Third Party Index

Snapshot 50731

Document
Trust center
URL
https://trust.jedox.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
489024 bytes
SHA-256 (raw)
4d24609c8a55a40afd062892604280f21110429df0978b31706e1eba92d319e3
SHA-256 (normalized text)
d9e6f5889b3740e9145ae837bba6e3d200f8905076b567688c29418c810333c1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

JedoxTrust Center
jedox.com
trust@jedox.com
Overview
Controls
Security and compliance
security rating
914 / 950
Industry Average
726
CSA STAR Level 1
CSA STAR Level 2
GDPR
ISO 27001
ISO 27017
ISO 9001
NIS2
SOC 1
SOC 2 Type II
About
Jedox is the world’s most adaptable planning and performance management platform that empowers organizations to deliver plans that outperform expectations. Over 2,900 organizations in 140 countries trust Jedox to model any scenario, integrate data from any source and simplify cross-organizational plans across all business systems. With Jedox, you can react quickly to changes, plan for opportunities, and uncover what you didn’t know was possible.
Controls
See all 438
Security policies and procedures
A formally defined information security program is documented, communicated & maintained.
Information security program scope covers internal issues and external threats.
Information security program resourcing is aligned to the organization's risk strategy, with adequate funding, staffing, and tools allocated.
+ 79 more
Asset management
Asset management program is approved by management and includes assigned ownership and responsibilities for maintaining, reviewing, and managing asset controls.
Asset register is maintained.
Acceptable use policy for information and associated assets has been developed, communicated and maintained effectively.
+ 78 more
Infrastructure management
Domain does not expire soon.
Domain has not expired.
Domain registrar or registry transfer protection enabled.
+ 88 more
Data protection
Periodic user access reviews are conducted.
Unique IDs are required for authentication across systems and devices.
User access rights are granted on a least-privilege basis, aligned with each role’s business needs.
+ 50 more
Application security
A secure development life cycle process is defined, implemented, and integrated into all development projects.
Software development, testing, and staging environments are kept separate from the production environment.
Security experts are engaged for development on all applications.
+ 40 more
Risk management
Formal risk assessment process is defined and implemented.
Cybersecurity risk appetite and risk tolerance statements are formally documented, communicated to relevant stakeholders, and reviewed on a defined schedule.
Information assets and business processes are inventoried and evaluated for risk exposure as part of the risk assessment process.
+ 27 more
Operational resilience
Scoped data backed up and stored offsite.
Backup and related restoration procedures tested at least annually.
Backup procedure in place for all information, software, and systems.
+ 55 more
Resources
Documents
SOC2_Bridge Letter_Oct 2025_June 2026
Last updated Oct 1, 2026
PS880
Last updated Mar 9, 2026
26.1 Penetration Test Attestation Letter
Last updated Feb 26, 2026
ISAE 3402 TYPE 2 REPORT
Last updated Dec 25, 2025
SOC 2 TYPE 2 REPORT
Last updated Dec 25, 2025
CSA STAR, CCM Version 4.0.5
Last updated Feb 6, 2026
Incident Management_V1.2_240430
Last updated Oct 7, 2025
ISO/IEC 27001:2024-01
Last updated Feb 6, 2026
ISO 9001:2015
Last updated Mar 6, 2025
Security policies and procedures
Controls
Information security program established
Information security
A formally defined information security program is documented, communicated & maintained.
Published Oct 7, 2025
CSA STAR, CCM Version 4.0.5
SOC 2 TYPE 2 REPORT
Information security program scope covers internal issues and external threats.
Published Oct 7, 2025
CSA STAR, CCM Version 4.0.5
SOC 2 TYPE 2 REPORT
ISO/IEC 27001:2024-01
Information security program resourcing is aligned to the organization's risk strategy, with adequate funding, staffing, and tools allocated.
Published Oct 7, 2025
Information security governance program implemented
Information security
Information security policy is enforced by an appointed owner.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Executive leadership provides effective oversight and governance of the cybersecurity programme, fostering a risk-aware culture and driving continuous improvement.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security and IT processes are retained in-house and/or outsourced with the same information security governance.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
All projects involving systems, applications, and platforms undergo an information security assessment.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security strategy, policies and standards are reviewed on an annual basis and after major changes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Compliance with information security policies is regularly and consistently monitored and managed.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Personnel have access to a clearly defined and confidential channel for promptly reporting suspected security events, policy violations, or observed weaknesses.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Policy objectives and requirements align with the strategic direction of the organization and are integrated into the organization's processes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
A process is in place for identifying, correcting, and preventing recurrence of nonconformities in the information security program.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Deployed AI systems include defined human oversight roles for human-in-the-loop intervention and override of automated decisions when required.
Published Oct 7, 2025
Risk management objectives are formally defined, approved by relevant stakeholders, and reviewed periodically.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Objectives and metrics are monitored to assess adherence to the information security policy and its effectiveness.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Management communicates and enforces the requirement that all personnel apply the organization’s security policies and procedures.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Compliance with information security policies is recorded and tracked in a risk register or equivalent system until resolved.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Reviews are conducted to ensure personnel, systems, and processes operate in compliance with applicable information security policies, standards, and procedures.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Critical dependencies are documented, prioritized based on impact, and communicated to relevant stakeholders.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Critical services relied on by external stakeholders are identified, documented and communicated appropriately.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Stakeholder groups relevant to cybersecurity risk management are identified, and their needs and expectations are documented and reviewed periodically.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security-related legal, regulatory, statutory, and contractual obligations are identified, documented, and reviewed on a scheduled basis.
