Snapshot 20189
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center alguna.com [email protected] Compliance overview Current compliance status across frameworks SOC 2 Type 2 Compliant Compliance Program An overview of security controls in place Access Control and Authorization Access granting process used Access requests to sensitive data required Access requests to sensitive infrastructure required Access revoking process enforced Account inventory maintained Dormant accounts disabled MFA required for administrative access MFA required for infrastructure access Password management policy enforced Data Management and Protection Data encrypted at rest Data encrypted in-transit Data inventory maintained Data labeled by sensitivity level Data management and retention policy established Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Data recovery process established Disaster recovery plans tested Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Data encrypted on end-user devices Firewall maintained on end-user devices Mobile device management (MDM) used Unauthorized software on end-user devices addressed and removed Infrastructure Security Active discovery tools used Buckets not exposed publicly Configuration management system established Firewall restricts public access to infrastructure Infrastructure changes logged Infrastructure changes require review Infrastructure deployed using an infrastructure-as-code tool Unauthorized assets addressed and removed Unique production database authentication enforced Web Application Firewall (WAF) used Monitoring and Incident Response Adequate audit log storage maintained Audit log management process maintained Audit logs collected Incident response policy established Infrastructure performance monitored Log management used Network infrastructure monitored Organizational Security Asset inventory maintained Asset management policy acknowledged by employees Code of conduct acknowledged by contractors Code of conduct acknowledged by employees Code of conduct enforced Company security commitments externally communicated Confidentiality Agreement acknowledged by contractors Confidentiality Agreement acknowledged by employees External support resources available (i.e., documentation) Offboarding process established Onboarding process established Performance evaluations conducted Reference calls performed for employees Roles and responsibilities specified Security awareness training conducted Service description communicated Software development lifecycle established System changes externally communicated System changes internally communicated Vendor agreements established Whistleblower policy established Risk Management Cybersecurity insurance maintained Risk assessments performed Risk management policy established Vendor inventory maintained Vendor management program established Vendors classified by data sensitivity Vendors classified by risk level Vulnerability Management Automated software patch management performed Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy acknowledged by employees