ISO 27001
ISO/IEC 27001:2022 Annex A
Helps support Annex A information transfer, access, cryptography, logging, monitoring, and secure disposal evidence across the 2022 control themes.
Certification support
Steek does not certify an organization by itself. It helps compliance, security, legal, healthcare, payment, finance, and audit teams produce defensible evidence for the controlled delivery part of ISO 27001, NIST CSF 2.0, NIS2, SOC 2, COBIT, GDPR, HIPAA, PCI DSS, and DORA programs.
Framework coverage
The same controlled delivery events can support multiple control families: verified identity, access restriction, protected transfer, revocation, retention, incident review, and supplier communication evidence.
ISO 27001
Helps support Annex A information transfer, access, cryptography, logging, monitoring, and secure disposal evidence across the 2022 control themes.
NIST CSF 2.0
Maps secure delivery evidence to Govern, Identify, Protect, Detect, Respond, and Recover outcomes in CSF 2.0.
NIS2
Supports Article 21 cybersecurity risk-management measures for secure communication, access control, cryptography, supply-chain handoffs, and incident handling.
Control mapping
Each row lists the framework's control or requirement ID and the specific Steek delivery evidence that can help your company satisfy that part of the control.
ISO 27001
Helps support Annex A information transfer, access, cryptography, logging, monitoring, and secure disposal evidence across the 2022 control themes.
Organizational controls
Policy, asset handling, access governance, supplier delivery, incident readiness, and evidence collection.
Control
A.5.10
Restricts sensitive document exchange to a controlled delivery workflow instead of reusable attachments or public file links.
Control
A.5.12
Supports classified confidential handoffs with delivery records that do not expose plaintext content or source document metadata.
Control
A.5.14
Provides encrypted transfer, recipient verification, expiry, revocation, and QR handoff evidence for sensitive exchanges.
Control
A.5.15
Limits document opens to intended recipients and records access decisions for later review.
Control
A.5.16
Ties recipient access to passkey-verified identity rather than possession of a forwarded link.
Control
A.5.24
Gives teams delivery and access events that can be reviewed during incident triage or customer support investigations.
People controls
Human responsibilities, awareness, confidentiality obligations, and event reporting around sensitive handoffs.
Control
A.6.3
Makes the preferred secure delivery behavior concrete for teams replacing email attachments.
Control
A.6.6
Supports confidential recipient handoffs with controlled access history when NDAs or confidentiality obligations apply.
Control
A.6.8
Records delivery, open, expiry, revocation, and failed access states that can inform security reporting.
Physical controls
Physical access and media handling evidence when documents move through QR or in-person workflows.
Control
A.7.9
Keeps off-premises recipients in a verified open flow instead of uncontrolled local copies distributed by email.
Control
A.7.10
Reduces dependence on removable media by supporting secure QR handoff and encrypted package delivery.
Control
A.7.14
Supports revocation and expiration records when access should stop after a device, room, or process changes hands.
Technological controls
Authentication, protected data handling, cryptography, logging, monitoring, and network delivery controls.
Control
A.8.2
Separates routine delivery from administrative actions and preserves evidence of controlled recipient access.
Control
A.8.3
Restricts document access to authorized recipients and eligible trusted devices.
Control
A.8.5
Uses passkey recipient verification before sensitive document access continues.
Control
A.8.10
Supports access expiry, revocation, and incomplete upload cleanup evidence where delivery should no longer be available.
Control
A.8.12
Replaces broad attachment distribution with expiring, recipient-bound confidential delivery.
Control
A.8.15
Creates a reviewable record of share creation, recipient access, open events, revocation, and delivery state changes.
Control
A.8.16
Makes recipient delivery and access outcomes visible for compliance and security review.
Control
A.8.24
Supports cryptography policy evidence with local encryption and versioned protection profiles for document delivery.
NIST CSF 2.0
Maps secure delivery evidence to Govern, Identify, Protect, Detect, Respond, and Recover outcomes in CSF 2.0.
Govern
Cybersecurity risk strategy, policy, oversight, and supplier communication outcomes.
Control
GV.OC-03
Gives compliance teams document-delivery evidence they can map to external confidentiality and security obligations.
Control
GV.PO-01
Operationalizes a policy choice that confidential files leave the organization through controlled delivery.
Control
GV.SC-05
Supports supplier and customer agreements that require protected document exchange and auditable handoff records.
