| 7bbb248db7dd5d48… | PYRANA.ai requires a vendor security assessment before third-party products or services are used so that the provider's ability to maintain appropriate security and privacy controls is confirmed. | active | contextual | yes | |
| f05e4b9f12daeccc… | For risks identified during the assessment process, PYRANA.ai must classify the risks and develop action plans to mitigate discovered risks so that identified issues are addressed. | active | contextual | yes | |
| bb1bc42b01d65b0a… | PYRANA.ai requires a risk assessment to be performed at least annually so that organizational risks are periodically evaluated. | active | contextual | yes | |
| 49b176128a6de842… | A message should be sent to security@pyrana.ai if a person believes there may be a security incident or threat so that the potential issue is reported to the security contact. | active | contextual | yes | |
| e0dedc2fb9a693bc… | Early detection and response can mitigate damages and minimize further risk to PYRANA.ai so that incident impact is reduced. | active | contextual | yes | |
| acccb69b74bcd82d… | Incident response procedures must ensure timely detection, effective response, proper handling, communication with affected parties, and documentation of lessons learned during security incidents. | active | contextual | yes | |
| 4ca2439b707cb64d… | The security incident response plan must be tested, reviewed, and updated at least annually so that it remains current and effective. | active | contextual | yes | |
| 334a20c6bd72d6c3… | The security incident response plan must be executed after discovery of an incident such as system compromise or unintended or unauthorized acquisition, access, use, or release of non-public information. | active | contextual | yes | |
| 6e46b0d8a700a591… | System and user activity logs may be used to assess the causes of incidents and problems so that investigations can determine underlying causes. | active | contextual | yes | |
| ea01a6948cf1d167… | Logging should be enabled at the application and infrastructure level to monitor administrative activities, logon attempts, data deletions, function changes, and changes to security configurations, permissions, and roles. | active | contextual | yes | |
| 39755084d8b23e57… | PYRANA.ai collects and monitors audit logs and alerts on key events from production systems, applications, databases, servers, message queues, load balancers, critical services, and IAM user and admin activities so that important operational and security events are observed. | active | contextual | yes | |
| 6df37a714da29c19… | The IT leadership team must assess patches monthly and approve them for implementation so that critical patches are updated on a timely basis. | active | contextual | yes | |
| e62e11fc92ce3888… | Agreements must be updated and amended as necessary when business, legal, and regulatory requirements change so that vendor arrangements remain aligned with current obligations. | active | contextual | yes | |
| 4498580b5d3e7356… | The vendor review may include collecting compliance audits such as SOC 1, SOC 2, PCI DSS, HITRUST, and ISO27001, or other security compliance evidence so that vendor assurance is supported by documented evidence. | active | contextual | yes | |
| 8090205321fe3970… | For risks identified during the assessment process, PYRANA.ai must classify the risks and develop action plans to mitigate discovered risks so that identified issues are managed systematically. | active | contextual | yes | |
| 3d6497afaf0bc0b1… | Early detection and response can mitigate damages and minimize further risk to PYRANA.ai so that prompt incident handling reduces organizational harm. | active | contextual | yes | |
| 39497ba46a96279c… | The security incident response plan must be tested, reviewed, and updated at least annually so that it remains effective and current. | active | contextual | yes | |
| ef20d51a3403fda4… | The incident response plan must be executed after discovery of an incident such as system compromise or unintended or unauthorized acquisition, access, use, or release of non-public information so that security incidents are addressed promptly. | active | contextual | yes | |
| e15d6670b5ce3ad5… | PYRANA.ai maintains a security incident response plan that defines responsibilities, detection, and corrective actions during a security incident so that incident handling is organized and directed. | active | contextual | yes | |
| e19bd29a93592782… | PYRANA.ai uses access control to prevent unauthorized access, deletion, or tampering of logging facilities and log information so that log integrity and availability are preserved. | active | contextual | yes | |
| b310507385714b3b… | Logs are made available to relevant team members for troubleshooting, auditing, and capacity planning activities so that operational and review tasks can be performed effectively. | active | contextual | yes | |
| 5354060c83168c22… | Logs must be securely stored and archived for a minimum of 1 year so that they can support potential forensic efforts. | active | contextual | yes | |
| 46187e8edc60a344… | Logging must be enabled for administrative activities, logon attempts, data deletions, function changes, security configuration changes, permission changes, and role changes at the application and infrastructure levels so that these activities can be monitored. | active | contextual | yes | |
| c5787c29cc4d2374… | The IT team continuously monitors system capacity and performance using monitoring tools so that anomalies that could compromise system availability are identified and detected. | active | contextual | yes | |
| 88bef7b2ddcc39ce… | PYRANA.ai controlled directories or repositories containing source code must be secured from unauthorized access so that source code remains protected. | active | contextual | yes | |
