Skip to main content

Control Evidence Mappings

Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.

Published (96)

AC-1: Establish access control policy and procedures for organizational systems

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-2: Manage system accounts including establishment, activation, modification, review, disabling, and removal

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-3: Enforce approved authorizations for logical access to information and system resources

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-4: Enforce approved authorizations for controlling the flow of information within the system and between systems

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-5: Separate duties of individuals to reduce risk of malevolent activity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-6: Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-7: Enforce a limit of consecutive invalid logon attempts and take action when maximum is exceeded

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-8: Display system use notification message before granting access

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-11: Prevent further access to the system by initiating a session lock after a defined period of inactivity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-12: Automatically terminate a user session after defined conditions

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-14: Identify permitted actions without identification or authentication

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-17: Establish usage restrictions and implementation guidance for remote access

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-1: Develop and document audit and accountability policy and procedures

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-2: Identify events that the system must be capable of auditing

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-3: Ensure audit records contain sufficient information to establish what occurred, when, where, source, outcome, and identity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-4: Allocate audit log storage capacity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-5: Alert personnel or take action upon audit logging process failures

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-6: Review and analyze audit records for indications of inappropriate or unusual activity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-7: Provide audit record reduction and report generation capability

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-8: Use internal system clocks to generate time stamps for audit records

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-9: Protect audit information and audit logging tools from unauthorized access, modification, and deletion

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-10: Provide irrefutable evidence that actions were performed (non-repudiation)

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-11: Retain audit records for a defined period to support after-the-fact investigations

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-12: Provide audit record generation capability at system components

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CA-2: Develop and implement security assessment plans

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CA-7: Develop and implement a system-level continuous monitoring strategy

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-2: Develop, document, and maintain a current baseline configuration of the system

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-3: Determine and document types of changes to the system that are configuration-controlled

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-6: Establish and document configuration settings for system components

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-8: Develop and document an inventory of system components

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-2: Uniquely identify and authenticate organizational users

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-4: Manage system identifiers by receiving authorization, selecting, assigning, and preventing reuse

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-5: Manage system authenticators including initial distribution, lost/compromised handling, and revocation

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-8: Uniquely identify and authenticate non-organizational users

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-4: Prevent unauthorized and unintended information transfer via shared system resources

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-7: Monitor and control communications at external managed interfaces

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-8: Protect the confidentiality and integrity of transmitted information

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-12: Establish and manage cryptographic keys

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-13: Implement cryptographic mechanisms in accordance with applicable laws and policies

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-28: Protect the confidentiality and integrity of information at rest

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

FedRAMP-AC-2(H): Manage system accounts with enhanced controls for high-impact systems

FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED

Published

FedRAMP-AC-3(H): Enforce approved authorizations with mandatory access control for high-impact data

FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED

Published

FedRAMP-AC-6(H): Employ least privilege with enhanced restrictions for high-impact operations

FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED

Published

FedRAMP-AU-2(H): Identify auditable events with expanded scope for high-impact systems

FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED

Published

FedRAMP-AU-3(H): Generate detailed audit records for all security-relevant events

FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED

Published

FedRAMP-AU-6(H): Review and correlate audit records with automated analysis tools

FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

FedRAMP-AU-9(H): Protect audit information with cryptographic integrity verification

FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

FedRAMP-AU-12(H): Generate audit records at all system components with centralized collection

FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

FedRAMP-CA-7(H): Implement continuous monitoring with automated assessment capabilities

FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

FedRAMP-CM-2(H): Maintain baseline configurations with automated drift detection

FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

FedRAMP-CM-6(H): Enforce configuration settings with automated compliance verification

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-IA-2(H): Implement multi-factor authentication for all access to high-impact systems

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-IA-5(H): Manage authenticators with enhanced rotation and complexity requirements

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SC-7(H): Implement boundary protection with enhanced monitoring at all external interfaces

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SC-8(H): Protect transmitted information with FIPS-validated cryptography

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SC-12(H): Establish and manage cryptographic keys with FIPS-compliant key management

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SC-13(H): Implement FIPS-validated cryptographic mechanisms for all data protection

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SC-28(H): Protect information at rest with FIPS-validated encryption

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SI-4(H): Implement system monitoring with real-time alerting for high-impact events

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SI-7(H): Employ integrity verification with automated response to detected changes

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-IR-4(H): Implement incident response with automated containment for high-impact systems

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-AC-11(H): Enforce session termination after defined inactivity period for privileged sessions

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-AC-5(H): Implement separation of duties with automated enforcement for critical operations

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-CA-3(H): Maintain system interconnection agreements with continuous authorization monitoring

