| bec351bbb3976b88… | Production servers must be scanned on an ongoing basis to test patch compliance so that implemented systems remain aligned with patching requirements. | active | contextual | yes | |
| ab48e1689505a321… | A patch management process exists to confirm that operating system level vulnerabilities are remediated in a timely manner so that OS security issues do not remain unresolved. | active | contextual | yes | |
| 1ac810de976dda75… | Resolution of critical and high vulnerabilities follows the incident response plan so that remediation activities are governed by established response procedures. | active | contextual | yes | |
| 9b44d12971aee6bc… | A remediation plan is developed and changes are implemented to remediate at minimum critical and high vulnerabilities so that severe weaknesses are addressed through planned corrective action. | active | contextual | yes | |
| 9b8396f36995dffa… | The IT and Engineering department review vulnerabilities and take necessary actions on those identified as high and critical so that the most severe issues receive active response. | active | contextual | yes | |
| e4516f026fd0e143… | Vulnerability management must include systematic identification, assessment, and remediation of security vulnerabilities, with prioritization based on risk level and potential information security impact. | active | contextual | yes | |
| ab03ebe6a0f02034… | Vulnerability scans are performed monthly, with scan frequency adjusted as required to meet ongoing and changing commitments and requirements so that assessment cadence remains aligned with obligations. | active | contextual | yes | |
| fe91030a93e5f621… | PYRANA.ai uses an automated tool to perform vulnerability assessments on infrastructure and applications so that security weaknesses are identified through systematic scanning. | active | contextual | yes | |
| 45d011cf293f2a26… | Patch classification may consider whether severity is security-related or based on other additional factors so that patch prioritization reflects more than a single criterion. | active | contextual | yes | |
| 0167050f3b9366fe… | PYRANA.ai uses a proactive vulnerability and patch management process that prioritizes and implements patches based on classification so that remediation effort aligns with issue categorization. | active | contextual | yes | |
| 1b85e1ffffbe094e… | For production servers, anti-virus definitions should be updated weekly so that malware detection remains current against newly identified threats. | active | contextual | yes | |
| 2ed33afdb85d97a6… | Anti-virus on production servers should be configured to scan automatically on a continuous basis so that malicious software can be detected without manual initiation. | active | contextual | yes | |
| dfdca0ca25ddaf6e… | Anti-virus and malware protection software must be installed and configured on all production servers to prevent, detect, and respond to unauthorized or malicious software introduction. | active | contextual | yes | |
| 58fbf34245766530… | PYRANA.ai defines data handling and classification requirements in its Data Classification Policy so that data categories and handling expectations are formally documented. | active | contextual | yes | |
| 35b5a240024f53e7… | Encryption technologies are used to protect communication and data transmission over public networks so that information in transit is safeguarded against exposure. | active | contextual | yes | |
| 2a0249c3128f7321… | Access to production environment access keys is restricted to authorized individuals so that sensitive credentials for production systems are protected from unauthorized use. | active | contextual | yes | |
| 176812506a080e2e… | PYRANA.ai uses its cloud provider’s key management service to encrypt data at rest and to store and manage encryption keys so that encryption operations and key custody are centrally controlled. | active | contextual | yes | |
| 29a8c97155867484… | Upon contract termination or customer request, customer data must be returned or securely deleted within 90 days, and confirmation of deletion must be maintained so that post-contract data disposition is verifiable. | active | contextual | yes | |
| a1e53ec9ded446e6… | Customer data must not be stored, processed, or transferred outside approved jurisdictions such as the United States without customer approval and appropriate safeguards so that cross-border handling remains authorized and protected. | active | contextual | yes | |
| 599e8f13c678f6e3… | PYRANA.ai defines data handling and classification requirements in its Data Classification Policy so that classification rules are governed by a dedicated policy document. | active | contextual | yes | |
| 3989a3550db25964… | Encryption technologies are used to protect communications and data transmissions over public networks so that data in transit is secured against exposure. | active | contextual | yes | |
| ae108c2df085f72d… | Access to production environment access keys is restricted to authorized individuals so that only approved personnel can use sensitive production credentials. | active | contextual | yes | |
| d44106f848638ba1… | PYRANA.ai uses its cloud provider's key management service to encrypt data at rest and to store and manage encryption keys so that encryption operations and key custody are centrally managed. | active | contextual | yes | |
| bf10e2244b8913d7… | When contracts terminate or a customer requests it, customer data must be returned or securely deleted within 90 days, and confirmation of deletion must be maintained so that post-termination data handling is documented. | active | contextual | yes | |
| f0f0e93b0b1a9a54… | Customer data must not be stored, processed, or transferred outside approved jurisdictions such as the United States unless customer approval and appropriate safeguards are in place so that jurisdictional restrictions are maintained. | active | contextual | yes | |
| 436097b1d84c1b0b… | PYRANA.ai must store and dispose of sensitive data in a manner that safeguards confidentiality, protects against unauthorized use or disclosure, and renders the data secure or appropriately destroyed so that sensitive information remains protected through its lifecycle. | active | contextual | yes | |
