| ab7f819afbbb6bd7… | PYRANA.ai maintains requirements and controls for separating development and production environments as necessary so that the two environments remain distinct when needed. | active | contextual | yes | |
| ba1338075e8be28a… | PYRANA.ai maintains a Change Management Policy with procedures covering change types, documentation, reviews or approvals, and emergency changes so that unauthorized changes and malicious code introduction are prevented. | active | contextual | yes | |
| 2a752b8f9a1f79e0… | The IT leadership team makes monthly patch assessments and approves implementation so that critical patches are updated on a timely basis. | active | contextual | yes | |
| 1c05aa9b5203adb3… | Production servers must be scanned on an ongoing basis to test patch compliance so that patch status is continuously verified in the production environment. | active | contextual | yes | |
| 24a7ece459e65606… | PYRANA.ai controlled directories or repositories containing source code are secured from unauthorized access so that source code remains protected against unapproved exposure or modification. | active | contextual | yes | |
| 3be921285e686176… | Changes to PYRANA.ai production infrastructure, systems, and applications must be documented, tested, and approved before deployment so that only reviewed and validated changes reach production. | active | contextual | yes | |
| 094957c21673f80e… | To protect against unauthorized changes and malicious code introduction, PYRANA.ai maintains a Change Management Policy with procedures covering change types, required documentation, required reviews or approvals, and emergency changes. | active | contextual | yes | |
| 18b230eff5251e16… | The IT leadership team performs monthly patch assessments and approves patches for implementation so that critical patches are updated in a timely manner. | active | contextual | yes | |
| 2eb2080a3de8cf85… | Production servers must be scanned on an ongoing basis to test patch compliance so that the organization can verify whether required patches have been applied. | active | contextual | yes | |
| 0cf21b13ad3d2bb1… | A patch management process exists to ensure operating system level vulnerabilities are remediated in a timely manner so that system-level security weaknesses do not remain unaddressed. | active | contextual | yes | |
| d03d5300f812d202… | Resolution of critical and high vulnerabilities follows the incident response plan so that vulnerability handling is executed according to the organization's established response process. | active | contextual | yes | |
| 81dc23dcf707994d… | A remediation plan is developed and changes are implemented to remediate at least critical and high vulnerabilities so that severe weaknesses are formally addressed through planned corrective action. | active | contextual | yes | |
| c17d79652ae64377… | The IT and Engineering department review identified vulnerabilities and take necessary actions on those classified as high and critical so that the most severe issues receive active response. | active | contextual | yes | |
| 7dd86cfb58ec7387… | Vulnerability management must include systematic identification, assessment, and remediation of security vulnerabilities, prioritized by risk level and potential information security impact so that remediation effort targets the most significant threats first. | active | contextual | yes | |
| 7c31e53367600cf8… | PYRANA.ai uses an automated tool to perform vulnerability assessments on infrastructure and applications so that vulnerability identification is conducted systematically across technical environments. | active | contextual | yes | |
| b9cd53a8f2d169f8… | PYRANA.ai uses a proactive vulnerability and patch management process that prioritizes and implements patches based on classification, including whether severity is security-related or influenced by other factors. | active | contextual | yes | |
| d6789b6fd8880558… | Anti-virus on production servers should be configured to scan automatically on a continuous basis so that malicious software can be detected without relying on manual initiation. | active | contextual | yes | |
| 2f090388032a78aa… | Anti-virus and anti-malware protection software must be installed and configured on all production servers to prevent, detect, and respond to unauthorized or malicious software introduction. | active | contextual | yes | |
| d17280b21db41643… | PYRANA.ai defines how data must be handled and classified in its Data Classification Policy so that data treatment requirements are formally established in a dedicated policy document. | active | contextual | yes | |
| c53d2af4f3fe983d… | Access to production environment access keys is restricted to authorized individuals so that only approved personnel can use sensitive credentials in the production environment. | active | contextual | yes | |
| 3c8f4ec858d099ae… | PYRANA.ai uses its cloud provider's key management service to encrypt data at rest and to store and manage encryption keys so that protected data and key custody are centrally controlled. | active | contextual | yes | |
| 143f57f874112418… | Upon contract termination or a customer request, customer data must be returned or securely deleted within 90 days, and confirmation of deletion must be retained so that data disposition is completed and evidenced. | active | contextual | yes | |
| 53f1f0e3d1ee2b1e… | Customer data must not be stored, processed, or transferred outside approved jurisdictions such as the United States unless the customer has approved the action and appropriate safeguards are in place so that jurisdictional and contractual data protection requirements are maintained. | active | contextual | yes | |
| 7d60e201d5ee3594… | PYRANA.ai controlled directories or repositories containing source code are secured from unauthorized access so that source code remains protected against unapproved use or exposure. | active | contextual | yes | |
| 154279593eb08aa2… | As necessary, PYRANA.ai maintains requirements and controls for separating development and production environments so that the two environments remain distinct when needed. | active | contextual | yes | |