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

FedRAMP-SR-3(H): Implement supply chain risk management with provenance verification for components

FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-GOV-1: Establish governance structures for AI risk management across the organization

NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED

Published

AI-RMF-GOV-2: Define roles, responsibilities, and authority for AI risk decisions

NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED

Published

AI-RMF-GOV-3: Implement organizational policies for responsible AI development and deployment

NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED

Published

AI-RMF-GOV-4: Establish processes for AI system documentation and transparency

NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED

Published

AI-RMF-GOV-5: Create mechanisms for ongoing AI risk assessment and monitoring

NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED

Published

AI-RMF-MAP-1: Identify and document AI system context, purpose, and intended use

NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

AI-RMF-MAP-2: Map AI system dependencies, data flows, and stakeholder impacts

NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

AI-RMF-MAP-3: Categorize AI risks based on likelihood, severity, and reversibility

NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

AI-RMF-MEASURE-1: Develop metrics and methods for measuring AI system performance and risk

NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

AI-RMF-MEASURE-2: Implement testing procedures for AI system reliability and safety

NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

AI-RMF-MEASURE-3: Establish benchmarks for acceptable AI system behavior and risk levels

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-1: Implement risk response strategies for identified AI risks

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-2: Establish processes for AI incident response and escalation

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-3: Create mechanisms for continuous improvement of AI risk management

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-4: Develop stakeholder communication procedures for AI risk information

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-5: Establish AI system decommissioning procedures with data retention requirements

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-6: Implement third-party AI component risk assessment and monitoring

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-7: Develop AI system performance degradation detection and response procedures

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-8: Establish AI model versioning and rollback procedures for production systems

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

AI-RMF-MANAGE-9: Implement AI system boundary definition and scope management processes

NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT

Published

GENAI-GOV-1.1: Establish governance for generative AI content provenance and attribution

NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED

Published

GENAI-GOV-1.2: Define acceptable use policies for generative AI in organizational context

NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED

Published

GENAI-MAP-1.1: Map generative AI system outputs to potential harm categories

NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED

Published

GENAI-MAP-1.2: Identify and document training data provenance and licensing status

NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED

Published

GENAI-MAP-2.1: Assess generative AI hallucination risks in operational context

NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED

Published

GENAI-MEASURE-1.1: Measure generative AI output quality and factual accuracy

NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

GENAI-MEASURE-2.1: Evaluate generative AI bias and fairness across protected categories

NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

GENAI-MANAGE-1.1: Manage generative AI content filtering and safety mechanisms

NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

GENAI-MANAGE-2.1: Implement human oversight for high-risk generative AI decisions

NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

GENAI-MANAGE-3.1: Establish feedback mechanisms for generative AI output quality improvement

NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED

Published

GENAI-MANAGE-4.1: Implement watermarking or provenance marking for generative AI outputs

NIST GenAI Profile 1.0 · INTEGRATION REQUIRED · PILOT

Published

In Progress (104)

These mappings are under editorial review and will be published after quality verification.

SI-4: Monitor the system to detect attacks, indicators of potential attacks, and unauthorized connections

NIST SP 800-53 · Under review

SI-7: Employ integrity verification tools to detect unauthorized changes to software, firmware, and information

NIST SP 800-53 · Under review

SI-10: Check the validity of information inputs

NIST SP 800-53 · Under review

SI-12: Manage and retain information within the system and output from the system in accordance with policies

NIST SP 800-53 · Under review

GENAI-MANAGE-5.1: Establish incident response procedures specific to generative AI content harms

NIST GenAI Profile · Under review

HIPAA-164.308(a)(1): Implement security management process with risk analysis and management

HIPAA · Under review

HIPAA-164.308(a)(2): Designate a security official responsible for security policies and procedures

HIPAA · Under review

HIPAA-164.308(a)(3): Implement workforce security with authorization and clearance procedures

HIPAA · Under review

HIPAA-164.308(a)(4): Implement information access management with access establishment and modification

HIPAA · Under review

HIPAA-164.308(a)(5): Implement security awareness training with periodic security reminders

HIPAA · Under review

HIPAA-164.308(a)(6): Implement security incident procedures with response and reporting

HIPAA · Under review

HIPAA-164.308(a)(7): Implement contingency plan with data backup, disaster recovery, and emergency operations

HIPAA · Under review

HIPAA-164.308(a)(8): Perform periodic technical and non-technical evaluations

HIPAA · Under review

HIPAA-164.310(a)(1): Implement facility access controls with contingency operations and access control

HIPAA · Under review

HIPAA-164.310(a)(2): Implement workstation use policies with appropriate physical safeguards