Published Oct 7, 2025
Cybersecurity operations are continuously improved based on observations and lessons learned from the execution of routine processes, procedures, and team activities.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Risk assessment policies and procedures established
Information security
Documented risk assessment process for information security.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Responsibilities for assessing and accepting residual information security risks are defined and assigned.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security risk assessment process address the risks to architecture, infrastructure, software, operations, business, cybersecurity, and IT services.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Risk assessment process includes evaluation of the potential consequences of identified risks and the likelihood of their recurrence.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Strategic cybersecurity opportunities are characterized and incorporated into risk management discussions and decision-making.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security policy framework established
Information security
An information security policy is implemented and maintained with clearly defined and measurable objectives.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security policies are based on accepted frameworks, and industry practices.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Topic-specific policies are defined and approved.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security policies and procedures cover third-party risk management.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security policies and standards are formally approved by senior management.
Published Oct 7, 2025
Effective exceptions and exemptions process for information security policies, standards and procedures.
Published Oct 7, 2025
Cybersecurity policies are periodically updated to reflect evolving threats, regulatory and technological changes, and strategic objectives, with updates communicated to all relevant stakeholders.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Acknowledgement of policies by new personnel before being granted access to the organization's information and assets.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Records and information handling program implemented
Information security
A documents and records-management programme is implemented and maintained.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Formal data governance program is implemented and maintained.
Published Oct 7, 2025
Records are protected from unauthorized disclosure, misuse, loss, destruction, or alteration.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Safe practices for accessing, processing, storing or transmitting data on external systems.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
IT operations governance established
IT operations management
Documented and approved operating procedures for information processing facilities are maintained and made available to personnel responsible for their execution.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Operational IT responsibilities are formally defined.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Executive management ensures IT operations policies and procedures are aligned with the organization’s strategy and information security objectives.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
A defined process exists to conduct independent reviews of IT operations policies and procedures at least annually.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Incident Management_V1.2_240430
Operational change management program established
IT operations management
Documented operational change management policy approved by management, communicated to appropriate constituents, and assigned an owner.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
All operational changes require formal operational and security impact assessment and approval prior to implementation.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Operational change management policy defines categories of changes based on severity, risk, or business impact.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Operational change management policy includes procedures for addressing emergency changes.
Published Oct 7, 2025
Operational change management policy includes multi-stakeholder review or a change advisory board.
Published Oct 7, 2025
Operational change management policy includes testing and rollback plans for all high-impact changes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Operational change management program implemented
IT operations management
Information security requirements are implemented when new systems are introduced, upgraded, or enhanced.
Published Oct 7, 2025
Security requirements for new, upgraded, or enhanced systems are defined based on data classification and are integrated into project planning and delivery.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security specifications for new, upgraded, or enhanced systems are developed using requirements from policies and regulations.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Business continuity requirements are considered for new, upgraded, or enhanced systems.
Published Oct 7, 2025
Implementation of new and upgraded systems follows defined change management procedures.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Testing is required for validation of all controls required for new, upgraded, or enhanced systems.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
All changes are documented and reviewed after implementation for appropriateness and security impact.
Published Oct 7, 2025
Installation of software on operational systems is restricted to authorized personnel.
Published Oct 7, 2025
Independent security assessments undertaken
Compliance management
Industry recognized third-party information security certifications held.
Published Oct 7, 2025
CSA STAR, CCM Version 4.0.5
SOC 2 TYPE 2 REPORT
ISO/IEC 27001:2024-01
Responsibility for planning, coordinating, and responding to independent security assessments is formally defined and assigned.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Results of independent assessments are reviewed by management and used to improve.
Published Oct 7, 2025
Internal audits of the information security program are conducted at planned intervals, in addition to external reviews.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Intellectual property and licensing
Compliance management
Topic-specific policies define acceptable use and protection of intellectual property, including software, documents, media, and trademarks.
Published Oct 7, 2025
Only licensed or authorized software and content are permitted; ownership records and usage compliance are reviewed periodically.
Published Oct 7, 2025
Human resources policy established
Human resources security
Documented human-resources security policy and procedures are formally approved, maintained, and communicated to all relevant personnel.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Human resources security policy effectiveness is reviewed at least annually using HR metrics and audit findings.
Published Oct 7, 2025
Confidentiality and non-disclosure agreements are reviewed periodically to ensure alignment with legal and business requirements.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Background checks in place
Human resources security
Human resources policies include constituent background screening criteria.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Background checks are performed pre-employment, and periodically as required by industry-specific standards or regulations.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Personnel security procedures in place
Human resources security
Human resources security policy includes a disciplinary process for non-compliance.
Published Oct 7, 2025
Human resources security policy defines constituent accountability for the use and misuse of their access credentials.
Published Oct 7, 2025
Terminated constituents understand their continuing information security responsibilities upon termination or role change.
Published Oct 7, 2025
Human resources security policy includes onboarding procedures that communicate information security responsibilities to all personnel including contract personnel.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Human resources security policy includes procedures for terminating contract personnel and ensuring information security responsibilities are upheld.
Published Oct 7, 2025
Employment agreements established and implemented
Human resources security
Constituents are required to sign employment agreements.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Employment agreements define personnel information security responsibilities, including acknowledgment of the Code of Conduct and Acceptable Use Policy.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Employment agreements include acknowledgement of confidentiality/non-disclosure policies.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Security training conducted
Human resources security
Personnel with dedicated information security responsibilities are required to engage in continuing education programs.
Published Oct 7, 2025
All new hires are required to complete information security awareness training during onboarding.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
All personnel, regardless of role, are required to complete general information security awareness training at least annually.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security responsibilities specific to each role are embedded into onboarding and functional training processes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security training effectiveness is periodically evaluated to ensure personnel understand and apply security responsibilities.
Published Oct 7, 2025
Asset management
Controls
Asset management program governance in place
Asset management program
Asset management program is approved by management and includes assigned ownership and responsibilities for maintaining, reviewing, and managing asset controls.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Asset register is maintained.
Published Oct 7, 2025
Acceptable use policy for information and associated assets has been developed, communicated and maintained effectively.