| 7b5cdfb736ead032… | PYRANA.ai maintains requirements and controls for separating development and production environments as necessary so that the two environments remain appropriately segregated. | active | contextual | yes | |
| 1b72b697ca28b570… | Changes to PYRANA.ai production infrastructure, systems, and applications must be documented, tested, and approved before deployment so that only authorized and validated changes reach production. | active | contextual | yes | |
| cffaec97fae6fc75… | The IT leadership team must assess patches monthly and approve implementation so that critical patches are updated on a timely basis. | active | contextual | yes | |
| 0258274cdda842a7… | Agreements will be updated and amended as necessary when business, laws, and regulatory requirements change so that contractual terms remain aligned with changing obligations. | active | contextual | yes | |
| a65cf9ec4bbb211e… | The vendor review may include gathering applicable compliance audits such as SOC 1, SOC 2, PCI DSS, HITRUST, and ISO27001, or other security compliance evidence so that vendor assurance is supported by documented evidence. | active | contextual | yes | |
| ef637fa3cf12b541… | PYRANA.ai requires a vendor security assessment before third-party products or services are used so that the provider can be confirmed to maintain appropriate security and privacy controls. | active | contextual | yes | |
| b0af96e634fb032c… | For risks identified during the risk assessment process, PYRANA.ai must classify the risks and develop action plans to mitigate discovered risks so that identified risks receive treatment planning. | active | contextual | yes | |
| bfe217e8db5e7fdd… | PYRANA.ai requires a risk assessment to be performed at least annually so that organizational risks are regularly evaluated. | active | contextual | yes | |
| c8b20be1af14dee7… | A message should be sent to security@pyrana.ai when someone believes there may be a security incident or threat so that potential incidents are reported to the security contact. | active | contextual | yes | |
| c937f2efaf3168a9… | Early detection and response can mitigate damages and minimize further risk to PYRANA.ai so that prompt incident handling reduces harm. | active | contextual | yes | |
| 24acd4f2d4dc2cf8… | PYRANA.ai uses various monitoring and surveillance tools to detect security threats and incidents so that threats can be identified through technical monitoring. | active | contextual | yes | |
| b31c1bff435031e6… | Incident response procedures must ensure timely detection, effective response, proper handling, communication with affected parties, and documentation of lessons learned so that security incidents are managed comprehensively. | active | contextual | yes | |
| fc65733f59bdcb39… | The security incident response plan is tested, reviewed, and updated at least annually so that it remains current and validated over time. | active | contextual | yes | |
| ed9d5d89748fe655… | The incident response plan is executed after discovery of incidents such as system compromise or unintended or unauthorized acquisition, access, use, or release of non-public information so that defined response actions begin upon incident discovery. | active | contextual | yes | |
| e42c98525ee4c80d… | PYRANA.ai maintains a security incident response plan that defines responsibilities, detection, and corrective actions during a security incident so that incident handling is formally guided. | active | contextual | yes | |
| fdf2c8a12876541b… | PYRANA.ai correlates events and alerts across all sources to identify root causes and formally declare incidents as necessary in accordance with the Security Incident Response Policy and Change Management Policy. | active | contextual | yes | |
| adf16fd19b52e217… | The monitoring tool generates alerts when specific predefined thresholds are met so that threshold-based conditions trigger notification. | active | contextual | yes | |
| d08378d61d0db66a… | PYRANA.ai uses access control to prevent unauthorized access, deletion, or tampering of logging facilities and log information so that log integrity and availability are protected. | active | contextual | yes | |
| 53ddc0848657e653… | System and user activity logs may be used to assess the causes of incidents and problems so that investigations can determine contributing factors. | active | contextual | yes | |
| 5ee9b60c1dae4992… | Logs are made available to relevant team members for troubleshooting, auditing, and capacity planning activities so that operational and review tasks can use logging data. | active | contextual | yes | |
| 6a06688de4119309… | Logs must be securely stored and archived for a minimum of 1 year so that they can assist with potential forensic efforts. | active | contextual | yes | |
| 31f87e90735f5416… | Logging should be enabled at the application and infrastructure level to monitor administrative activities, logon attempts, data deletions, function changes, security configurations, permissions, and roles so that critical activities are observable. | active | contextual | yes | |
| b768e9511c6f4715… | The IT team continuously monitors system capacity and performance through monitoring tools so that anomalies that could compromise system availability are identified and detected. | active | contextual | yes | |
| 3119c8b81ef03254… | PYRANA.ai collects and monitors audit logs and alerts on key events from production systems, applications, databases, servers, message queues, load balancers, critical services, and IAM user and admin activities so that important operational and security events are tracked. | active | contextual | yes | |
| b670dd0ecd0411ef… | PYRANA.ai controlled directories or repositories containing source code are secured from unauthorized access so that source code remains protected. | active | contextual | yes | |