| 9309685841573525… | Workstations should be configured for automatic patch updates and must be scanned daily to test patch compliance so that security updates are applied and verified regularly. | active | contextual | yes | |
| 54109297c8fa874d… | Windows-based workstations and laptops should have anti-virus and malware protection software installed and configured, and the anti-virus should update automatically every day so that endpoint protection remains current. | active | contextual | yes | |
| 720f4b4e69437dd4… | Use of removable media should be restricted, and when removable media is needed to transfer restricted data outside the company or to authorized users, appropriate approval is required so that sensitive transfers are controlled. | active | contextual | yes | |
| f734aae2854594c4… | Disk encryption and system passwords should be enabled on all organization workstations so that workstation data and access are protected. | active | contextual | yes | |
| 9e8c701b5ed3f449… | The company must maintain an inventory of assets that includes asset ownership and location details, and management must review and update the inventory as needed or at least annually so that asset records remain current. | active | contextual | yes | |
| a4b1f3aa62a2d816… | PYRANA.ai maintains an Asset Register or Asset Monitoring Tool to track assets and set configurations in line with baseline hardening standards so that asset security controls are managed consistently. | active | contextual | yes | |
| 764c3ae57c640b2c… | Audits of access and privileges for sensitive PYRANA.ai applications, infrastructure, systems, and data are performed regularly and reviewed by authorized personnel so that privileged access remains monitored. | active | contextual | yes | |
| 7a1b7b0087c0c48b… | System access must be revoked immediately when an employee is terminated or resigns so that former personnel no longer retain access to organizational systems. | active | contextual | yes | |
| bca71d8857abf320… | Requests to escalate privileges or change privileges and access permissions must be documented and approved by an authorized manager so that access changes are controlled and traceable. | active | contextual | yes | |
| fa75e120876ab296… | Any arrangement in which a business associate handles information on behalf of the entity must be documented through a written contract or other arrangement that meets applicable requirements so that the relationship is formally governed. | active | contextual | yes | |
| 10d8dca51d2e1e30… | PYRANA.ai defines data handling and classification requirements in its Data Classification Policy so that classification rules are formally documented in a dedicated policy. | active | contextual | yes | |
| f61c7eebdcb404d2… | The organization uses data loss prevention software to prevent sensitive information from being transmitted over email so that email channels do not leak protected data. | active | contextual | yes | |
| 3cf46c81215dfd7b… | Encryption technologies are used to protect communication and data transmission over public networks so that data in transit is secured. | active | contextual | yes | |
| 85b2cd066f21742a… | Access to production environment access keys is restricted to authorized individuals so that sensitive credentials are limited to approved personnel. | active | contextual | yes | |
| 0d2efded488bda07… | PYRANA.ai uses its cloud provider key management service to encrypt data at rest and to store and manage encryption keys so that encryption operations and key custody are handled through the provider service. | active | contextual | yes | |
| 0f37df1df4919c5c… | Upon contract termination or customer request, customer data is returned or securely deleted within 90 days and confirmation of deletion is maintained so that post-contract data handling is documented and timely. | active | contextual | yes | |
| c6b1603897e44676… | Customer data must not be stored, processed, or transferred outside approved jurisdictions such as the US without customer approval and appropriate safeguards so that jurisdictional restrictions are maintained. | active | contextual | yes | |
| ee404c4f2ed6da2c… | Data entered into PYRANA.ai applications must be validated where possible so that information quality is ensured and the impacts of web-based attacks on systems are mitigated. | active | contextual | yes | |
| 6c8a412fffbc5fcb… | PYRANA.ai stores and disposes of sensitive data in a manner that reasonably safeguards confidentiality, protects against unauthorized use or disclosure, and renders the data secure or appropriately destroyed so that sensitive information remains protected through its lifecycle. | active | contextual | yes | |
| afb566d35e202d4c… | Training for employees responsible for disposing of electronic media includes best practices for secure removal so that disposal activities comply with the stated standards and documentation requirements. | active | contextual | yes | |
| 55a3d6ee4c16f5a6… | Evidence of ePHI removal must include a signed form from the employees responsible for the removal confirming that ePHI was appropriately erased so that disposal actions are attested by accountable personnel. | active | contextual | yes | |
| bc1654d1710fc0ca… | Documentation is required as evidence of proper removal of electronic protected health information when devices or media are removed so that ePHI disposal can be demonstrated. | active | contextual | yes | |
| 5fe0f3139802bfbf… | Removal of devices or media from the inventory list during the in-scope period triggers a verification process so that asset removals are formally checked. | active | contextual | yes | |
| 89c4dadcd3436913… | The company should engage a third party to sanitize digital media and remove data and software before disposal or degaussing so that disposed media no longer contains recoverable information. | active | contextual | yes | |
| eef7aa83d034a8ea… | Workstations must be scanned daily to test patch compliance so that the organization can verify patching status each day. | active | contextual | yes | |
| 09a4ccf953b3deeb… | Workstations should be configured to receive automatic patch updates so that security fixes are applied without manual intervention. | active | contextual | yes | |