Published Oct 7, 2025
Information handling policy or procedure developed, communicated and maintained effectively.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
All asset types are identified and recorded in the asset inventory with assigned owners.
Published Oct 7, 2025
All organizational assets are prioritized based on classification, criticality, and mission impact.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Asset lifecycle is managed from acquisition through disposal, including reassignment, decommissioning, and return of assets.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Processes ensure the return of all organizational assets upon termination or internal role change, including devices, credentials, and documentation, with responsibilities defined in policy.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Topic-specific policies for information classification, labelling, and transfer are documented, communicated, and maintained.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information classification and data handling policies established
Asset management program
Information is classified according to legal or regulatory requirements, business value, and sensitivity to unauthorized disclosure or modification.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information handling policy includes storage requirements.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information handling policy defines security requirements for electronic transmission of data, including the use of secure protocols and approved file transfer services.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information handling policy ensures the information's classification is properly labeled in its physical and electronic formats.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Records retention policy and retention schedule cover paper and electronic records.
Published Oct 7, 2025
A data retention and destruction policy is implemented that defines storage duration and business/legal requirements for records.
Published Oct 7, 2025
Data flows for sensitive information are documented, maintained, and reviewed at least annually.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Authorized internal and external network communication paths and data flows are documented, maintained, and reviewed annually.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Secure data-destruction procedures ensure information and media are irretrievably deleted when no longer required for business, legal, or regulatory purposes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Data loss prevention (DLP) solution in place
Asset management program
A data loss prevention (DLP) solution is implemented.
Published Oct 7, 2025
Data loss prevention (DLP) security solution includes a handling process if data loss is suspected or occurs.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Measures prevent sensitive, unauthorized, or malicious data from entering AI datasets.
Published Oct 7, 2025
Data loss prevention (DLP) security solution covers all relevant data channels, including email, endpoints, cloud storage, and file transfers.
Published Oct 7, 2025
Data loss prevention (DLP) solution generates alerts and logs for policy violations, with reporting to responsible teams.
Published Oct 7, 2025
Data loss prevention (DLP) policies and rules are reviewed periodically and updated based on evolving threats or compliance requirements.
Published Oct 7, 2025
Security tool coverage and effectiveness are monitored via defined metrics.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Encryption and key management procedures established and implemented
Asset management program
Encryption keys are managed and maintained for scoped data.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Encryption keys are generated in a manner consistent with key management industry standards.
Published Oct 7, 2025
Encryption is applied to scoped data at rest, based on data classification and risk.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Encryption is applied to scoped data in transit, based on data classification and risk.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Encryption and key management practices are defined in a documented policy aligned with industry standards.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Only approved cryptographic algorithms and trusted libraries are permitted for encryption and key management.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Security tooling, automation, and integration program established
Asset management program
Security-specific tools are implemented to support key information security functions.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Security tools supporting key controls are inventoried, with defined owners and documented purpose.
Published Oct 7, 2025
Security tooling integrates with operational platforms to support automated or auditable workflows.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Asset management policy enforced
Asset management program
Procedures and controls for transferring information are defined and enforced.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Scoped data is not sent or received via physical media.
Published Oct 7, 2025
Media containing scoped data is securely wiped or destroyed upon disposal, with disposal actions logged and approved.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Chain-of-custody is maintained when transporting data.
Published Oct 7, 2025
Supplier-provided services, including systems storing or processing organizational data, are inventoried and reviewed for security compliance.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Mobile device management program in place
Endpoint security
User endpoint device management program developed and communicated effectively.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Endpoint security configuration standards are implemented, maintained, and apply to all user devices.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Policies and procedures define protection requirements for off-premises use of organizational assets.
Published Oct 7, 2025
Endpoint-device configurations are centrally enforced and continuously monitored through secure configuration-management processes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Enterprise-issued user endpoint devices are registered and configured according to organizational security policies prior to accessing corporate resources.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Enterprise-issued mobile devices are issued to authorized personnel only.
Published Oct 7, 2025
Remote wipe or data loss protection is enabled for all user endpoint devices.
Published Oct 7, 2025
Registered endpoint devices are reviewed periodically and unauthorized or unused devices are removed.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Personal devices accessing organizational data are subject to mobile application management (MAM) or containerization controls, or are explicitly disallowed.
Published Oct 7, 2025
Installation of unapproved or high-risk applications on endpoint devices is restricted based on device type and risk level.
Published Oct 7, 2025
Endpoints protected from malicious content
Endpoint security
Web filter in place to block access to websites containing malicious, illegal, or inappropriate content.
Published Oct 7, 2025
Endpoint-protection mechanisms use threat intelligence to block access to known-malicious domains, websites, and IP addresses, and to prevent download or execution of malicious file types.
Published Oct 7, 2025
Security event logs are reviewed regularly.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Robust physical security controls implemented
Physical security
Physical access to secure areas is managed, controlled, and monitored through access mechanisms.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Physical security perimeters use barriers and secured access points.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Physical access control credentials are updated or revoked promptly upon personnel role changes or termination.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Only authorized personnel are granted physical access to secure areas, based on role and business need.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Visitors to secure areas are logged, issued temporary credentials if needed, and escorted at all times.
Published Oct 7, 2025
Perimeter controls are reviewed periodically to ensure they remain effective and appropriate to the risk environment.
Published Oct 7, 2025
Secure areas are continuously monitored for unauthorized access.
Published Oct 7, 2025
Personnel are required to follow documented procedures when working in secure areas, including restrictions on unauthorized devices and activities.
Published Oct 7, 2025
Physical protections such as reinforced doors, surveillance systems, and intrusion detection are implemented.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Clear desk and clear screen policies are defined and enforced.
Published Oct 7, 2025
Storage media containing sensitive information is protected from unauthorized access, copying, or removal.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Storage media is securely wiped before reassignment or reuse.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Cables carrying data or supporting information services are protected against unauthorized access, interference, or damage.
