To ensure compliance with legal requirements the following controls may be necessary:
Identification of applicable legislation:
All relevant statutory, regulatory and contractual requirements should be explicitly defined and documented for each information system
The specific controls and individual responsibilities to meet these requirements should be similarly defined and documented.
Intellectual property rights:
Appropriate procedures shall be implemented to ensure compliance with legal restrictions on the use of material in respect of intellectual property rights, and on the use of proprietary software products
Safeguarding of organisational records:
Important records of an organisation shall be protected from loss, destruction and falsification.