| f2b8623fe9cfb801… | All devices containing sensitive information, including mobile devices, must be configured to automatically lock after a period of inactivity, such as by using a screen saver, so that unattended screens are protected. | active | contextual | yes | |
| 856bb968e91785d0… | Systems containing covered information must enforce session time-outs and lockouts through technical controls so that access is automatically restricted when users are inactive or absent. | active | contextual | yes | |
| 78bec56c3e9431de… | All mobile and desktop devices must be locked when unoccupied so that unattended devices do not expose sensitive or covered information. | active | contextual | yes | |
| 8c439262deb97ded… | PYRANA.ai employees and contractors must remain aware of their surroundings and ensure that no unauthorized individual can see or hear sensitive information so that confidential information is not exposed. | active | contextual | yes | |
| 0d7d8e896e7e0aa9… | PYRANA.ai personnel must secure all sensitive information in hardcopy or electronic form in their work area whenever it is unattended, for both remote and in-office work, so that sensitive information is protected from unauthorized access. | active | contextual | yes | |
| b94f3f08de609156… | PYRANA.ai maintains an Asset Register or Asset Monitoring Tool designed to track assets and set configuration in line with baseline hardening standards so that asset security can be managed consistently. | active | contextual | yes | |
| f956a93e2c586938… | Audits of access and privileges to sensitive PYRANA.ai applications, infrastructure, systems, and data are performed regularly and reviewed by authorized personnel so that access oversight is maintained. | active | contextual | yes | |
| 40a80499ac24d021… | Requests for escalation of privileges or changes to privileges and access permissions must be documented and approved by an authorized manager so that access changes are controlled and auditable. | active | contextual | yes | |
| a88a79c6cc761f69… | PYRANA.ai adheres to the principle of least privilege, meaning team members are given access only to the information and resources necessary to perform their job functions as determined by management or a designee. | active | contextual | yes | |
| ca3d12a5fe66ac77… | To comply with HIPAA, satisfactory assurances from a vendor handling electronic protected health information on behalf of the entity must be documented through a written contract or other arrangement that meets applicable requirements. | active | contextual | yes | |
| ada9887b4c15166a… | No unauthorized personnel should have access to personal data so that personal information remains restricted to approved individuals. | active | contextual | yes | |
| ee02f8397dd331f3… | PYRANA.ai personnel must treat personal data with appropriate security and handling and accommodate data subject requests as required by applicable laws and regulations so that privacy obligations are met. | active | contextual | yes | |
| 630695a5caf8f1bb… | The SOC 2 report of the subservice organization should be reviewed annually so that the effectiveness of the subservice organization's controls can be evaluated. | active | contextual | yes | |
| 5a42bd14895453aa… | Physical security and environmental controls have been implemented by the subservice organization to protect systems inside the server room so that infrastructure is safeguarded at the hosting location. | active | contextual | yes | |
| 040518a2b28edef8… | All production systems should be hosted in a cloud environment or within customer-hosted and customer-managed deployments within Pyrana.ai's support scope so that hosting occurs in environments with appropriate physical security controls managed by a subservice organization. | active | contextual | yes | |
| 44f2843d32accb0e… | While working at home, employees and applicable contractors should be mindful when visitors are present because visitors could become privy to sensitive information displayed on computer screens. | active | contextual | yes | |
| bb37d76c7aba1f0a… | Connecting directly to a public wireless network that does not use at least WPA-2 or an equivalent wireless protocol is prohibited so that remote connections meet minimum wireless security standards. | active | contextual | yes | |
| 96c5dba3b0717b46… | When in a public space, personnel must block sight lines and avoid customer or other confidential conversations so that nearby people cannot observe screens or overhear sensitive discussions. | active | contextual | yes | |
| 30a8e43c67612b89… | Employees and contractors accessing the PYRANA.ai network or other cloud-based networks or tools must use HTTPS or TLS 1.2 or higher at minimum so that data in transit is protected. | active | contextual | yes | |
| bfc05f312d99e481… | Any PYRANA.ai issued device used to access company applications, systems, infrastructure, or data must be used only by its authorized employee or contractor so that device access remains attributable and controlled. | active | contextual | yes | |
| 51f8955b534528b9… | All devices containing sensitive information, including mobile devices, must be configured to automatically lock after a period of inactivity so that unattended screens are protected. | active | contextual | yes | |
| e188b7c683213a5a… | Session time-outs and lockouts are enforced through technical controls for all systems containing covered information so that inactive sessions are automatically protected. | active | contextual | yes | |
| 119e1f191c1a84fc… | PYRANA.ai employees and contractors must remain aware of their surroundings and ensure unauthorized individuals cannot see or hear sensitive information so that visual and auditory exposure is prevented. | active | contextual | yes | |
| ed76139bfedd83fc… | Keys used to access sensitive information must not be left at an unattended desk so that unauthorized persons cannot use them to reach protected information. | active | contextual | yes | |
| 4d48be761d2b9096… | PYRANA.ai personnel must remove hardcopies of sensitive information from desks and lock them in a drawer when desks are unoccupied and at the end of the work day so that physical sensitive records remain protected. | active | contextual | yes | |
| b2be5e72f271a7c0… | PYRANA.ai personnel must secure all sensitive information in hardcopy or electronic form in unattended work areas during both remote and in-office work so that sensitive information is protected from unauthorized access. | active | contextual | yes | |
