Control Evidence Mappings
Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.
Published (96)
AC-1: Establish access control policy and procedures for organizational systems
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-2: Manage system accounts including establishment, activation, modification, review, disabling, and removal
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-3: Enforce approved authorizations for logical access to information and system resources
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-4: Enforce approved authorizations for controlling the flow of information within the system and between systems
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-5: Separate duties of individuals to reduce risk of malevolent activity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-6: Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-7: Enforce a limit of consecutive invalid logon attempts and take action when maximum is exceeded
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-8: Display system use notification message before granting access
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-11: Prevent further access to the system by initiating a session lock after a defined period of inactivity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-12: Automatically terminate a user session after defined conditions
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-14: Identify permitted actions without identification or authentication
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-17: Establish usage restrictions and implementation guidance for remote access
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-1: Develop and document audit and accountability policy and procedures
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-2: Identify events that the system must be capable of auditing
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-3: Ensure audit records contain sufficient information to establish what occurred, when, where, source, outcome, and identity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-4: Allocate audit log storage capacity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-5: Alert personnel or take action upon audit logging process failures
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-6: Review and analyze audit records for indications of inappropriate or unusual activity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-7: Provide audit record reduction and report generation capability
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-8: Use internal system clocks to generate time stamps for audit records
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-9: Protect audit information and audit logging tools from unauthorized access, modification, and deletion
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-10: Provide irrefutable evidence that actions were performed (non-repudiation)
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-11: Retain audit records for a defined period to support after-the-fact investigations
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-12: Provide audit record generation capability at system components
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CA-2: Develop and implement security assessment plans
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CA-7: Develop and implement a system-level continuous monitoring strategy
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-2: Develop, document, and maintain a current baseline configuration of the system
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-3: Determine and document types of changes to the system that are configuration-controlled
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-6: Establish and document configuration settings for system components
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-8: Develop and document an inventory of system components
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-2: Uniquely identify and authenticate organizational users
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-4: Manage system identifiers by receiving authorization, selecting, assigning, and preventing reuse
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-5: Manage system authenticators including initial distribution, lost/compromised handling, and revocation
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-8: Uniquely identify and authenticate non-organizational users
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-4: Prevent unauthorized and unintended information transfer via shared system resources
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-7: Monitor and control communications at external managed interfaces
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-8: Protect the confidentiality and integrity of transmitted information
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-12: Establish and manage cryptographic keys
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-13: Implement cryptographic mechanisms in accordance with applicable laws and policies
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-28: Protect the confidentiality and integrity of information at rest
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
FedRAMP-AC-2(H): Manage system accounts with enhanced controls for high-impact systems
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AC-3(H): Enforce approved authorizations with mandatory access control for high-impact data
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AC-6(H): Employ least privilege with enhanced restrictions for high-impact operations
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AU-2(H): Identify auditable events with expanded scope for high-impact systems
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AU-3(H): Generate detailed audit records for all security-relevant events
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AU-6(H): Review and correlate audit records with automated analysis tools