Published Oct 7, 2025
Physical security policy established
Physical security
A physical security program is established and communicated, with a defined owner.
Published Oct 7, 2025
Security perimeters are formally defined and implemented based on risk and business requirements to protect areas containing sensitive information and critical assets.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Physical security program is reviewed at least annually and following significant changes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Physical security procedures for visitors enforced
Physical security
Visitors are required to sign in and out and provide valid ID.
Published Oct 7, 2025
Visitors required to wear a badge distinguishing them from employees.
Published Oct 7, 2025
Visitor logs are maintained for at least 90 days.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Access rights and visitor activity are managed and logged.
Published Oct 7, 2025
Activities of visitors and third-party personnel are monitored for potential security incidents.
Published Oct 7, 2025
Robust environmental protection controls established
Physical security
Procedures to address physical and environmental threats have been identified and implemented.
Published Oct 7, 2025
Environmental controls include water damage protection measures.
Published Oct 7, 2025
Environmental controls include HVAC and humidity controls.
Published Oct 7, 2025
Environmental controls include heat and smoke detectors and fire suppression.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Equipment is located in areas protected against fire, flooding, dust, and vibration.
Published Oct 7, 2025
Backup and maintenance of critical equipment and systems in place
Physical security
Critical supporting utilities are designed and implemented.
Published Oct 7, 2025
Generator or generator area in offices and facilities.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Maintenance support contracts in place for critical infrastructure and equipment.
Published Oct 7, 2025
Infrastructure management
Controls
Domain ownership protections in place
DNS security
Domain does not expire soon.
Published Oct 7, 2025
Domain has not expired.
Published Oct 7, 2025
Domain registrar or registry transfer protection enabled.
Published Oct 7, 2025
Domain not flagged as inactive.
Published Oct 7, 2025
Domain not pending deletion.
Published Oct 7, 2025
Domain not pending restoration.
Published Oct 7, 2025
Domain free of registry DNS resolution hold.
Published Oct 7, 2025
Domain free of registrar DNS resolution hold.
Published Oct 7, 2025
Domain renewal not prohibited by registry.
Published Oct 7, 2025
Domain renewal not prohibited by registrar.
Published Oct 7, 2025
DNS responses are authenticated
DNS security
No subdomain takeover vulnerability detected.
Published Oct 7, 2025
Proactive measures to reduce unauthorized mailbox access
DNS security
No unregistered MX records detected.
Published Oct 7, 2025
Maintains minimal Wordpress attack surface
Internet-facing services (IFS)
WordPress XML-RPC API disabled.
Published Oct 7, 2025
WordPress version not exposed.
Published Oct 7, 2025
Insecure WordPress installation not detected.
Published Oct 7, 2025
Outdated WordPress installation not detected.
Published Oct 7, 2025
Limits access to frequently exploited products
Internet-facing services (IFS)
MOVEit Transfer with HTTP and HTTPS port open not detected.
Published Oct 7, 2025
MOVEit Transfer with HTTP not available not detected.
Published Oct 7, 2025
FortiOS SSL VPN interface not detected.
Published Oct 7, 2025
Citrix Gateway not detected.
Published Oct 7, 2025
Citrix ADC not detected.
Published Oct 7, 2025
Outdated Citrix Gateway version not detected.
Published Oct 7, 2025
Outdated Citrix ADC version not detected.
Published Oct 7, 2025
Citrix ShareFile not detected.
Published Oct 7, 2025
Cisco IOS XE Web UI not detected.
Published Oct 7, 2025
Ivanti Connect Secure VPN not detected.
Published Oct 7, 2025
GitLab not detected.
Published Oct 7, 2025
Removes access to networked management interfaces
Internet-facing services (IFS)
Veeam Backup software not detected.
Published Oct 7, 2025
Prevents compromise of internet-facing systems
Internet-facing services (IFS)
No indicator of system compromise in Cisco IOS XE Web UI.
Published Oct 7, 2025
Potentially malicious Polyfill sources not discovered.
Published Oct 7, 2025
Website configurations expose minimal information
Website security
X-Powered-By header not exposed.
Published Oct 7, 2025
Referrer policy is not unsafe-url.
Published Oct 7, 2025
ASP.NET version header not exposed.
Published Oct 7, 2025
ASP.NET version header not exposing specific ASP.net version.
Published Oct 7, 2025
Website configurations prevent clickjacking and cross-site scripting
Website security
CSP implemented without insecure active sources.
Published Oct 7, 2025
CSP implemented without insecure passive sources.
Published Oct 7, 2025
Data in transit is encrypted
Encryption
SSL expiration period shorter than 398 days.
Published Oct 7, 2025
SSL chain certificates do not expire within 20 days.
Published Oct 7, 2025
Strong encryption used for data in transit
Encryption
Strong SSL algorithm.
Published Oct 7, 2025
Strong public certificate key length.
Published Oct 7, 2025
Strong Diffie-Hellman prime used in key exchange.
Published Oct 7, 2025
Strong or non-common Diffie-Hellman prime used in key exchange.
Published Oct 7, 2025
No insecure cipher suites supported.
Published Oct 7, 2025
No weak cipher suites supported in TLS 1.2.
Published Oct 7, 2025
Data encrypted with trusted certificate
Encryption
Certificate not found on our revoked certificate list.
Published Oct 7, 2025
Trusted SSL certificate.
Published Oct 7, 2025
Proactive measures to reduce unnecessary Wordpress data disclosure
Data leakage
WordPress user list not exposed.
Published Oct 7, 2025
No leaked data detected.
Published Oct 7, 2025
Listing of file storage directories is disabled
Data leakage
No listable directories found.
Published Oct 7, 2025
Domain index is not a listable directory.
Published Oct 7, 2025
No open cloud storage service detected.
