Management performs an annual risk assessment that includes the following:
• Determining business objectives.
• Involving appropriate levels of management.
RISKS CONTROLS • Analyzing risks associated with the threats. ATTRIBUTES POLICIES AUDIT
Procedures
• Identifyingand processes
threats are formally
to operations, documented
including securityscoping
threats,logical and restricted
using information access
technology
Risk ID Risk Description
Failure to define and communicate separation of duties. Leading to Control ID using
Control Description
principles of least privilege and separation of duties, user provisioning/deprovisioning Control Objective Control Owner Process
Access Control Frequency Impact Method Nature Assertion
Completeness, Policy Test Procedures Evidence
asset records.
unauthorized
Risks or impropertracked
are not formalized, access to
or sensitive
mitigatedsystems.
in accordance with forConsiders
• software,the
infrastructure,
significance and architectures
of the risks. covering sensitive information assets. Procedures Continuous Key Manual Preventative Accuracy, Cut-off
business obligations. • Determining a risk mitigation strategy. Annual Risk Assessment Annual Key Manual Preventative Accuracy
Completeness,
Company systems
Company data and datacorrupted
is breached, are lost due to a vendor
or made impact.
unavailable due to a The
A entityor
business
Anti-virus assesses
continuity and
anti-malware andmanages
solutionsrisks
disaster are associated
recovery is with
plan to
installed in vendors
place
detect and business
toprevent
or ensure partners
the organization
unauthorized or is Annual Vendor Reviews Annual Key Manual Detective Accuracy
malware attack. process leads non-compliance of contractual able to continue
malicious [Link] in the event of an interruption or failure of critical business Anti-Malware Continuous Key Automated Preventative Cutoff, Accuracy
Lack of formalized processes. The plan, including restoration of backups, Valuation &
obligations The entity maintains,
Employees with access monitors, and evaluates
to customer data current is
are required
tested annually. The
processing
to undergo capacity andCompany
a background use of
check Background Checks Continuous Key Manual Preventative Allocation
Company systems and data are breached or destroyed due to a uses a multi-location
system strategy
components (infrastructure, for its data,
facilities
andto permit the resumption of critical operations
natural disaster
Equipment or malicious
failures attack.
result in unavailability of critical company data at other entity
software) facilities
to manage in the event of loss
capacity of a facility. BC/DR Plan Annual Key Manual Preventative Right & Obligation
The
The company
Company requires
has changesdemand
implemented to
a Code
and to
software andenable the implementation
infrastructure
Of Business Conduct and components
Ethical
ofofadditional
the service to
and systems.
Information security is notapprove,
addressed in project plans and therefore capacity
be to help
authorized, meet
formally itsdocumented,
objectives. tested, reviewed, Capacity Management Continuous Key Automated Preventative Cutoff
Failure to define, review, publish, share, or communicate policy. The policy is reviewed, updated if applicable, andand approved prior to being
approved Completeness,
Occurrence,
risks are notSecurity
Information identified and treated.
Policies. Therefore, personnel don't understand implemented
by the senior in the production
management environment.
annually. The and
Codecontractual
includes information about Change Management
Commitment to Integrity Continuous Key Manual Preventative Accuracy, Valuation
Completeness,
The entity communicates the boundaries requirements and commitments
information
Lack of clearsecurity requirements.
contractual requirements causes unclear obligations to anonymous
to customerscommunication
through explicit channels.
provisions that are accepted through the contract acceptance & Ethical Behaviour Annual Key Manual Preventative Accuracy
Completeness,
customers. process.
Documented data backup policies and procedures are in place to guide personnel in Customer
Daily Commitments
Incremental Continuous Key Manual Preventative Accuracy, Existence
Company systems
data is unavailable when needed. The Data Classification
performing data backup Policy and Data
and restore Protection Policy identifies the types of confidential
activities. Backups Daily Key Automated Preventative Accuracy
Company and data are breached by unauthorized persons Data communication
information possessed between the customer
by the entity and types andofthe servicesthat
protection via are
the required.
internet uses
The an
due to improper
Incorrect labelinguse of encryption.
could lead to exposure of sensitive data and data encrypted session.
sensitivity Data Encryption Continuous Key Automated Preventative Cutoff
Employeesof the
are data and
required to security of the storage/processing
sign an acknowledgment form, uponlocation should
hire and on an beannual
considered
leakage.