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-AU-9(H): Protect audit information with cryptographic integrity verification
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-AU-12(H): Generate audit records at all system components with centralized collection
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-CA-7(H): Implement continuous monitoring with automated assessment capabilities
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-CM-2(H): Maintain baseline configurations with automated drift detection
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-CM-6(H): Enforce configuration settings with automated compliance verification
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-IA-2(H): Implement multi-factor authentication for all access to high-impact systems
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-IA-5(H): Manage authenticators with enhanced rotation and complexity requirements
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-7(H): Implement boundary protection with enhanced monitoring at all external interfaces
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-8(H): Protect transmitted information with FIPS-validated cryptography
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-12(H): Establish and manage cryptographic keys with FIPS-compliant key management
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-13(H): Implement FIPS-validated cryptographic mechanisms for all data protection
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-28(H): Protect information at rest with FIPS-validated encryption
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SI-4(H): Implement system monitoring with real-time alerting for high-impact events
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SI-7(H): Employ integrity verification with automated response to detected changes
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-IR-4(H): Implement incident response with automated containment for high-impact systems
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-AC-11(H): Enforce session termination after defined inactivity period for privileged sessions
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-AC-5(H): Implement separation of duties with automated enforcement for critical operations
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-CA-3(H): Maintain system interconnection agreements with continuous authorization monitoring
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SR-3(H): Implement supply chain risk management with provenance verification for components
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
AI-RMF-GOV-1: Establish governance structures for AI risk management across the organization
NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED
AI-RMF-GOV-2: Define roles, responsibilities, and authority for AI risk decisions
NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED
AI-RMF-GOV-3: Implement organizational policies for responsible AI development and deployment
NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED
AI-RMF-GOV-4: Establish processes for AI system documentation and transparency
NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED
AI-RMF-GOV-5: Create mechanisms for ongoing AI risk assessment and monitoring
NIST AI RMF 1.0 · SUPPORTED EVIDENCE · TESTED
AI-RMF-MAP-1: Identify and document AI system context, purpose, and intended use
NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
AI-RMF-MAP-2: Map AI system dependencies, data flows, and stakeholder impacts
NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
AI-RMF-MAP-3: Categorize AI risks based on likelihood, severity, and reversibility
NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
AI-RMF-MEASURE-1: Develop metrics and methods for measuring AI system performance and risk
NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
AI-RMF-MEASURE-2: Implement testing procedures for AI system reliability and safety
NIST AI RMF 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
AI-RMF-MEASURE-3: Establish benchmarks for acceptable AI system behavior and risk levels
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-1: Implement risk response strategies for identified AI risks
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-2: Establish processes for AI incident response and escalation
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-3: Create mechanisms for continuous improvement of AI risk management
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-4: Develop stakeholder communication procedures for AI risk information
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-5: Establish AI system decommissioning procedures with data retention requirements
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-6: Implement third-party AI component risk assessment and monitoring
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-7: Develop AI system performance degradation detection and response procedures
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-8: Establish AI model versioning and rollback procedures for production systems
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
AI-RMF-MANAGE-9: Implement AI system boundary definition and scope management processes
NIST AI RMF 1.0 · INTEGRATION REQUIRED · PILOT
GENAI-GOV-1.1: Establish governance for generative AI content provenance and attribution
NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED
GENAI-GOV-1.2: Define acceptable use policies for generative AI in organizational context
NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED
GENAI-MAP-1.1: Map generative AI system outputs to potential harm categories
NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED
GENAI-MAP-1.2: Identify and document training data provenance and licensing status
NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED
GENAI-MAP-2.1: Assess generative AI hallucination risks in operational context
NIST GenAI Profile 1.0 · SUPPORTED EVIDENCE · TESTED
GENAI-MEASURE-1.1: Measure generative AI output quality and factual accuracy
NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
GENAI-MEASURE-2.1: Evaluate generative AI bias and fairness across protected categories
NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
GENAI-MANAGE-1.1: Manage generative AI content filtering and safety mechanisms
NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
GENAI-MANAGE-2.1: Implement human oversight for high-risk generative AI decisions
NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
GENAI-MANAGE-3.1: Establish feedback mechanisms for generative AI output quality improvement
NIST GenAI Profile 1.0 · PARTIAL TECHNICAL SUPPORT · SUPPORTED
GENAI-MANAGE-4.1: Implement watermarking or provenance marking for generative AI outputs
NIST GenAI Profile 1.0 · INTEGRATION REQUIRED · PILOT
In Progress (104)
These mappings are under editorial review and will be published after quality verification.
SI-4: Monitor the system to detect attacks, indicators of potential attacks, and unauthorized connections
NIST SP 800-53 · Under review
SI-7: Employ integrity verification tools to detect unauthorized changes to software, firmware, and information
NIST SP 800-53 · Under review
SI-10: Check the validity of information inputs
NIST SP 800-53 · Under review
SI-12: Manage and retain information within the system and output from the system in accordance with policies
NIST SP 800-53 · Under review
GENAI-MANAGE-5.1: Establish incident response procedures specific to generative AI content harms
NIST GenAI Profile · Under review
HIPAA-164.308(a)(1): Implement security management process with risk analysis and management
HIPAA · Under review
HIPAA-164.308(a)(2): Designate a security official responsible for security policies and procedures
HIPAA · Under review
HIPAA-164.308(a)(3): Implement workforce security with authorization and clearance procedures
HIPAA · Under review
HIPAA-164.308(a)(4): Implement information access management with access establishment and modification
HIPAA · Under review
HIPAA-164.308(a)(5): Implement security awareness training with periodic security reminders
HIPAA · Under review
HIPAA-164.308(a)(6): Implement security incident procedures with response and reporting
HIPAA · Under review
HIPAA-164.308(a)(7): Implement contingency plan with data backup, disaster recovery, and emergency operations
HIPAA · Under review
HIPAA-164.308(a)(8): Perform periodic technical and non-technical evaluations
HIPAA · Under review
HIPAA-164.310(a)(1): Implement facility access controls with contingency operations and access control
HIPAA · Under review
HIPAA-164.310(a)(2): Implement workstation use policies with appropriate physical safeguards
HIPAA · Under review
HIPAA-164.310(b): Implement workstation security with physical access restrictions
HIPAA · Under review
HIPAA-164.310(c): Implement device and media controls with disposal and re-use procedures
HIPAA · Under review
HIPAA-164.310(d)(1): Implement device and media controls with accountability and data backup
HIPAA · Under review
HIPAA-164.310(d)(2): Implement media movement tracking with data backup and storage
HIPAA · Under review
HIPAA-164.312(a)(1): Implement access control with unique user identification
HIPAA · Under review
HIPAA-164.312(a)(2): Implement emergency access procedures for protected health information
HIPAA · Under review
HIPAA-164.312(b): Implement audit controls with hardware, software, and procedural mechanisms
HIPAA · Under review
HIPAA-164.312(c)(1): Implement integrity controls with mechanisms to authenticate electronic PHI
HIPAA · Under review
HIPAA-164.312(c)(2): Implement integrity controls with electronic mechanisms to corroborate information
HIPAA · Under review
HIPAA-164.312(d): Implement person or entity authentication for PHI access
HIPAA · Under review
HIPAA-164.312(e)(1): Implement transmission security with integrity controls
HIPAA · Under review
HIPAA-164.312(e)(2): Implement transmission security with encryption for PHI in transit
HIPAA · Under review
HIPAA-164.314(a)(1): Implement business associate contracts with satisfactory assurances
HIPAA · Under review
HIPAA-164.314(b)(1): Implement requirements for group health plans with implementation specifications
HIPAA · Under review
HIPAA-164.316(b)(1): Implement documentation requirements with retention and availability
HIPAA · Under review
HIPAA-164.404(a): Implement breach notification procedures with required timelines and content
HIPAA · Under review
HIPAA-164.308(a)(1)(ii)(C): Implement sanctions policy for workforce members who violate security policies
HIPAA · Under review
HIPAA-164.308(a)(1)(ii)(D): Implement information system activity review with regular log analysis
HIPAA · Under review
HIPAA-164.312(a)(2)(iv): Implement encryption and decryption mechanisms for PHI at rest
HIPAA · Under review
HIPAA-164.312(a)(2)(iii): Implement automatic logoff for electronic sessions after inactivity period
HIPAA · Under review
EUAIA-Art6: Classification of AI systems as high-risk based on intended purpose and deployment context
EU AI Act · Under review
EUAIA-Art8: Establish and maintain risk management system throughout AI system lifecycle
EU AI Act · Under review
EUAIA-Art9: Implement data governance with training, validation, and testing data requirements
EU AI Act · Under review
EUAIA-Art10: Maintain technical documentation demonstrating compliance with requirements
EU AI Act · Under review
EUAIA-Art11: Implement record-keeping with automatic logging of AI system operations
EU AI Act · Under review
EUAIA-Art12: Ensure transparency with clear information about AI system capabilities and limitations
EU AI Act · Under review
EUAIA-Art13: Provide information to users about AI system operation and intended purpose
EU AI Act · Under review
EUAIA-Art14: Implement human oversight measures proportionate to risk level
EU AI Act · Under review
EUAIA-Art15: Ensure accuracy, robustness, and cybersecurity throughout AI system lifecycle
EU AI Act · Under review
EUAIA-Art16: Establish quality management system for high-risk AI systems
EU AI Act · Under review
EUAIA-Art17: Implement post-market monitoring system for high-risk AI systems
