| a92d851d84c7a169… | All devices containing sensitive information, including mobile devices, must be configured to automatically lock after a period of inactivity such as a screen saver so that idle devices are secured without manual action. | active | contextual | yes | |
| b1e6db31b3cb1d1d… | Technical controls must enforce session time-outs and lockouts for all systems containing covered information so that unattended or idle sessions are automatically protected. | active | contextual | yes | |
| 0115e441816d48d4… | All mobile and desktop devices must be locked when unoccupied so that unattended systems do not expose sensitive information or access. | active | contextual | yes | |
| 8d69217c17da6d99… | Employees and contractors must remain aware of their surroundings and ensure unauthorized individuals cannot see or hear sensitive information so that information is not exposed through observation or overhearing. | active | contextual | yes | |
| d6df30b51cfd6f64… | Keys used to access sensitive information must not be left at an unattended desk so that physical access controls are not compromised. | active | contextual | yes | |
| 7bf48dfa5b6290da… | When desks are unoccupied and at the end of the work day, personnel must remove hardcopies of sensitive information from desks and lock them in a drawer so that physical documents are protected from unauthorized access. | active | contextual | yes | |
| ebc264a82a330ce1… | PYRANA.ai personnel must secure all sensitive hardcopy and electronic information in their work area whenever it is unattended, whether working remotely or in the office, so that exposed information is protected. | active | contextual | yes | |
| 6abced4b76729d95… | Security awareness and training must include general security awareness, role-specific security requirements, and ongoing education about emerging threats so that personnel remain informed of relevant security responsibilities and risks. | active | contextual | yes | |
| d29ec67adeb54e47… | An authorized PYRANA.ai member must review each background check in accordance with local laws so that screening is legally compliant and formally assessed. | active | contextual | yes | |
| 2de91aba0479ba72… | Records of all policy and procedure changes must be kept and reviewed by the Board so that an auditable history of governance changes is maintained. | active | contextual | yes | |
| 90067971b2a18be0… | Changes to security, privacy, and confidentiality policies require prior approval from the appropriate level of management so that policy modifications are formally controlled. | active | contextual | yes | |
| 10d9d3ff0b193288… | All personnel must read, accept, and follow all PYRANA.ai policies and plans upon starting and at least annually so that policy awareness and compliance are maintained. | active | contextual | yes | |
| 9781a056b85fc935… | The policy applies to all PYRANA.ai assets used by personnel acting on behalf of PYRANA.ai or accessing its applications, infrastructure, systems, or data so that all relevant organizational resources are covered. | active | contextual | yes | |
| f9f3884217074786… | This policy is guided by PYRANA.ai-specific security requirements, including compliance with applicable laws and regulations, so that the security program aligns with legal and organizational obligations. | active | contextual | yes | |
| cd2bcfbe2ba073a5… | The topics and requirements in the policy must be continuously improved so that PYRANA.ai maintains a secure information security posture over time. | active | contextual | yes | |
| 3667e29833e4efe5… | All devices containing sensitive information, including mobile devices, must be configured to automatically lock after a period of inactivity such as a screen saver so that unattended devices are protected. | active | contextual | yes | |
| 39d02df27400f7f1… | Session time-outs and lockouts must be enforced through technical controls on all systems containing covered information so that inactive or unattended sessions are automatically restricted. | active | contextual | yes | |
| 6edddb4fb411d71e… | All mobile and desktop devices must be locked when unoccupied so that unattended systems do not expose sensitive information or system access. | active | contextual | yes | |
| 94919fd1c903364b… | Employees and contractors must remain aware of their surroundings and ensure unauthorized individuals cannot see or hear sensitive information so that visual and auditory exposure is prevented. | active | contextual | yes | |
| f6cb3d7283e3abae… | Keys used to access sensitive information must not be left at an unattended desk so that unauthorized persons cannot use unattended keys to reach protected materials. | active | contextual | yes | |
| f0b09fee9b381641… | Personnel must remove hardcopies of sensitive information from desks and lock them in a drawer when desks are unoccupied and at the end of the work day so that physical documents are not exposed. | active | contextual | yes | |
| 403c2773d07d7128… | PYRANA.ai personnel must secure all sensitive hardcopy and electronic information in their work area whenever it is unattended so that sensitive information remains protected in both remote and office settings. | active | contextual | yes | |
| 50911b4e68d61e00… | The effectiveness of security awareness and training programs must be regularly assessed and documented so that PYRANA.ai can verify and evidence training performance. | active | contextual | yes | |
| 422924bd42e2d23d… | Security awareness and training must include general security awareness, role-specific security requirements, and ongoing education about emerging threats so that personnel receive comprehensive and current security instruction. | active | contextual | yes | |
| cc55efc08581917c… | An authorized PYRANA.ai member must review each background check in accordance with local laws so that personnel screening complies with legal requirements. | active | contextual | yes | |