HIPAA · Under review

HIPAA-164.310(b): Implement workstation security with physical access restrictions

HIPAA · Under review

HIPAA-164.310(c): Implement device and media controls with disposal and re-use procedures

HIPAA · Under review

HIPAA-164.310(d)(1): Implement device and media controls with accountability and data backup

HIPAA · Under review

HIPAA-164.310(d)(2): Implement media movement tracking with data backup and storage

HIPAA · Under review

HIPAA-164.312(a)(1): Implement access control with unique user identification

HIPAA · Under review

HIPAA-164.312(a)(2): Implement emergency access procedures for protected health information

HIPAA · Under review

HIPAA-164.312(b): Implement audit controls with hardware, software, and procedural mechanisms

HIPAA · Under review

HIPAA-164.312(c)(1): Implement integrity controls with mechanisms to authenticate electronic PHI

HIPAA · Under review

HIPAA-164.312(c)(2): Implement integrity controls with electronic mechanisms to corroborate information

HIPAA · Under review

HIPAA-164.312(d): Implement person or entity authentication for PHI access

HIPAA · Under review

HIPAA-164.312(e)(1): Implement transmission security with integrity controls

HIPAA · Under review

HIPAA-164.312(e)(2): Implement transmission security with encryption for PHI in transit

HIPAA · Under review

HIPAA-164.314(a)(1): Implement business associate contracts with satisfactory assurances

HIPAA · Under review

HIPAA-164.314(b)(1): Implement requirements for group health plans with implementation specifications

HIPAA · Under review

HIPAA-164.316(b)(1): Implement documentation requirements with retention and availability

HIPAA · Under review

HIPAA-164.404(a): Implement breach notification procedures with required timelines and content

HIPAA · Under review

HIPAA-164.308(a)(1)(ii)(C): Implement sanctions policy for workforce members who violate security policies

HIPAA · Under review

HIPAA-164.308(a)(1)(ii)(D): Implement information system activity review with regular log analysis

HIPAA · Under review

HIPAA-164.312(a)(2)(iv): Implement encryption and decryption mechanisms for PHI at rest

HIPAA · Under review

HIPAA-164.312(a)(2)(iii): Implement automatic logoff for electronic sessions after inactivity period

HIPAA · Under review

EUAIA-Art6: Classification of AI systems as high-risk based on intended purpose and deployment context

EU AI Act · Under review

EUAIA-Art8: Establish and maintain risk management system throughout AI system lifecycle

EU AI Act · Under review

EUAIA-Art9: Implement data governance with training, validation, and testing data requirements

EU AI Act · Under review

EUAIA-Art10: Maintain technical documentation demonstrating compliance with requirements

EU AI Act · Under review

EUAIA-Art11: Implement record-keeping with automatic logging of AI system operations

EU AI Act · Under review

EUAIA-Art12: Ensure transparency with clear information about AI system capabilities and limitations

EU AI Act · Under review

EUAIA-Art13: Provide information to users about AI system operation and intended purpose

EU AI Act · Under review

EUAIA-Art14: Implement human oversight measures proportionate to risk level

EU AI Act · Under review

EUAIA-Art15: Ensure accuracy, robustness, and cybersecurity throughout AI system lifecycle

EU AI Act · Under review

EUAIA-Art16: Establish quality management system for high-risk AI systems

EU AI Act · Under review

EUAIA-Art17: Implement post-market monitoring system for high-risk AI systems

EU AI Act · Under review

EUAIA-Art26: Obligations for deployers of high-risk AI systems including oversight and monitoring

EU AI Act · Under review

EUAIA-Art27: Fundamental rights impact assessment for high-risk AI systems in public sector

EU AI Act · Under review

EUAIA-Art28: Obligations for providers and deployers regarding transparency

EU AI Act · Under review

EUAIA-Art29: Reporting obligations for serious incidents and malfunctioning

EU AI Act · Under review

EUAIA-Art52: Transparency obligations for AI systems interacting with natural persons

EU AI Act · Under review

EUAIA-Art53: Obligations for providers of general-purpose AI models

EU AI Act · Under review

EUAIA-Art54: Obligations for providers of GPAI models with systemic risk

EU AI Act · Under review

EUAIA-Art55: Codes of practice for general-purpose AI compliance

EU AI Act · Under review

EUAIA-Art56: Governance and enforcement mechanisms for AI Act compliance

EU AI Act · Under review

EUAIA-Art49: Registration obligations for high-risk AI systems in EU database

EU AI Act · Under review

EUAIA-Art43: Conformity assessment procedures for high-risk AI systems

EU AI Act · Under review

EUAIA-Art47: EU declaration of conformity requirements and content

EU AI Act · Under review

EUAIA-Art48: CE marking requirements and affixing procedures for AI systems

EU AI Act · Under review

EUAIA-Art99: Penalties and administrative fines for non-compliance with AI Act provisions