EU AI Act · Under review
EUAIA-Art26: Obligations for deployers of high-risk AI systems including oversight and monitoring
EU AI Act · Under review
EUAIA-Art27: Fundamental rights impact assessment for high-risk AI systems in public sector
EU AI Act · Under review
EUAIA-Art28: Obligations for providers and deployers regarding transparency
EU AI Act · Under review
EUAIA-Art29: Reporting obligations for serious incidents and malfunctioning
EU AI Act · Under review
EUAIA-Art52: Transparency obligations for AI systems interacting with natural persons
EU AI Act · Under review
EUAIA-Art53: Obligations for providers of general-purpose AI models
EU AI Act · Under review
EUAIA-Art54: Obligations for providers of GPAI models with systemic risk
EU AI Act · Under review
EUAIA-Art55: Codes of practice for general-purpose AI compliance
EU AI Act · Under review
EUAIA-Art56: Governance and enforcement mechanisms for AI Act compliance
EU AI Act · Under review
EUAIA-Art49: Registration obligations for high-risk AI systems in EU database
EU AI Act · Under review
EUAIA-Art43: Conformity assessment procedures for high-risk AI systems
EU AI Act · Under review
EUAIA-Art47: EU declaration of conformity requirements and content
EU AI Act · Under review
EUAIA-Art48: CE marking requirements and affixing procedures for AI systems
EU AI Act · Under review
EUAIA-Art99: Penalties and administrative fines for non-compliance with AI Act provisions
EU AI Act · Under review
GDPR-Art5: Principles relating to processing of personal data including lawfulness, fairness, and transparency
GDPR · Under review
GDPR-Art6: Lawfulness of processing with legal basis requirements
GDPR · Under review
GDPR-Art12: Transparent information, communication, and modalities for exercising data subject rights
GDPR · Under review
GDPR-Art13: Information to be provided where personal data are collected from the data subject
GDPR · Under review
GDPR-Art14: Information to be provided where personal data have not been obtained from the data subject
GDPR · Under review
GDPR-Art15: Right of access by the data subject to their personal data
GDPR · Under review
GDPR-Art17: Right to erasure and the right to be forgotten
GDPR · Under review
GDPR-Art20: Right to data portability between controllers
GDPR · Under review
GDPR-Art22: Automated individual decision-making including profiling with safeguards
GDPR · Under review
GDPR-Art25: Data protection by design and by default in processing operations
GDPR · Under review
GDPR-Art28: Obligations of processors with contractual requirements
GDPR · Under review
GDPR-Art30: Records of processing activities maintained by controller and processor
GDPR · Under review
GDPR-Art32: Security of processing with appropriate technical and organizational measures
GDPR · Under review
GDPR-Art33: Notification of personal data breach to supervisory authority
GDPR · Under review
GDPR-Art35: Data protection impact assessment for high-risk processing operations
GDPR · Under review
GDPR-Art37: Designation and position of data protection officer
GDPR · Under review
GDPR-Art44: Conditions for international transfers of personal data
GDPR · Under review
GDPR-Art31: Cooperation with supervisory authority in performance of its tasks
GDPR · Under review
SOC2-CC1.1: Control environment demonstrates commitment to integrity and ethical values
SOC 2 · Under review
SOC2-CC1.2: Board of directors demonstrates independence and oversight of internal controls
SOC 2 · Under review
SOC2-CC2.1: Management communicates information about internal control objectives and responsibilities
SOC 2 · Under review
SOC2-CC3.1: Entity identifies and assesses risks to achievement of objectives
SOC 2 · Under review
SOC2-CC5.1: Entity selects and develops control activities to mitigate risks
SOC 2 · Under review
SOC2-CC6.1: Entity implements logical and physical access controls over information assets
SOC 2 · Under review
SOC2-CC6.2: Entity restricts logical access to systems and data to authorized users
SOC 2 · Under review
SOC2-CC7.1: Entity detects and responds to system anomalies and security events
SOC 2 · Under review
SOC2-CC8.1: Entity manages changes to system components in a controlled manner
SOC 2 · Under review
SOC2-CC9.1: Entity identifies and mitigates risks from business disruptions
SOC 2 · Under review
SOC2-CC4.1: Entity evaluates and communicates internal control deficiencies in a timely manner
SOC 2 · Under review
SOC2-CC4.2: Entity obtains reasonable assurance about whether controls are operating effectively
SOC 2 · Under review
SOC2-CC6.3: Entity implements controls over system boundaries and data classification
SOC 2 · Under review
SOC2-CC7.2: Entity monitors system capacity and performance against defined thresholds
SOC 2 · Under review
SOC2-CC9.2: Entity implements data retention and disposal controls per policy requirements
SOC 2 · Under review
ISO27001-A5.1: Information security policies reviewed and approved by management
ISO 27001 · Under review
ISO27001-A5.2: Information security roles and responsibilities clearly defined and allocated
ISO 27001 · Under review
ISO27001-A8.1: Operational planning and control of information security processes
ISO 27001 · Under review
ISO27001-A8.2: Information security risk assessment performed at planned intervals
ISO 27001 · Under review
ISO27001-A8.3: Information security risk treatment plan implemented and monitored
ISO 27001 · Under review
ISO27001-A9.3: Management review of information security management system at planned intervals
ISO 27001 · Under review
ISO27001-A9.2: Internal audit of ISMS conducted at planned intervals against requirements
ISO 27001 · Under review
ISO27001-A10.1: Nonconformities identified and corrective actions implemented and verified
ISO 27001 · Under review
ISO27001-A10.2: Continual improvement of ISMS suitability, adequacy, and effectiveness
ISO 27001 · Under review
ISO27001-A7.2: Competence of persons doing work affecting information security performance
ISO 27001 · Under review
ISO27001-A7.5: Documented information required by ISMS created, updated, and controlled
ISO 27001 · Under review