Published Oct 7, 2025
Proactive measures to reduce data disclosure to third parties
Data leakage
Meta/Facebook Pixel not detected.
Published Oct 7, 2025
TikTok Pixel not detected.
Published Oct 7, 2025
Networks are segregated
Network security
Networks are segmented into domains with clearly defined perimeters on separate networks, based on a thorough evaluation of each domain’s security requirements.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Networks segmented into domains based on an evaluation of the security requirements for each domain.
Published Oct 7, 2025
Client data is logically or physically segregated and isolated from other clients’ data across networks, storage, applications, and backups.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
The rationale for network segmentation decisions is documented and reviewed periodically.
Published Oct 7, 2025
Network security policies and procedures in place
Network security
Management approved policy for remote access to scoped systems and data.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Wireless policy or program has assigned owner and has been approved by management.
Published Oct 7, 2025
Security and hardening standards for network devices are defined and enforced.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Safeguards are implemented to detect and block abusive traffic to AI models.
Published Oct 7, 2025
Formally defined network security policy is implemented and maintained.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Network architecture incorporates Zero Trust principles such as least privilege access, segmentation, and continuous verification where applicable.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Remote access requires strong authentication (e.g., MFA, VPN with least privilege).
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Remote work requires the use of organization-managed or approved devices with secure configurations.
Published Oct 7, 2025
Information accessed, processed, or stored remotely must be protected through secure storage, screen locking, and physical safeguards.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Network traffic and services are continuously monitored to detect anomalies, suspicious activity, and potential indicators of compromise.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Only approved services running
Network security
No unauthorized open service ports detected.
Published Oct 7, 2025
No malicious activity detected
IP reputation
Not a suspected phishing page.
Published Oct 7, 2025
Not a suspected malware provider.
Published Oct 7, 2025
Not suspected of unwanted software.
Published Oct 7, 2025
No reports of unsolicited scanning in the last 30 days.
Published Oct 7, 2025
No reports of unsolicited scanning in the last 90 days.
Published Oct 7, 2025
No reports of brute force login attempts in the last 30 days.
Published Oct 7, 2025
No reports of brute force login attempts in the last 90 days.
Published Oct 7, 2025
No reports of botnet activity in the last 30 days.
Published Oct 7, 2025
No reports of botnet activity in the last 90 days.
Published Oct 7, 2025
No reports of spam activity in the last 30 days.
Published Oct 7, 2025
No reports of spam activity in the last 90 days.
Published Oct 7, 2025
No reports of malware distribution in the last 30 days.
Published Oct 7, 2025
No reports of malware distribution in the last 90 days.
Published Oct 7, 2025
No reports of phishing activity in the last 30 days.
Published Oct 7, 2025
No reports of phishing activity in the last 90 days.
Published Oct 7, 2025
Email sender authenticated
Email security
SPF syntax correct.
Published Oct 7, 2025
Strict SPF filtering - not using +all.
Published Oct 7, 2025
Strict SPF filtering - not using ?all.
Published Oct 7, 2025
Strict SPF filtering - not using ~all.
Published Oct 7, 2025
SPF ptr mechanism not used.
Published Oct 7, 2025
DMARC policy is not p=none.
Published Oct 7, 2025
DMARC policy is not p=quarantine.
Published Oct 7, 2025
DMARC policy percentage is default.
Published Oct 7, 2025
Data protection
Controls
Access control processes established and implemented
Access management
Periodic user access reviews are conducted.
Published Oct 16, 2025
Unique IDs are required for authentication across systems and devices.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
User access rights are granted on a least-privilege basis, aligned with each role’s business needs.
Published Oct 16, 2025
Process in place to modify access rights of users who have changed roles.
Published Oct 16, 2025
Inactive user IDs disabled or deleted after defined periods of inactivity.
Published Oct 16, 2025
Process that allows authenticators to be revoked when necessary.
Published Oct 16, 2025
Use of privileged accounts is logged and monitored to detect misuse or unauthorized activity.
Published Oct 16, 2025
Access exceptions and temporary access are documented, time-bound, and approved through a formal process.
Published Oct 16, 2025
Use of privileged utility programs is restricted, approved, and monitored.
Published Oct 16, 2025
Access to information and other associated assets is restricted through technical and procedural controls.
Published Oct 16, 2025
Privileged access rights are reviewed at least quarterly.
Published Oct 16, 2025
Policies include prompt removal of physical and logical access rights upon termination or change of employment.
Published Oct 16, 2025
Identities are verified prior to provisioning access to systems and services.
Published Oct 16, 2025
Identity lifecycle processes are implemented to provision, update, and revoke access for all user and system identities.
Published Oct 16, 2025
Users are informed of their responsibilities for protecting access credentials and securely accessing information and systems.
Published Oct 16, 2025
Access provisioning and deprovisioning are automated and integrated with HR or identity lifecycle processes.
Published Oct 16, 2025
Identity assertions are cryptographically protected, securely transmitted, and verified prior to granting access.
Published Oct 16, 2025
Documented access control policy in place
Access management
Access control policy approved by senior management, maintained and communicated effectively.
Published Oct 16, 2025
Segregation of duties in place for granting and approving access to scoped systems and data.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Privileged accounts are kept distinct from standard accounts, and their use is documented and restricted to only those key roles that require them.
Published Oct 16, 2025
Authentication mechanisms are securely implemented and enforced
Access management
Processes in place to protect passwords and PIN numbers.
Published Oct 16, 2025
Authentication policy is documented, approved, and enforced across all authentication mechanisms and systems.
Published Oct 16, 2025
Authentication credentials are securely distributed to users following identity verification.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Processes are in place to securely reset or recover authentication credentials when required.
Published Oct 16, 2025
Phishing-resistant authentication methods are adopted where feasible based on risk.
Published Oct 16, 2025
Authentication mechanisms protect against brute-force attacks.
Published Oct 16, 2025
Multi-factor authentication is enforced for user access to non-public organizational systems and applications.