| 0276728c1afe63db… | PYRANA.ai maintains an Asset Register or Asset Monitoring Tool to track assets and set configuration according to baseline hardening standards so that asset inventory and configuration management align with security baselines. | active | contextual | yes | |
| e5d9c6972939ad27… | Audits of access and privileges for sensitive PYRANA.ai applications, infrastructure, systems, and data are performed regularly and reviewed by authorized personnel so that access rights receive ongoing oversight. | active | contextual | yes | |
| eaf8e3a09d5d0c4a… | System access is revoked immediately upon termination or resignation so that former personnel cannot retain access after their relationship with PYRANA.ai ends. | active | contextual | yes | |
| e6456fd6bc2bf228… | Requests to escalate privileges or change privileges and access permissions must be documented and approved by an authorized manager so that access changes are controlled and auditable. | active | contextual | yes | |
| 465f361f7f7c4676… | PYRANA.ai follows the principle of least privilege by granting team members access only to the information and resources necessary for their job functions as determined by management or a designee so that access remains limited to business need. | active | contextual | yes | |
| 846c23a902ccc650… | To comply with HIPAA, satisfactory assurances from a vendor acting as a business associate for electronic protected health information must be documented in a written contract or other arrangement that meets applicable requirements. | active | contextual | yes | |
| 8baa00c667f1d155… | No unauthorized personnel should have access to personal data so that personal information remains restricted to approved individuals only. | active | contextual | yes | |
| 80c9ac0437fc1eee… | PYRANA.ai personnel must handle personal data with appropriate security and processing practices and must accommodate data subject requests as required by applicable laws and regulations so that privacy obligations are met. | active | contextual | yes | |
| c3498547d0a4cc98… | The SOC 2 report of the subservice organization should be reviewed annually to evaluate the effectiveness of that organization's controls so that PYRANA.ai can assess outsourced control performance on a recurring basis. | active | contextual | yes | |
| 9edabc3f4aa303fc… | Physical security and environmental controls have been implemented by the subservice organization to protect systems inside the server room so that server-room systems are safeguarded against physical and environmental threats. | active | contextual | yes | |
| a9fb9d74934af051… | The hosting environment for production systems is equipped with appropriate physical security controls and that responsibility belongs to the subservice organization so that physical protection duties are assigned to the hosting provider. | active | contextual | yes | |
| 2926097ef70de98d… | All production systems should be hosted either in a cloud environment or in customer-hosted and customer-managed deployments within Pyrana.ai's support scope so that hosting occurs in environments covered by defined responsibility and security controls. | active | contextual | yes | |
| 14296492359ece2a… | While working at home, employees and applicable contractors should be mindful when visitors are present because visitors such as maintenance personnel could see sensitive information left displayed on computer screens. | active | contextual | yes | |
| 50a040013ba36482… | Connecting directly to a public wireless network that does not use at least WPA-2 or an equivalent wireless protocol is prohibited so that wireless communications meet a minimum security standard. | active | contextual | yes | |
| d5d4d56136930c28… | When working in a public space, personnel must block sight lines and avoid customer or other confidential conversations so that nearby people cannot observe screens or overhear sensitive discussions. | active | contextual | yes | |
| ff5d2bef8e561b11… | Employees or contractors accessing the PYRANA.ai network or other cloud-based networks or tools are required to use HTTPS or TLS 1.2 or higher at minimum so that data in transit is protected. | active | contextual | yes | |
| a31accdeb0f9522a… | Any PYRANA.ai issued device used to access company applications, systems, infrastructure, or data may be used only by the employee or contractor authorized for that device so that device access remains attributable and controlled. | active | contextual | yes | |
| 6007a884d80f62fe… | All devices containing sensitive information, including mobile devices, must be configured to lock automatically after a period of inactivity such as through a screen saver so that unattended devices become protected without manual action. | active | contextual | yes | |
| 76d1a99e7f00223f… | Session time-outs and lockouts are enforced through technical controls for all systems containing covered information so that access protection does not rely solely on user behavior. | active | contextual | yes | |
| 3fb67aa82296f491… | All mobile and desktop devices must be locked when unoccupied so that unattended systems do not expose sensitive information or permit unauthorized access. | active | contextual | yes | |
| cef343ee0b01145b… | PYRANA.ai employees and contractors must remain aware of their surroundings and ensure that no unauthorized individual can see or hear sensitive information so that confidential information is not exposed through observation or overhearing. | active | contextual | yes | |
| c68e79b7ca4e4b8a… | Keys used to access sensitive information must not be left at an unattended desk so that unauthorized persons cannot use them to reach protected materials. | active | contextual | yes | |
| 5ada01871ddba64f… | PYRANA.ai personnel must remove hardcopies of sensitive information from desks and lock them in a drawer when desks are unoccupied and at the end of the work day so that physical records are protected from unauthorized access. | active | contextual | yes | |
| 08024b0c7a5bea2a… | PYRANA.ai personnel are required to keep all sensitive information in hardcopy or electronic form secure in their work area whenever it is unattended so that sensitive data remains protected in both remote and in-office environments. | active | contextual | yes | |