| 6ca9c639e07cdf13… | Training for employees responsible for disposing of electronic media must include best practices for secure removal so that disposal activities comply with the stated standards and documentation requirements. | active | contextual | yes | |
| 9b918d1382613325… | Documentation must be maintained as evidence of proper removal of electronic Protected Health Information, including a signed form from responsible employees confirming that ePHI was appropriately erased so that media disposal is auditable. | active | contextual | yes | |
| d994104813b63d10… | Removal of any device or media from the inventory list during the in-scope period must trigger a verification process so that asset removals are checked for proper handling. | active | contextual | yes | |
| 783421bc1096a30a… | Workstations should be configured for automatic patch updates and must be scanned daily to test patch compliance so that patch status is continuously maintained and verified. | active | contextual | yes | |
| 6394a7bb20850946… | Windows-based workstations and laptops should have anti-virus and malware protection software installed and configured, and the anti-virus must update automatically every day so that endpoint protection remains current. | active | contextual | yes | |
| 0c5cc2529f59ec28… | Use of removable media should be restricted, and when it is required to transfer restricted data outside the company or to authorized users, appropriate approval must be obtained so that external data transfers are controlled. | active | contextual | yes | |
| e01a44f3f4967368… | Disk encryption and system passwords should be enabled on all organizational workstations so that workstation data and access are protected. | active | contextual | yes | |
| c169d3c45e5d17f4… | The company must maintain an asset inventory that includes ownership and location details, and management must review and update the listing as needed or at least annually so that asset records remain current. | active | contextual | yes | |
| 09c3b39f668791b9… | PYRANA.ai performs regular audits of access and privileges for sensitive applications, infrastructure, systems, and data, and authorized personnel review those audits so that sensitive access remains monitored. | active | contextual | yes | |
| b3b8a5586b0a23aa… | System access must be revoked immediately when an employee is terminated or resigns so that former personnel no longer retain access to PYRANA.ai systems. | active | contextual | yes | |
| 4688a70ae6b6c3a6… | Requests to escalate privileges or change access permissions must be documented and approved by an authorized manager before access changes are granted so that privilege modifications are controlled and traceable. | active | contextual | yes | |
| 591e5b057d983907… | PYRANA.ai requires access for team members to be limited to only the information and resources necessary for their job functions as determined by management or a designee so that system access follows the principle of least privilege. | active | contextual | yes | |
| dd3a58a9fe0ac035… | PYRANA.ai defines how data is handled and classified in its Data Classification Policy so that classification rules are formally documented in a dedicated policy. | active | contextual | yes | |
| f983f6a9883754e5… | The organization uses DLP, meaning Data Loss Prevention, software to prevent sensitive information from being transmitted over email so that email channels do not leak protected data. | active | contextual | yes | |
| 614b81d412037a25… | Encryption technologies are used to protect communication and data transmission over public networks so that information remains protected while in transit. | active | contextual | yes | |
| 0afb4eed77b09979… | Access to production environment access keys is restricted to authorized individuals so that sensitive credentials for production systems are limited to approved personnel. | active | contextual | yes | |
| 1a15f015c60f20d8… | PYRANA.ai uses its cloud provider's key management service to encrypt data at rest and to store and manage encryption keys so that encryption operations and key custody are centrally controlled. | active | contextual | yes | |
| 5094a0edc47edadb… | When contracts terminate or a customer requests it, customer data must be returned or securely deleted within 90 days, and confirmation of deletion must be maintained so that post-contract data handling is documented. | active | contextual | yes | |
| 490fede73290bfcf… | Customer data must not be stored, processed, or transferred outside approved jurisdictions such as the US without customer approval and appropriate safeguards so that jurisdictional controls are maintained. | active | contextual | yes | |
| 1f615a99ebd09420… | PYRANA.ai stores and disposes of sensitive data in a manner that reasonably safeguards confidentiality, protects against unauthorized use or disclosure, and renders the data secure or appropriately destroyed so that sensitive information remains protected throughout its lifecycle. | active | contextual | yes | |
| fae0ff17f9afced2… | Employees responsible for disposing of electronic media must receive training on best practices for secure removal so that disposal complies with the stated standards and documentation requirements. | active | contextual | yes | |
| 3ba800476aa716c4… | Documentation must provide evidence of proper removal of electronic Protected Health Information, including a signed form from responsible employees confirming that ePHI was appropriately erased so that disposal actions are auditable. | active | contextual | yes | |
| 57976b8a473f2c66… | Removal of devices or media from the inventory list during the in-scope period triggers a verification process so that asset removals are checked for proper handling. | active | contextual | yes | |
| 252aacfee97f0401… | The company should use a third party to sanitize digital media and remove data and software before disposal or degaussing so that disposed media no longer contains recoverable information. | active | contextual | yes | |