Information security management
Article 10
The contract shall require providers to declare that the primary repository and, where applicable, the second repository, is managed in accordance with internationally recognised information security management standards. Providers certified to ISO/IEC 27001:2013 shall be presumed to meet those standards.