Failure to communicate and acknowledge employee policies results when
basis, applying
indicatingclassification.
that they have been given access to the employee handbook and Data Protection Policy Annual Key Manual Preventative Occurrence
Completeness,
in misconduct of acceptable use breached
policies. by unauthorized persons understand their responsibility for Employee handbook Annual Key Manual Preventative Completeness,
Company systems and data are Full disk
The encryption
company is enforced
has developed on adhering
company
a Security
to
Incident
the associated
laptops through
Response apolicies and procedures.
centralized
Policy in order toendpoint
respond to
Accuracy
Completeness,
Accuracy,
due to improper use of encryption. management
security system.
incidents and personal data breaches in accordance Endpoint Encryption Continuous Key Automated Preventative Accuracy, Cut-off
The entity’s IT security group monitors the security impact of with applicable
emerging laws andand
technologies Occurrence,
Incident response
Appropriate contactsis slow
with and ineffective.
interest groups are not maintained regulations.
Production
the impact network
of changes device, database,
to applicable andorserver
laws logs are
regulations aretransmitted
consideredto bya senior
centralized Incident Response
Industry Security Continuous Key Manual Corrective Classification, Cutoff
Completeness,
logging system, which is monitored by appropriate, qualified security staff. The company Completeness,
resulting in
Company a lack
data of understanding
is lost or mishandled of current
due threats.
to lack of communication on management.
A policyestablish
is documented Subscriptions Continuous Key Manual Preventative Accuracy
should controlsand distributed
which internally
ensure access and is
to logs externally
restricted which
only addresses
to authorized the Information Security Accuracy,
appropriate
Company safeguards.
systems and data are breached by unauthorized persons information
The Company's
personnel security
and can requirements
Organizational
demonstrate Chartof the
that the logs
and data the company
reporting
have channelshandles
remained is reviewedfrom
unaltered and time
approved
of by Policies Annual Key Manual Preventative Occurrence
due to improper segregation. Management
collection.
Security annually.
reviews, This chart
vulnerability is availableand
assessments, for all employees
penetration via designated
testing are performedtool. An
byfrom Log Management Continuous Key Automated Corrective Accuracy &
The production
organizational network
structure is
is segmented
in place to help ensure that confidential data is isolated Valuation
Productionlines
systems are compromised due of
to a
improper information security personnel and to establish
third-party and communicate
vendors on a periodic keybasis
areas toofidentify
authority,
Reporting are unclear and escalation businesssegmentation.
impacting other unrelated
responsibility,
threats and
networks.
and
assess appropriate
their lines
potential of [Link] organizational structure is updated Network Segmentation Continuous Key Automated Preventative Allocation
events is slow and and
ineffective. Quarterly
[Link] access reviews are impact
conducted to system security,
of production availability,
servers, and and
databases, Organization Chart Continuous Key Automated Preventative
Right &
Right
Right
& Obligation,
Obligation,
& Obligation
Company systems data are breached by unauthorized persons confidentiality. Any security vulnerabilities that are detected are triaged
applications to validate that internal user access is commensurate with job responsibilities and monitored Completeness,
Cutoff,
via a vulnerability
Escalated privilegesin are
non-production
not reviewedsystems or networks.
and adjusted when job changes through
by resolution.
reviewing with manager and/or system owners. Identified access changes are tracked to Penetration Testing Annual Key Manual Preventative Accuracy, Cutoff
Completeness,
occur
Overlycausing unnecessary
permissive and to
access leads improper access.
increased exposure of sensitive remediation.
Administrative access privileges to the in-scope systems are restricted to user accounts Periodic Access
Privileged Reviews
Access Quarterly Key Manual Preventative Accuracy
data.
