Governance. Risk. Compliance. Cybersecurity.
Controls & Requirements

Controls & Requirements — ADHICS v2

ADHICS v2 requires a defined, evidenced and continuously monitored control set. MAST maintains a unified control catalogue that maps each requirement to your existing controls — eliminating duplication.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Control domains

  • Governance
  • Asset management
  • Risk management
  • Human resources security
  • Physical and environmental security
  • Access control
  • Operations management
  • Communications, third-party and incident management
  • Health information and exchange
ADHICS v2 control coverage by domain

Horizontal bar chart titled "ADHICS v2 control coverage by domain". Values: Governance 70%, Asset management 83%, Risk management 96%, Human resources security 79%, Physical and environmental security 92%, Access control 75%.

  • Governance
    70%
  • Asset management
    83%
  • Risk management
    96%
  • Human resources security
    79%
  • Physical and environmental security
    92%
  • Access control
    75%

How we document each control

  • Statement of control and intent
  • Owner, executor and reviewer (RACI)
  • Frequency, trigger and operating window
  • Evidence type, location and retention
  • Linked risks and KRIs
  • Audit history and last test result
Control record fields

Checklist titled "Control record fields" with 6 items, every item marked complete: Statement of control and intent; Owner, executor and reviewer (RACI); Frequency, trigger and operating window; Evidence type, location and retention; Linked risks and KRIs; Audit history and last test result.

  • Statement of control and intent
  • Owner, executor and reviewer (RACI)
  • Frequency, trigger and operating window
  • Evidence type, location and retention
  • Linked risks and KRIs
  • Audit history and last test result

Mapping to adjacent frameworks

Our catalogue maps each control to ISO 27001, ISO 27701, SOC 2, NIST CSF, PCI DSS, CBUAE, SAMA, NCA ECC and ADHICS v2. One implementation, many audits.