| 4e8cb18489746158… | Records of all policy and procedure changes must be retained and reviewed by the Board so that change history is documented and overseen. | active | contextual | yes | |
| 78887912ff91d556… | The CTO, CISO, COO, or Board of Directors are authorized to modify, remove, or approve modifications to these policies and procedures so that policy governance is limited to designated authorities. | active | contextual | yes | |
| b68d37017a31227e… | Any changes to security, privacy, and confidentiality policies require prior approval from the appropriate level of management so that policy modifications are formally controlled. | active | contextual | yes | |
| bb8708734aac704b… | Internal security, privacy, and confidentiality policy and procedure documents must be maintained and made accessible to employees with read-only permissions so that employees can consult them without altering them. | active | contextual | yes | |
| 9b09507681e7d5dd… | Management must review and approve policy and procedure documents annually or whenever significant changes occur so that governance documentation remains current and authorized. | active | contextual | yes | |
| ba66e7214e42f123… | The organization uses third-party software to manage its information security, business code of conduct, and operating practice policies and procedures so that governance documents are centrally administered. | active | contextual | yes | |
| bef128236e844f27… | All personnel must read, accept, and follow all PYRANA.ai policies and plans when starting work and at least annually thereafter so that policy awareness and compliance are maintained. | active | contextual | yes | |
| b2fbf33a0e167b68… | This policy is guided by security requirements specific to PYRANA.ai, including compliance with applicable laws and regulations, so that the security program aligns with legal and organizational obligations. | active | contextual | yes | |
| 3a0629b3d220c948… | PYRANA.ai may update this policy and apply different levels of security controls to different information assets based on risk and other considerations so that protections align with asset-specific risk. | active | contextual | yes | |
| 0b936d8ea55d9308… | The policy topics and requirements must be continuously improved over time so that PYRANA.ai maintains a secure information security posture. | active | contextual | yes | |
| 29dba71331563607… | This Information Security Policy defines topics and requirements that maintain the security, confidentiality, integrity, and availability of PYRANA.ai applications, systems, infrastructure, and data so that organizational information assets remain protected. | active | contextual | yes | |
| 96f98570616f2696… | All devices containing sensitive information, including mobile devices, must be configured to lock automatically after a period of inactivity such as a screen saver so that unattended devices are secured without manual action. | active | contextual | yes | |
| f7003d7d8118e19f… | Technical controls must enforce session time-outs and lockouts for all systems containing covered information so that inactive or unauthorized sessions are restricted automatically. | active | contextual | yes | |
| 3cee9030af97cea1… | All mobile and desktop devices must be locked when unoccupied so that unattended devices do not expose sensitive information or system access. | active | contextual | yes | |
| 05e6e9b4a2d2b616… | Employees and contractors must remain aware of their surroundings and ensure unauthorized individuals cannot see or hear sensitive information so that visual and auditory exposure of sensitive data is prevented. | active | contextual | yes | |
| a3ddb9e8b5a48c4d… | Keys used to access sensitive information must not be left at an unattended desk so that physical access controls are not compromised when work areas are unattended. | active | contextual | yes | |
| 2f46fffd3948fef2… | Personnel must remove hardcopies of sensitive information from desks and lock them in a drawer when desks are unoccupied and at the end of the work day so that physical documents are protected. | active | contextual | yes | |
| 44578c2b533d64b6… | PYRANA.ai personnel must secure all sensitive hardcopy and electronic information in their work area whenever it is unattended, whether working remotely or in the office, so that exposed information is protected from unauthorized access. | active | contextual | yes | |
| 235a383c67f2f391… | The effectiveness of security awareness and training programs must be regularly assessed and documented so that PYRANA.ai can verify and evidence program performance. | active | contextual | yes | |
| 0ddbe3c35bbafbea… | Security awareness and training must include general security awareness, role-specific security requirements, and ongoing education about emerging threats so that personnel remain informed about relevant security responsibilities and risks. | active | contextual | yes | |
| befe4616085e6440… | PYRANA.ai promotes engineers’ understanding of secure coding so that the security and robustness of PYRANA.ai products are improved. | active | contextual | yes | |
| 898f3993c1aa8415… | Personnel must sign an industry-standard confidentiality agreement before accessing sensitive information so that PYRANA.ai confidential information is protected. | active | contextual | yes | |
| dcaf09ceedaa8f70… | An authorized PYRANA.ai member must review each background check in accordance with local laws so that personnel screening complies with applicable legal requirements. | active | contextual | yes | |
| 1c4b7fb1e4cbf5cc… | All new PYRANA.ai employees and contractors must complete a background check or reference check before joining so that personnel screening occurs prior to engagement. | active | contextual | yes | |
| 46c6c7dab8c7a588… | Records of all policy and procedure changes must be retained and reviewed by the Board so that governance changes are documented and subject to oversight. | active | contextual | yes | |