Published Oct 16, 2025
Multi-factor authentication required for privileged system access.
Published Oct 16, 2025
Multi-factor authentication enforced for all endpoint access.
Published Oct 16, 2025
Compliance with MFA requirements is monitored and reviewed regularly to ensure enforcement across all applicable systems.
Published Oct 16, 2025
SSO is enforced across all organizational systems and applications, including both internal and third-party applications.
Published Oct 16, 2025
All SSO logins require multi-factor authentication (MFA).
Published Oct 16, 2025
SSO authentication events and anomalies (e.g., failed logins, location mismatches) are monitored and integrated with security alerting.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Administrative access to the SSO platform requires just-in-time elevation or additional verification.
Published Oct 16, 2025
Access management audit trail
Access management
User access records are retained for at least 12 months.
Published Oct 7, 2025
Session timeouts and reauthentication requirements are enforced based on risk level and inactivity thresholds.
Published Oct 7, 2025
Data privacy and protection policy in place
Privacy management
Data privacy and protection policy has been implemented.
Published Oct 16, 2025
Formal privacy program covers for the protection of personal information handled on behalf of the client.
Published Oct 16, 2025
Data subjects can request removal of their personal data from AI systems where feasible.
Published Oct 16, 2025
A privacy impact assessment (PIA) process is established and integrated into new system, service, or vendor onboarding.
Published Oct 16, 2025
The privacy policy explicitly aligns with applicable national and international privacy regulations.
Published Oct 16, 2025
The privacy policy is reviewed and re-approved at least annually or upon material change.
Published Oct 16, 2025
Safe handling of Personally Identifiable Information (PII)
Privacy management
PII is classified and labeled according to sensitivity, with corresponding handling requirements.
Published Oct 16, 2025
Documented policies and procedures to address cross-border and international data flows.
Published Oct 16, 2025
PII disposal is logged and verified to prevent unauthorized retention.
Published Oct 16, 2025
Clear accountability for privacy obligations
Privacy management
A qualified and accountable owner is designated to oversee the privacy programme and ensure compliance with all privacy requirements, including contractual client-data obligations.
Published Oct 16, 2025
Publicly facing communication channels in place to enable submission and response to privacy inquiries, complaints, and disputes.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Roles and responsibilities for privacy risk management are documented, including escalation paths.
Published Oct 16, 2025
Privacy management encompasses third and fourth parties
Privacy management
Contracts and agreements with third parties include appropriate data protection safeguards.
Published Oct 16, 2025
Third-party risk management program covers security of client scoped data.
Published Oct 16, 2025
Cybersecurity responsibilities for third parties and customers are documented, communicated, and coordinated across internal stakeholders and external entities.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Third-party due diligence includes evaluation of data protection and privacy policies, practices, and technical controls.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Third-party data access and transmission are explicitly disclosed and approved.
Published Oct 16, 2025
Application security
Controls
Secure software development practices
Software development
A secure development life cycle process is defined, implemented, and integrated into all development projects.
Published Oct 16, 2025
Software development, testing, and staging environments are kept separate from the production environment.
Published Oct 16, 2025
Security experts are engaged for development on all applications.
Published Oct 16, 2025
Third-party or outsourced development is governed by security requirements, auditability, and contract clauses.
Published Oct 16, 2025
Secure code reviews include analysis of vulnerability to recent attacks.
Published Oct 16, 2025
Web server patches, service packs, and hot fixes are tested, documented, and approved prior to deployment.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Access to development, test, and production environments is role-based and uses separate credentials.
Published Oct 16, 2025
Outsourced development is actively supervised and monitored.
Published Oct 16, 2025
Security testing processes are formally defined and implemented during development and acceptance stages.
Published Oct 16, 2025
Secure coding standards are defined and applied throughout the development process.
Published Oct 16, 2025
Security fixes and patches are rolled out according to defined severity-based timelines.
Published Oct 16, 2025
AI systems are assessed for known risks using established adversarial threat models.
Published Oct 16, 2025
Static and dynamic application security testing (SAST/DAST) is integrated into continuous integration/continuous deployment pipelines.
Published Oct 16, 2025
Audit activities involving operational systems are planned in advance and approved by relevant management.
Published Oct 16, 2025
Access granted for audit or assurance testing is limited to the minimum level required, authorized prior to use, and logged.
Published Oct 16, 2025
Security testing tools and auditor devices are verified to meet organizational security requirements before accessing operational systems.
Published Oct 16, 2025
Secure architecture design standards established
Software development
Management approved IT architectural plan.
Published Oct 7, 2025
Secure design principles are documented and consistently applied across system architecture and engineering processes.
Published Oct 7, 2025
Architecture reviews are conducted to validate that secure design principles are applied consistently.
Published Oct 7, 2025
Baseline secure configurations are defined and regularly reviewed for all hardware, software, services, and networking assets.
Published Oct 7, 2025
Configuration changes are logged and monitored for unauthorized modifications.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Developer security training implemented
Software development
Developers receive formal, role-specific training on secure coding, threat modeling, and privacy engineering as part of onboarding and annual refreshers.
Published Oct 7, 2025
Test data procedures implemented
Software development
Sensitive information is not used in the test, development, or QA environments.
Published Oct 7, 2025
Authorization is required if production data is copied to the test environment.
Published Oct 7, 2025
Test data securely is destroyed following testing.
Published Oct 7, 2025
Where production data is used for testing, it is masked, anonymized, or tokenized.
Published Oct 7, 2025
All test data is subject to the same classification and destruction policy as production data.
Published Oct 7, 2025
Developer access management
Software development
Policy and procedures in place to control access to source code and development tools.
Published Oct 7, 2025
Developer access to production environments is controlled.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Developer access to production environments uses just-in-time elevation or temporary tokens.
