against the official Gazette of India publication baseline.
Data Fiduciary; processors by contractual propagation
Protection of possessed/controlled data
Minimum security, access, visibility, continuity/backup, one-year security data/log retention, contract safeguards, organisational/technical measures.
r6(1)(e): unless compliance with law requires otherwise.