Controls
Updated 27 days agoInfrastructure Security
ControlStatus
- Remote access MFA enforcedThe company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
- Remote access encrypted enforcedThe company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection.
- Network segmentation implementedThe company's network is segmented to prevent unauthorized access to customer data.
- Unique account authentication enforcedThe company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys.
- Data encryption utilizedThe company's datastores housing sensitive customer data are encrypted at rest.
Organizational Security
ControlStatus
- Password policy enforcedThe company requires passwords for in-scope system components to be configured according to the company's policy.
- Security awareness training implementedThe company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.
Internal Security Procedures
ControlStatus
- Backup processes establishedThe company's data backup policy documents requirements for backup and recovery of customer data.
- Incident response policies establishedThe company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.
- Incident management procedures followedThe company's security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management according to the company's security incident response policy and procedures.
- Monitoring, measurement, analysisThe organization monitors, measures, analyzes, and evaluates its information security performance and the effectiveness of the information security management system.
Product Security
ControlStatus
- Data transmission encryptedThe company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
- Vulnerability and system monitoring procedures establishedThe company's formal policies outline the requirements for vulnerability scanning, dependency monitoring, and production observability.