Identify
Data inventory, risk assessment, improvement, and supplier-risk context.
Control
ID.AM-07
Helps identify controlled confidential delivery records without exposing plaintext document contents in the visible handoff.
Control
ID.RA-06
Documents a practical risk response for sensitive external file transfer and recipient uncertainty.
Control
ID.IM-03
Provides delivery outcomes and access history that can feed process improvement reviews.
Protect
Identity, authentication, access control, and data security safeguards.
Control
PR.AA-03
Requires recipient passkey verification before a sensitive document open flow continues.
Control
PR.AA-04
Binds delivery decisions to verified recipient identity instead of link possession.
Control
PR.AA-05
Supports least-privilege document access with intended recipients, expiry, and revocation.
Control
PR.DS-01
Keeps stored document packages encrypted so the service does not need plaintext files.
Control
PR.DS-02
Uses controlled encrypted delivery and expiring access paths for confidential transfer.
Detect
Monitoring and analysis of potentially adverse access or delivery events.
Control
DE.CM-03
Records sender and recipient delivery actions in a form that is safe to hand to a reviewer.
Control
DE.AE-02
Supports investigation of unexpected opens, failed validation, revocation, and token consumption events.
Respond
Incident triage, analysis, coordination, and evidence preservation.
Control
RS.MA-02
Provides delivery records that help validate whether a document was opened, expired, or revoked.
Control
RS.AN-06
Preserves access and delivery event history for incident investigation workflows.
Control
RS.CO-03
Enables controlled sharing with designated external recipients while preserving delivery context.
Recover
Recovery communication and restoration evidence after incidents or process disruption.
Control
RC.RP-06
Helps close document-delivery incidents with a clear history of access, revocation, and final state.
Control
RC.CO-03
Supports verified resending or renewed access when recovery requires a safe replacement handoff.
NIS2
Supports Article 21 cybersecurity risk-management measures for secure communication, access control, cryptography, supply-chain handoffs, and incident handling.
Article 21(2) risk-management measures
All-hazards cybersecurity measures that include communication, access, cryptography, suppliers, and incident handling.
Control
Art. 21(2)(a)
Supports a policy-backed move from attachments to controlled confidential delivery.
Control
Art. 21(2)(b)
Provides access, expiry, revocation, and open records for document-delivery incident review.
Control
Art. 21(2)(d)
Controls sensitive document exchanges with suppliers, customers, and service partners.
Control
Art. 21(2)(f)
Gives reviewers evidence that secure delivery controls are used and producing auditable events.
Control
Art. 21(2)(h)
Supports encryption policy evidence for confidential file delivery without server-side plaintext access.
Control
Art. 21(2)(i)
Maps recipient verification, intended-recipient access, and revocation records to access-control procedures.
Control
Art. 21(2)(j)
Uses passkey verification and protected delivery paths for high-risk external communication.
SOC 2
Helps support Security, Availability, Processing Integrity, Confidentiality, and Privacy evidence where confidential delivery is in scope.
Security
Common Criteria for logical access, operations, monitoring, change, and risk mitigation.
Control
CC6.1
Supports logical access evidence with recipient verification, access restriction, and encrypted document packages.
Control
CC6.2
Supports verified recipient onboarding through passkey-based identity checks.
Control
CC6.3
Provides revocation and expiry records for changing document access after delivery.
Control
CC6.7
Replaces uncontrolled attachments with encrypted, recipient-bound delivery and audit history.
Control
CC7.2
Records document access and delivery events for compliance and security review.
Control
CC7.3
Helps teams evaluate unexpected delivery outcomes such as failed validation, expired access, or revoked links.
Control
CC9.2
Supports controlled exchange of confidential documents with customers, suppliers, and partners.
Availability
Committed availability and recovery expectations for the secure delivery workflow.
Control
A1.2
Supports recovery evidence when a delivery needs to be reissued, revoked, or reopened through a controlled workflow.
Processing Integrity
Complete, valid, accurate, timely, and authorized processing commitments.
Control
PI1.4
Helps correct mistaken delivery by revoking or expiring access and creating a fresh controlled handoff.
Confidentiality
Protection and disposal of information designated as confidential.
Control
C1.1
Protects confidential files with local encryption, intended-recipient access, and delivery audit trails.
Control
C1.2
Supports expiry, revocation, and cleanup evidence for delivery access that should no longer be available.
Privacy
Personal information handling commitments when recipient or sender data is in scope.
