IDQuestionAnswerExplanation and source
LOG-03.1Are security-related events identified and monitored within applications and the underlying infrastructure?YesThe company mandates capturing security-relevant events across product and infrastructure, and s…
[1] security-logging-standard.md
BCR-01.2Are the policies and procedures reviewed and updated at least annually?YesPolicies and procedures are required to be reviewed and approved on at least an annual basis.…
[1] controlled-document-procedure.md
HRS-11.2Are regular security awareness training updates provided?YesRegular security awareness training updates are provided through annual security awareness train…
[1] sec-training.md
CCC-07.1Are detection measures implemented with proactive notification if changes deviate from established baselines?PartialThe policies document that security detection controls identify events outside of established se…
[1] sec-incident-response.md
DSP-17.1Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle?YesThe provided documents confirm that processes, standards, and technical measures are established…
[1] data-classification-standard.md
HRS-07.1Are employees required to sign an employment agreement before gaining access to organizational information systems, resources, and assets?—No proof found