| ca907bb35dbae5d1… | Anti-virus software should be configured to update automatically on a daily basis so that malware protection remains current. | active | contextual | yes | |
| c66d70dcefb89944… | Anti-virus and malware protection software should be installed and configured on Windows-based workstations and laptops so that those endpoints are protected against malicious software. | active | contextual | yes | |
| bef3f255bc3211f2… | Use of removable media should be restricted, and when removable media is required to transfer restricted data outside the company or to authorized users, appropriate approval should be required so that data transfers remain controlled. | active | contextual | yes | |
| 6d1ded745d48ba92… | Disk encryption and system passwords should be enabled across all organization workstations so that workstation data and access are protected. | active | contextual | yes | |
| c4974cddaa6b031f… | Management reviews and updates the asset inventory on an as-needed basis or at least annually so that asset records remain current. | active | contextual | yes | |
| bbe2b5758108f02d… | The company maintains an inventory of assets that includes asset ownership and location details so that organizational assets can be identified and managed. | active | contextual | yes | |
| 4917375db5d7784d… | PYRANA.ai maintains an Asset Register or Asset Monitoring Tool to track assets and set configurations in line with baseline hardening standards so that asset security controls can be managed consistently. | active | contextual | yes | |
| 9e0bcef611812e39… | Audits of access and privileges for sensitive PYRANA.ai applications, infrastructure, systems, and data are performed regularly and reviewed by authorized personnel so that sensitive access remains under oversight. | active | contextual | yes | |
| b1d8644bf4a6b499… | System access is revoked immediately when an employee is terminated or resigns so that former personnel no longer retain access to organizational systems. | active | contextual | yes | |
| 8802c452fb06c0b2… | Requests to escalate privileges or change privileges and access permissions must be documented and approved by an authorized manager so that access changes are formally controlled. | active | contextual | yes | |
| 65e7f9d93dbb8483… | PYRANA.ai follows the principle of least privilege by granting team members only the information and resources necessary for their job functions as determined by management or a designee so that access remains limited to business need. | active | contextual | yes | |
| 7c7b7c9eb3779a6e… | Access to information handled on behalf of an entity must be documented through a written contract or other arrangement with the business associate when applicable requirements apply so that the relationship meets required compliance obligations. | active | contextual | yes | |
| 9f6d7c8bb5a059e2… | PYRANA.ai maintains an Asset Register or Asset Monitoring Tool to track assets and set configurations in accordance with baseline hardening standards so that asset security and configuration management are supported. | active | contextual | yes | |
| 3067027ca6f50254… | Access and privilege audits for sensitive PYRANA.ai applications, infrastructure, systems, and data are performed regularly and reviewed by authorized personnel so that sensitive access rights receive ongoing oversight. | active | contextual | yes | |
| a4ce6ceec61e45bb… | System access must be revoked immediately when an employee or contractor is terminated or resigns so that former personnel cannot retain access after separation. | active | contextual | yes | |
| 7bb5836d183cfb3a… | Requests to escalate privileges or change privileges and access permissions must be documented and approved by an authorized manager so that access changes are formally controlled and authorized. | active | contextual | yes | |
| 15c81f134cfcb4c3… | To comply with HIPAA, satisfactory assurances from a vendor that creates, receives, maintains, or transmits electronic protected health information on behalf of the entity must be documented in a written contract or other arrangement meeting applicable requirements. | active | contextual | yes | |
| e6d428b2f632a2e0… | The SOC 2 report of the subservice organization should be reviewed annually to evaluate the effectiveness of the controls at that subservice organization so that third-party control assurance is periodically assessed. | active | contextual | yes | |
| 85174a32aa84300d… | The subservice organization has implemented physical security and environmental controls to protect systems inside the server room so that server-room systems are safeguarded against physical and environmental threats. | active | contextual | yes | |
| 18dcbd55ded91f49… | The hosting environment for production systems is equipped with appropriate physical security controls, and responsibility for those controls belongs to the subservice organization, so that physical protection is managed by the hosting provider. | active | contextual | yes | |
| db54deaf8402fcd2… | Production systems should be hosted either in a cloud environment or in customer-hosted and customer-managed deployments within Pyrana.ai's support scope so that hosting occurs in environments with defined responsibility and security controls. | active | contextual | yes | |
| 0abc6800afcab562… | While working at home, employees and applicable contractors should be mindful when visitors are present because visitors such as maintenance personnel could see sensitive information left visible on computer screens. | active | contextual | yes | |
| fe617e05b6582786… | Employees or contractors accessing the PYRANA.ai network or other cloud-based networks or tools must use HTTPS or TLS 1.2 or higher at minimum so that data in transit is protected. | active | contextual | yes | |
| 04683ed06ee4fcc7… | Any PYRANA.ai-issued device used to access company applications, systems, infrastructure, or data may be used only by the authorized employee or contractor assigned to that device so that device access remains controlled. | active | contextual | yes | |