Legal Register
Control Workpaper
OBL-17 Rule 6 (safeguard detail) RULE-6

OBL-17: Prescribed Security Safeguard Controls (Rule 6)

Implements continuous security monitoring, encryption, and audit log safeguards under Rule 6.

Statutory scope: Rule 6 (safeguard detail) · Assigned to Security / service owner · Systems: Consent Ledger & Policy Decision Point (SYS-010); SIEM & Security Telemetry Store (SYS-012)

Operational Interface Requirement

Recommended interface: Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.

Expected Audit Assertion / Test Result

Supply forged purpose or stale authority; expected outcome is deny. Deployment identity, key and direct-store controls still require actual integration tests.

Governance & Architecture

Recommended Activity Owner
Security / service owner
Target Systems & Interfaces

Verification Specification & Workpaper

Proposed Test Specimen ID
SPEC-Q10-OBL-17

proposed per-row review/acceptance specification; not a claim of executed statutory coverage

Populated Teaching Workpaper
out/dossier/CASE-001/security-decisions.json

populated hypothetical decision/specimen; not actual enterprise execution

Local Execution Reference
out/dossier/CASE-001/tests/results.json

Canonical Statutory Grounding

Source references verified against the official Gazette of India publication baseline.

RULE-6 Lines 1087–1111
Commencement: 2027-05-13 (scheduled, not yet operative)
Obligated Actor

Data Fiduciary; processors by contractual propagation

Trigger Context

Protection of possessed/controlled data

Statutory Conditions

Minimum security, access, visibility, continuity/backup, one-year security data/log retention, contract safeguards, organisational/technical measures.

Statutory Exceptions

r6(1)(e): unless compliance with law requires otherwise.