EU AI Act · Under review

GDPR-Art5: Principles relating to processing of personal data including lawfulness, fairness, and transparency

GDPR · Under review

GDPR-Art6: Lawfulness of processing with legal basis requirements

GDPR · Under review

GDPR-Art12: Transparent information, communication, and modalities for exercising data subject rights

GDPR · Under review

GDPR-Art13: Information to be provided where personal data are collected from the data subject

GDPR · Under review

GDPR-Art14: Information to be provided where personal data have not been obtained from the data subject

GDPR · Under review

GDPR-Art15: Right of access by the data subject to their personal data

GDPR · Under review

GDPR-Art17: Right to erasure and the right to be forgotten

GDPR · Under review

GDPR-Art20: Right to data portability between controllers

GDPR · Under review

GDPR-Art22: Automated individual decision-making including profiling with safeguards

GDPR · Under review

GDPR-Art25: Data protection by design and by default in processing operations

GDPR · Under review

GDPR-Art28: Obligations of processors with contractual requirements

GDPR · Under review

GDPR-Art30: Records of processing activities maintained by controller and processor

GDPR · Under review

GDPR-Art32: Security of processing with appropriate technical and organizational measures

GDPR · Under review

GDPR-Art33: Notification of personal data breach to supervisory authority

GDPR · Under review

GDPR-Art35: Data protection impact assessment for high-risk processing operations

GDPR · Under review

GDPR-Art37: Designation and position of data protection officer

GDPR · Under review

GDPR-Art44: Conditions for international transfers of personal data

GDPR · Under review

GDPR-Art31: Cooperation with supervisory authority in performance of its tasks

GDPR · Under review

SOC2-CC1.1: Control environment demonstrates commitment to integrity and ethical values

SOC 2 · Under review

SOC2-CC1.2: Board of directors demonstrates independence and oversight of internal controls

SOC 2 · Under review

SOC2-CC2.1: Management communicates information about internal control objectives and responsibilities

SOC 2 · Under review

SOC2-CC3.1: Entity identifies and assesses risks to achievement of objectives

SOC 2 · Under review

SOC2-CC5.1: Entity selects and develops control activities to mitigate risks

SOC 2 · Under review

SOC2-CC6.1: Entity implements logical and physical access controls over information assets

SOC 2 · Under review

SOC2-CC6.2: Entity restricts logical access to systems and data to authorized users

SOC 2 · Under review

SOC2-CC7.1: Entity detects and responds to system anomalies and security events

SOC 2 · Under review

SOC2-CC8.1: Entity manages changes to system components in a controlled manner

SOC 2 · Under review

SOC2-CC9.1: Entity identifies and mitigates risks from business disruptions

SOC 2 · Under review

SOC2-CC4.1: Entity evaluates and communicates internal control deficiencies in a timely manner

SOC 2 · Under review

SOC2-CC4.2: Entity obtains reasonable assurance about whether controls are operating effectively

SOC 2 · Under review

SOC2-CC6.3: Entity implements controls over system boundaries and data classification

SOC 2 · Under review

SOC2-CC7.2: Entity monitors system capacity and performance against defined thresholds

SOC 2 · Under review

SOC2-CC9.2: Entity implements data retention and disposal controls per policy requirements

SOC 2 · Under review

ISO27001-A5.1: Information security policies reviewed and approved by management

ISO 27001 · Under review

ISO27001-A5.2: Information security roles and responsibilities clearly defined and allocated

ISO 27001 · Under review

ISO27001-A8.1: Operational planning and control of information security processes

ISO 27001 · Under review

ISO27001-A8.2: Information security risk assessment performed at planned intervals

ISO 27001 · Under review

ISO27001-A8.3: Information security risk treatment plan implemented and monitored

ISO 27001 · Under review

ISO27001-A9.3: Management review of information security management system at planned intervals

ISO 27001 · Under review

ISO27001-A9.2: Internal audit of ISMS conducted at planned intervals against requirements

ISO 27001 · Under review

ISO27001-A10.1: Nonconformities identified and corrective actions implemented and verified

ISO 27001 · Under review

ISO27001-A10.2: Continual improvement of ISMS suitability, adequacy, and effectiveness

ISO 27001 · Under review

ISO27001-A7.2: Competence of persons doing work affecting information security performance

ISO 27001 · Under review

ISO27001-A7.5: Documented information required by ISMS created, updated, and controlled

ISO 27001 · Under review