Control
P4.1
Helps limit delivery metadata and retention to the evidence needed for secure document sharing.
Control
P6.1
Supports controlled disclosure to intended recipients with recipient-scoped access evidence.
COBIT
Uses COBIT governance and management objective IDs for risk, security, data, service, and compliance evidence around document delivery.
Governance objectives
Evaluate, Direct and Monitor objectives for governance system, benefits, risk, resources, and stakeholder transparency.
Control
EDM03
Supports governance decisions to reduce external document-delivery risk with verified, revocable access.
Control
EDM05
Provides clear delivery evidence for stakeholders asking how confidential files are protected after sending.
Management objectives
Align, Plan and Organize; Build, Acquire and Implement; Deliver, Service and Support; Monitor, Evaluate and Assess.
Control
APO12
Documents a repeatable response to the risk of uncontrolled attachments and public links.
Control
APO13
Supports security management with encrypted delivery, recipient verification, and auditable access events.
Control
APO14
Helps keep confidential document delivery aligned with data handling and metadata minimization expectations.
Control
BAI08
Creates reusable evidence and delivery patterns teams can apply across legal, finance, HR, and customer workflows.
Control
DSS05
Supports day-to-day protected delivery with authentication, encryption, monitoring, and revocation.
Control
DSS06
Adds control points to business document handoffs without forcing recipients through a heavy portal.
Control
MEA03
Gives compliance teams control-ID-ready evidence for external audit and customer assurance requests.
GDPR
Helps legal and privacy teams evidence controlled disclosure, access limitation, encryption, breach investigation, and accountability for personal-data document handoffs.
Chapter II - Principles
Core processing principles and accountability duties for personal data handled through confidential delivery.
Control
Art. 5(1)(f)
Supports appropriate security for personal-data documents with encrypted delivery, intended-recipient access, and revocation.
Control
Art. 5(2)
Creates delivery records that help controllers demonstrate how sensitive disclosures were controlled.
Chapter IV - Controller and processor
Privacy-by-design, records, security of processing, and breach documentation obligations.
Control
Art. 25
Makes recipient-bound delivery, expiry, and metadata minimization part of the default document handoff.
Control
Art. 30
Provides structured delivery evidence that can support records for controlled external disclosure workflows.
Control
Art. 32(1)(a)
Supports encryption evidence for personal-data files without requiring server-side plaintext handling.
Control
Art. 32(1)(b)
Adds verified access, encrypted packages, and auditable state changes to confidential document delivery.
Control
Art. 32(1)(d)
Gives teams measurable delivery outcomes they can review when assessing secure sharing controls.
Control
Art. 33(5)
Preserves delivery and access history that can help reconstruct whether a shared document was opened, expired, or revoked.
Control
Art. 34(1)
Supports controlled follow-up communications to affected recipients when a breach response requires secure document delivery.
HIPAA
Helps healthcare teams protect ePHI document delivery with access control, audit controls, integrity checks, person or entity authentication, and transmission security evidence.
Administrative safeguards
Security management, information access, awareness, and incident procedures for ePHI workflows.
Control
45 CFR §164.308(a)(1)(ii)(D)
Provides access, open, expiry, and revocation records for review of ePHI delivery activity.
Control
45 CFR §164.308(a)(4)(ii)(B)
Supports authorized ePHI handoffs by limiting access to intended verified recipients.
Control
45 CFR §164.308(a)(5)(ii)(C)
Captures failed or unexpected recipient verification outcomes that can inform access monitoring.
Control
45 CFR §164.308(a)(6)(ii)
Gives incident responders document-delivery evidence when investigating a possible improper disclosure.
Technical safeguards
Access control, audit controls, integrity, authentication, and transmission security for electronic protected health information.
Control
45 CFR §164.312(a)(1)
Limits ePHI document access to authorized recipients and eligible open flows.
Control
45 CFR §164.312(a)(2)(i)
Ties sensitive document access to a specific verified recipient rather than a forwarded link.
Control
45 CFR §164.312(a)(2)(iv)
Supports encryption and decryption evidence for ePHI files handled through local protected delivery.
Control
45 CFR §164.312(b)
Records and exposes document-delivery events for authorized compliance and security review.
Control
45 CFR §164.312(c)(1)
Supports controlled packages and access history that help detect improper alteration or unauthorized handoff states.
Control
45 CFR §164.312(d)
Requires recipient verification before ePHI document access continues.