Published Oct 7, 2025
Access to source code is version-controlled and monitored for unauthorized changes.
Published Oct 7, 2025
Security analysis tools are used to detect defects in source code prior to production deployment.
Published Oct 7, 2025
Vulnerability management program established
Vulnerability management
Vulnerability management program and policy has been effectively developed and maintained.
Published Oct 7, 2025
Vulnerability scans are performed on a defined cadence, covering all internet-exposed and internal assets.
Published Oct 7, 2025
Risk-based prioritization is applied using CVSS and/or exploitability data.
Published Oct 7, 2025
Time-to-remediate targets are defined and tracked for high, medium, and low vulnerabilities.
Published Oct 7, 2025
Supported software versions are maintained
Vulnerability management
No products with an upcoming end of life detected.
Published Oct 7, 2025
No products with discretionary support detected.
Published Oct 7, 2025
Known vulnerabilities remediated
Vulnerability management
No known vulnerabilities detected.
Published Oct 7, 2025
Penetration testing program in place
Vulnerability management
Third-party web application penetration tests are conducted.
Published Oct 7, 2025
Penetration testing has a defined scope including web applications, internal infrastructure, and APIs where applicable.
Published Oct 7, 2025
Penetration test findings are tracked and remediated through a formal process.
Published Oct 7, 2025
Special interest group membership
Vulnerability management
Documented evidence of membership to forums relating to information security (such as ISC2, ISACA, OWASP), with an assigned role to monitor and feed insights back into the security program.
Published Oct 7, 2025
Risk management
Controls
Formalized risk assessment process
Enterprise risk management
Formal risk assessment process is defined and implemented.
Published Oct 7, 2025
Cybersecurity risk appetite and risk tolerance statements are formally documented, communicated to relevant stakeholders, and reviewed on a defined schedule.
Published Oct 7, 2025
Information assets and business processes are inventoried and evaluated for risk exposure as part of the risk assessment process.
Published Oct 7, 2025
Risk assessments are reviewed at planned intervals and upon major changes to the business environment or threat landscape.
Published Oct 7, 2025
Risk status and treatment outcomes are regularly communicated to enterprise risk stakeholders and incorporated into enterprise risk management (ERM) decision-making processes.
Published Oct 7, 2025
3rd-Nth party risk management program enforced
Third-Nth party management
A third-party risk management (TPRM) program is established and implemented.
Published Oct 7, 2025
All suppliers are identified and prioritized based on the criticality of their products or services to operations and cybersecurity posture.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Third-party risk management program policies, standards, and procedures are reviewed and approved by senior management.
Published Oct 7, 2025
Third-party risk management process includes onboarding and offboarding procedures for vendors.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Critical suppliers are identified and assessed for cybersecurity risks prior to acquisition or onboarding.
Published Oct 7, 2025
Third-party risk management program includes a definition of contract development, adherence and management policies and processes.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Third parties are continuously monitored for security risk, compliance, and performance throughout the lifecycle of their products and services.
Published Oct 7, 2025
Third-parties or service providers are evaluated for reassessment when there are material changes to risk posture, service offerings or contracts.
Published Oct 7, 2025
Cybersecurity risks from suppliers and third parties are included in risk communication across relevant business units and leadership.
Published Oct 7, 2025
Third-party risk management program requires third parties to disclose and provide visibility into their 3rd/Nth party dependencies.
Published Oct 7, 2025
Third-party risk management program includes requirements for traceability of subcontracted services or software components.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Third-party risk management program includes consideration of 4th and Nth parties in the ICT supply chain.
Published Oct 7, 2025
Third-party risk program defines periodic and event-based reassessment criteria.
Published Oct 7, 2025
Cloud services are evaluated for security risks and compliance prior to acquisition or use.
Published Oct 7, 2025
Cloud services are configured and monitored in accordance with defined security policies and contractual requirements.
Published Oct 7, 2025
Exit strategies and processes are documented for cloud services.
Published Oct 7, 2025
Hardware and software are verified for authenticity and integrity prior to acquisition or use, using trusted sources and validation mechanisms.
Published Oct 7, 2025
Supply chain risk considerations are integrated into enterprise risk management activities, including risk registers, strategy reviews, and prioritization processes.
Published Oct 7, 2025
Supply chain security practices are integrated into the organization's cybersecurity and enterprise risk management programs.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Contractual obligations cover Nth parties
Third-Nth party management
Third-party contracts obligate sub-suppliers (4th/Nth parties) to implement privacy and information-security controls equivalent to those required of the primary supplier.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
All third-party and outsourced service provider relationships require confidentiality and/or non-disclosure agreements.
Published Oct 7, 2025
Third-party contracts include fourth/Nth party privacy and security control requirements where applicable.
Published Oct 7, 2025
Third-party contracts require notification within a defined timeframe upon breach or significant incident.
Published Oct 7, 2025
Contracts include the right to audit or request evidence of compliance from subcontractors and 4th parties.
Published Oct 7, 2025
Data processing agreements and security/privacy clauses are mandated in all third-party contracts involving personal or sensitive data.
Published Oct 7, 2025
Operational resilience
Controls
Backup processes implemented
Business continuity
Scoped data backed up and stored offsite.
Published Oct 16, 2025
Backup and related restoration procedures tested at least annually.
Published Oct 16, 2025
Backup procedure in place for all information, software, and systems.
Published Oct 16, 2025
Backup data is encrypted in transit.
Published Oct 16, 2025
Backup data is encrypted at rest.
Published Oct 16, 2025
Backup data is protected from unauthorized access.
Published Oct 16, 2025
Backup procedures clearly define recovery point objectives (RPO) and recovery time objectives (RTO), which are reviewed and updated based on risk and business impact.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Immutable or isolated backup copies are maintained, preventing modification or deletion for a defined retention period.
Published Oct 16, 2025
SOC 2 TYPE 2 REPORT
Business continuity plans in place
Business continuity
Formal procedures for business continuity have been developed and documented.