Compromised credentials leads to unauthorized access to sensitive accessible by authorized personnel. Management
Production Access Continuous Key Manual Preventative Accuracy
Completeness,
The company has a formal systems development life cycle (SDLC) methodology in place
systems.
Failure to implement a formalized SDLC leads to invalid testing, Access to production
that governs environment
the development, requires implementation,
acquisition, two factor authentication
changes, and SSH certification.
including emergency Restricted Continuous Key Manual Preventative Accuracy, Existence
Completeness,
availability
Access of the service,
credentials are notand violates
validated separation
causing of duties attack
an increased principles. changes,
An and maintenance
authorized IP address viaofan
information
authorizedsystems andpassword,
username, related technology
and MFA, requirements.
and an SSH SDLC Methodology
Secure Access to Continuous Key Manual Preventative Accuracy
Completeness,
surface for production systems. public key connection
Management arecontinued
establishes required for remote
training access
and to production.
monitors completion of security training Production Systems Continuous Key Manual Preventative Accuracy
Completeness,
The Vendor Management Policy defines a framework for the onboarding and management
Employees
Vendors areare
notnot aware of security
appropriately best
reviewed topractices.
ensure contractual programs
of upon
the vendor hire and atlife
relationship least annually.
cycle. The Security team assesses new vendors according to SecurityManagement
Vendor Training Annual Key Manual Preventative Accuracy
security obligations can be met. the Vendor
The companyManagement Policy prior
has implemented to engaging
a designated tool with the vendor.
in order to perform continuous Program Continuous Key Manual Preventative Accuracy
Completeness,
Critical vulnerabilities are exploited by adversaries. vulnerability
The companyscans.
has a Alerts
definedare sent to and
cadence the documented
relevant personnel,
processbased on predefined
for successful rules.
backup Vulnerability
Annual Backup Management Continuous Key Manual Preventative Accuracy
Disasterthat
System recovery
is not event causes
cataloged loss of customer
appropriately data.
does not receive restoration.
A formal inventory of production system assets that includes asset owners is maintained, Restoration Test Annual Key Manual Preventative Cutoff, Accuracy
Valuation &
necessary security updates. and changes
Formal to the are
procedures inventory are logged.
documented that outline the process the Company's staff follows to Asset Inventory
Backup and Recovery Continuous Key Manual Preventative Allocation
Point in time recovery for critical or sensitive systems is unavailable. back up and
An annual recover
board customer
meeting data.
is conducted with executive level attendance and meeting Procedures Annual Key Manual Preventative Right & Obligation
Lack
Thereofisvisibility and oversight
a misalignment betweenof company
the boardsobjectives
expectations and the minutes
The entity
board of directors designs,
establishes and maintains a formal charterdocuments,
which describes Annual Board Meetings Annual Key Manual Preventative Cutoff
The authorizes, develops or acquires, configures, tests,their Completeness,
Occurrence,
companies objectives.
Unauthorized changes are implemented into production with adverse responsibilities
approves, and oversight
and implements of management’s
changes system
to infrastructure, of internal
data, control.
software, and procedures to Board Oversight Continuous Key Manual Preventative Accuracy, Valuation
Completeness,
or unexpectedtoresults.
Modifications configurations by unauthorized personnel leads to meet its objectives.
Configuration settings are secured through access assigned to specified personnel with Change Management
Configuration Continuous Key Manual Preventative Accuracy
Completeness,
application security
Misalignment vulnerabilities.
with controls or gaps in coverage as the product monitoring enabled to ensure standard security controls are implemented. Management Continuous Key Manual Preventative Accuracy
Completeness,
evolves. processes are adversely impacted by a change that was
Customer compliance with AWS security standards and automatically pushed to the host fleet Control Self-Assessment
Customer Release Annual Key Manual Preventative Accuracy
not communicated.