Control
45 CFR §164.312(e)(1)
Protects ePHI document transfer through encrypted, recipient-bound delivery rather than open attachments.
Control
45 CFR §164.312(e)(2)(i)
Helps recipients and senders rely on controlled delivery state and audit events during transmission.
Control
45 CFR §164.312(e)(2)(ii)
Supports encryption evidence for transmitted ePHI documents when encryption is appropriate.
Documentation requirements
Documentation retention and availability expectations for Security Rule policies and activity evidence.
Control
45 CFR §164.316(b)(1)
Provides exportable delivery evidence that can support documented security procedures.
Control
45 CFR §164.316(b)(2)(i)
Supports retention decisions for access evidence while document access itself can expire or be revoked.
PCI DSS
Helps payment teams replace account-data attachments with controlled, encrypted, auditable delivery when payment documents fall inside PCI DSS scope.
Protect account data
PCI DSS requirements for protecting stored account data and transmissions over open public networks.
Control
Req. 3.5.1
Supports encrypted package evidence for payment documents while the organization remains responsible for PCI scope and PAN handling.
Control
Req. 4.2.1
Replaces payment-document attachments with protected, recipient-bound transfer and expiring access paths.
Implement strong access control measures
Business-need access, user identification, authentication, and multi-factor access requirements.
Control
Req. 7.2.1
Supports a documented pattern where only intended recipients can open payment-related documents.
Control
Req. 8.2.1
Binds access evidence to a verified recipient instead of shared mailbox or forwarded-link possession.
Control
Req. 8.3.1
Uses passkey recipient verification before sensitive payment document access continues.
Control
Req. 8.4.2
Can support phishing-resistant recipient verification where the delivery workflow is treated as in scope by the assessor.
Regularly monitor and test networks
Audit logging, audit log contents, and review evidence for cardholder-data workflows.
Control
Req. 10.2.1
Records share creation, recipient access, failed opens, expiry, and revocation events for payment-document delivery.
Control
Req. 10.3.1
Provides recipient and sender context for authorized delivery-event review.
Control
Req. 10.4.1
Gives compliance teams delivery events they can include in routine payment-data access review.
Maintain an information security policy
Scope, acceptable use, incident response, and service-provider evidence expectations.
Control
Req. 12.5.2
Helps document whether payment-document delivery is inside or outside the assessed cardholder data environment.
Control
Req. 12.10.1
Provides delivery evidence that can help investigate suspected payment-data disclosure incidents.
Control
Req. 12.10.7
Supports post-incident review with concrete access, expiry, and revocation outcomes.
DORA
Supports EU financial entities with evidence for ICT risk management, protection, detection, incident handling, and third-party document exchange under Regulation (EU) 2022/2554.
Chapter II - ICT risk management
Risk-management framework, protection, prevention, detection, response, recovery, learning, and communication requirements.
Control
Art. 6
Supports a controlled delivery control within the ICT risk framework for confidential external documents.
Control
Art. 8
Helps identify sensitive delivery workflows and the records needed to govern them.
Control
Art. 9
Adds encryption, recipient verification, expiry, and revocation to prevent uncontrolled disclosure.
Control
Art. 10
Makes unexpected access, failed verification, and unusual delivery states visible for review.
Control
Art. 11
Supports revoking, expiring, or reissuing secure delivery after a document-sharing incident.
Control
Art. 12
Supports controlled replacement handoffs when business recovery requires a document to be resent.
Control
Art. 13
Provides delivery outcomes that can feed lessons learned and control-improvement reviews.
Control
Art. 14
Supports secure communications with customers, counterparties, and regulators when confidential files must be exchanged.
Chapter III - ICT-related incident management
Incident classification, reporting, and notification evidence for ICT-related incidents.
Control
Art. 17
Provides access and delivery-event evidence for classifying document-sharing incidents.
Control
Art. 18
Helps determine whether a failed, revoked, or unexpected document access event affects confidentiality.
Control
Art. 19
Preserves delivery history that can support incident reports when a document-sharing event is reportable.
Chapter V - ICT third-party risk
General principles for ICT third-party risk where confidential documents move between regulated entities and providers.
Control
Art. 28
Supports controlled, auditable exchange with third parties without publishing private implementation or infrastructure details.
Audit-ready handoff
Use Steek when a sensitive document leaves your organization and the business still needs proof of identity, access control, expiry, revocation, and delivery history.