| 468b4cf82d045bc2… | PYRANA.ai maintains a Change Management Policy with procedures covering change types, required documentation, required review or approvals, and emergency changes so that unauthorized changes and malicious code introduction are prevented. | active | contextual | yes | |
| 3115f670d185d072… | Production servers must be scanned on an ongoing basis to test patch compliance so that the organization can verify whether required patches remain applied. | active | contextual | yes | |
| 1d00c787f5b098b4… | A patch management process exists to confirm that operating system level vulnerabilities are remediated in a timely manner so that system-level security weaknesses are not left unresolved. | active | contextual | yes | |
| 5964bbd7448f248e… | Resolution of critical and high vulnerabilities follows the incident response plan so that remediation activities are governed by the organization’s established response process. | active | contextual | yes | |
| d6205d205d0a8de7… | A remediation plan is developed and changes are implemented to remediate at least critical and high vulnerabilities so that serious weaknesses are formally addressed through planned corrective action. | active | contextual | yes | |
| cfff2cb50f2663d1… | The IT and Engineering department review vulnerabilities and take necessary actions on those identified as high and critical so that severe security issues receive active response. | active | contextual | yes | |
| 317a31f4cb391fb4… | Vulnerability management must include systematic identification, assessment, and remediation of security vulnerabilities, prioritized by risk level and potential impact to information security so that the most consequential issues are addressed first. | active | contextual | yes | |
| a9f34a6431a0fa18… | Vulnerability scans are performed monthly, with frequency adjusted as required to meet ongoing and changing commitments and requirements so that scanning remains aligned with current obligations. | active | contextual | yes | |
| 009c833eac2efc73… | PYRANA.ai uses an automated tool to perform vulnerability assessments on infrastructure and applications so that technical environments are regularly evaluated for security weaknesses. | active | contextual | yes | |
| 53621baa2a412552… | Patch classification may consider whether severity is security-related or based on additional factors so that patch prioritization reflects more than a single criterion. | active | contextual | yes | |
| 45dc3f2e4c22943c… | PYRANA.ai uses a proactive vulnerability and patch management process that prioritizes and implements patches based on classification so that remediation is aligned to severity and other relevant factors. | active | contextual | yes | |
| 555fb3a32559aad9… | Anti-virus software on production servers should be configured to scan automatically on a continuous basis so that malicious software activity is checked without interruption. | active | contextual | yes | |
| e84058524e38e4da… | Anti-virus and malware protection software must be installed and configured on all production servers so that unauthorized or malicious software can be prevented, detected, and acted upon. | active | contextual | yes | |
| b4004f81334fcaba… | PYRANA.ai defines the handling and classification of data in its Data Classification Policy so that data treatment rules are established in a dedicated governing document. | active | contextual | yes | |
| f36d537b9aa2ae23… | The organization uses DLP, which stands for Data Loss Prevention, software to prevent sensitive information from being transmitted over email so that email channels do not leak protected data. | active | contextual | yes | |
| ae1cf6c907398b81… | Encryption technologies are used to protect communication and data transmission over public networks so that information remains protected while traversing external network paths. | active | contextual | yes | |
| 0cfe7159b18c7027… | Access to production environment access keys is restricted to authorized individuals so that only approved personnel can use sensitive credentials in production systems. | active | contextual | yes | |
| 43ade79034691e41… | PYRANA.ai uses its cloud provider’s key management service to encrypt data at rest and to store and manage encryption keys so that protected data and key custody are centrally controlled. | active | contextual | yes | |
| 7e1c03ea83f1d985… | Upon contract termination or a customer request, customer data must be returned or securely deleted within 90 days, and confirmation of deletion must be maintained so that data disposition is completed and evidenced. | active | contextual | yes | |
| 8754fdc2023314c6… | Customer data must not be stored, processed, or transferred outside approved jurisdictions such as the United States unless the customer has approved the action and appropriate safeguards are in place so that jurisdictional and data protection requirements are maintained. | active | contextual | yes | |
| bf1042a95d81c7b5… | PYRANA.ai controlled directories or repositories containing source code are secured from unauthorized access so that code assets are protected against improper exposure or modification. | active | contextual | yes | |
| 42a596ba2e6425de… | As necessary, PYRANA.ai maintains requirements and controls for separating development and production environments so that operational and non-production activities remain isolated when needed. | active | contextual | yes | |
| 56ec4c630d02d178… | Changes to PYRANA.ai production infrastructure, systems, and applications must be documented, tested, and approved before deployment so that production changes are controlled prior to release. | active | contextual | yes | |
| 96eba1d149daea3d… | To protect against unauthorized changes and malicious code introduction, PYRANA.ai maintains a Change Management Policy with procedures covering change types, documentation, reviews or approvals, and emergency changes. | active | contextual | yes | |
| 9d637f66668728f1… | The IT leadership team makes monthly patch assessments and approves implementation so that critical patches are updated in a timely manner. | active | contextual | yes | |