Data leakage likelihood is increased due to improper handling of Company
Policies posts
and notifications
procedures are inofplace
new releases
to defineand
datacustomer-impacting
categories and guidechanges.
personnel in data Communications Continuous Key Manual Preventative Cutoff
Completeness,
Occurrence,
sensitive
Data datais not completed within appropriate time frame leading
request labeling, handling,
Customer transmission,
data deletion requests storage, retention,
are managed and removal
centrally of data.
to help ensure the data is deleted Data Delete
Data Classification
RequestPolicy Annual Key Manual Preventative Accuracy, Valuation
Completeness,
to regulatoryorviolation
Contractual andobligations
regulatory fines. are not met for disposing of within
The agreed-upon
entity disposes timeframe. Completion Continuous Key Manual Preventative Accuracy
A replication processofisconfidential or sensitive
in place to perform realinformation to meet
time replication the entity’s
between objectives
databases. Data Retention and Completeness,
data.
Replication delay creates misalignment with recovery time related to retention.
Replication lag is monitored and notification alerts are sent to designated IT staff. Disposal Procedures Continuous Key Manual Preventative Accuracy, Existence
objectives.
Lack of transparency and visibility into customer impacting issues Administrator accesslink
A customer support is restricted tofor
is provided authorized
users to personnel.
inform the vendor of security issues or Database
Customer Replication
Incident Continuous Key Automated Preventative Accuracy
within the product complaints.
An enterprise monitoring application is configured to monitor the in-scope systems capacity Reporting Mechanism Continuous Key Manual Corrective Cutoff
System availability
Security events are is compromised.
not received and investigated in a timely levels
An and
IDSand alert IT personnel
is configured to alert when predefined
security personnelthresholds have security
when network been met.
vulnerabilities are Infrastructure
Intrusion Monitoring Continuous
Detection Key Automated Detective Occurrence
Roles responsibilities of key managers are defined in written job descriptions, including
manner, increasing the likelihood of breach. detected.
duties such as proper oversight, System Continuous Key Automated Detective Cutoff
Password parameters have beenmanagement,
implemented in and monitoringwith
accordance of vendor, security
corporate and
password Completeness,
Occurrence,
Gap in responsibilities creates a single point of failure. availability
policies for activities.
user workstations and devices. Users are required to provide a password to Job Description Continuous Key Manual Preventative Accuracy, Valuation
Completeness,
User device
Failure is compromised
to identify due to weak
underperformance credential
or skill enforcement.
gaps results in authenticate
Employees to the an
receive network
annualand sensitive environments.
assessment of performance covering measurable objectives Password Parameters Continuous Key Manual Preventative Accuracy
unacceptable
Line outcomes.
of sight and control of sensitive data is lost through the use of and
A alignment
removable with company
media values.
policy is documented for the authorization process, restrictions, and Performance Reviews Annual Key Manual Preventative Cutoff
Completeness,
Occurrence,
external devices. handling to identify, analyze, treat, and monitor risks that impact business objectives and
Program Removable Media Continuous Key Manual Preventative Accuracy, Valuation
Completeness,
Risksof
Lack are not formally
company identified
awareness to stakeholders
regarding and management.
the necessary security and regulatory
Defined requirements
roles and responsibilities are set for maintaining information security and Risk Management
Security and Compliance Continuous Key Manual Preventative Accuracy
Completeness,
compliance
Oversight ofrequirements.
privileged accounts with elevated access is not compliance.
Service account credentials are accessed by designated personnel with audit trail Service Account Password Continuous
Roles Key Manual Preventative Accuracy, Existence
maintained.
Customers are unable to receive timely and accurate support for reporting. Credentials
A service level are rotated
agreement outlineson a mechanism
the quarterly basis.
for a customer to receive product Management Continuous Key Manual Preventative Accuracy
product utilization. support.
Requirements for confidentiality or non-disclosure agreements reflecting the organization’s Support Link on Website
Vendor Confidentiality Continuous Key Manual Detective Cutoff
Unclear expectations and requirements regarding data protection. needsis implemented to restrict access, protect authentication and identification
WAF Agreements Continuous Key Manual Preventative Occurrence
Completeness,
Unauthorized access to sensitive data systems. credentials, and require additional credentials or authentication. Web Application Firewalls Continuous Key Manual Preventative Accuracy