The OC5 subsidiary rules
OC5 states principles; the subsidiary rules make them operational, family by family: IAA (identities, authentication, authorization), SWR (software restrictions), NET (networking), EPT (endpoints), OPS (service operations), DPP (data protection and privacy), DEV (software development — where mandatory SecureFlag training for people who touch code lives).
Topology
- Part of: oc5
- Governs: password-policy — codified as an IAA rule.
- Governs: mfa-rollout — likewise.
- Cites: oc5-computing-rules — the family index.
- Cites: revised-security-rules — the approval history.