Published Oct 7, 2025
Procedures are in place to ensure ICT continuity plans are regularly tested, evaluated for effectiveness, and approved by management.
Published Oct 7, 2025
Business continuity procedures include the continuity of information security activities and processes including intrusion detection, vulnerability management and log collection.
Published Oct 7, 2025
Business continuity plans include specific provisions for cloud-hosted services, including roles and responsibilities shared with cloud providers.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security requirements (confidentiality, integrity, and availability) are maintained during disruptions.
Published Oct 7, 2025
Redundancy mechanisms for critical systems are tested regularly.
Published Oct 7, 2025
Technical redundancy mechanisms are implemented to prevent downtime and ensure continuous system operation during outages.
Published Oct 7, 2025
System and infrastructure resource usage is monitored and adjusted to meet current and forecasted capacity needs, including stress testing of critical systems.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Integrity of restored systems and data is verified after an incident, and restoration is confirmed complete only after systems return to normal operating status.
Published Oct 7, 2025
Contingency measures are implemented to ensure business continuity during critical AI system disruptions.
Published Oct 7, 2025
Disaster recovery procedures established
Business continuity
Disaster recovery procedure in place to restore the security of information for critical business processes in the event of an interruption or failure.
Published Oct 7, 2025
Disaster recovery procedure in place to ensure that there are appropriate personnel ready to deal with any disruptions.
Published Oct 7, 2025
Formal disaster recovery procedures include specific actions to be taken in response to a disruptive event for each affected area.
Published Oct 7, 2025
Proactive detection of potential incidents
Cybersecurity incident management
Regular reviews of events are conducted to detect suspicious activity or potential incidents affecting systems with scoped data.
Published Oct 7, 2025
Regular security monitoring includes alerts for malware infections and suspicious activity.
Published Oct 7, 2025
A proactive detection capability is established and maintained .
Published Oct 7, 2025
Detection processes include automated correlation of logs, threat intelligence, and anomaly detection across endpoints, network, and cloud.
Published Oct 7, 2025
Threat intelligence from internal and external sources is collected and analysed to identify adversary tactics, techniques, and procedures (TTPs).
Published Oct 7, 2025
A documented process is in place to receive, analyze, and respond to vulnerability disclosures from internal and external sources, including coordinated disclosure from researchers or third parties.
Published Oct 7, 2025
Security alerts are tuned for false positives, prioritized based on asset criticality, and reviewed regularly.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Incident Management_V1.2_240430
Detection and response capabilities are thoroughly tested, and improvements from these exercises are identified and implemented.
Published Oct 7, 2025
Adversarial threat detection techniques and remediation steps address data poisoning or evasion attacks against AI models.
Published Oct 7, 2025
Incident response plan in place
Cybersecurity incident management
Cybersecurity Incident Management Program is approved and has a designated owner.
Published Oct 7, 2025
Incident-management programme has a clearly defined scope that includes all systems, networks, applications, endpoints, cloud environments, third-party services, and AI-driven systems where applicable.
Published Oct 7, 2025
Incident response plan includes a detailed action plan in the event of a security breach.
Published Oct 7, 2025
Incident response plan includes an escalation process with defined escalation paths and internal communication protocols.
Published Oct 7, 2025
Incident response plan includes notifying authorities and customers of serious data breaches.
Published Oct 7, 2025
Clocks are synchronized to enable correlation and analysis of security-related events and other recorded logging data.
Published Oct 7, 2025
Incident response plan recovery phase is executed following containment and eradication and requires remediation of any affected systems discovered after incident closure.
Published Oct 7, 2025
Lessons learned from information security incidents are documented and used to improve detection capabilities, response procedures, and preventive controls.
Published Oct 7, 2025
Procedures ensure prompt response and communication of operational impacts from degraded AI performance or biased outputs.
Published Oct 7, 2025
Incident response roles and responsibilities are assigned and communicated to relevant personnel, and reviewed regularly.
Published Oct 7, 2025
Confirmed security incidents are promptly contained through defined procedures.
Published Oct 7, 2025
Confirmed incidents are eradicated through defined procedures.
Published Oct 7, 2025
Incident response plans cover all potential incident types.
Published Oct 7, 2025
All incident reports are triaged and validated through a defined process before escalation or response activities are initiated.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Information security events are assessed using a defined process to determine whether they should be classified as incidents.
Published Oct 7, 2025
Incident classification criteria include data classification, impact to operations, regulatory exposure, and system criticality.
Published Oct 7, 2025
Incident details are shared with designated internal and external stakeholders during response activities.
Published Oct 7, 2025
Incident response and recovery plans include participation of relevant third parties and suppliers, with defined roles, communication procedures, and testing.
Published Oct 7, 2025
SOC 2 TYPE 2 REPORT
Criteria for initiating the recovery phase are defined, documented, and applied during incident response.
Published Oct 7, 2025
Incident response recovery actions are selected, scoped, and prioritized based on system criticality and business impact.
Published Oct 7, 2025
Recovery progress is communicated to designated internal and external stakeholders.
Published Oct 7, 2025
Public updates on recovery progress are shared through approved channels using defined messaging.
Published Oct 7, 2025
Incident recovery is formally closed based on defined criteria, with all incident documentation completed.
Published Oct 7, 2025
Root cause analysis is performed for all significant information security incidents.
Published Oct 7, 2025
Relevant authorities are identified and appropriate organizational contacts are established and maintained.
Published Oct 7, 2025
Security events are analyzed in real time or near real time to assess their scope, potential business impact, and criticality.
Published Oct 7, 2025
Information security incidents are recorded, tracked through resolution, and retained to support incident response improvement and reporting.
Published Oct 7, 2025
Procedures are in place to identify, collect, and preserve information relevant to security events and incidents for use as evidence.
Published Oct 7, 2025