A description of the various controls required to adhere to specific regulatory or more informally generated requirements.
The controls will usually be implemented using a combination of non-functional requirements to IT solutions (both
infrastructure and applications) and to IT processes and/or procedures.