| 80c6f23e2301c79a… | The CTO, CISO, COO, or Board of Directors are authorized to modify, remove, or approve modifications to these policies and procedures so that policy governance is restricted to designated leadership roles. | active | contextual | yes | |
| c9ceb25baa8976bc… | Changes to security, privacy, and confidentiality policies require prior approval from the appropriate level of management so that policy modifications are formally authorized before implementation. | active | contextual | yes | |
| 56dbf4214a86896f… | Internal security, privacy, and confidentiality policy and procedure documents are maintained with read-only access for employees so that employees can access them without unauthorized modification. | active | contextual | yes | |
| 10213e2a80f30a47… | Questions about the PYRANA.ai information security program should be directed to security@pyrana.ai so that personnel have a designated contact for security inquiries. | active | contextual | yes | |
| d84e631d04af79eb… | Policy and procedure documents must be reviewed and approved by management annually or when significant changes occur so that governance documentation remains current and authorized. | active | contextual | yes | |
| 36619f39b69cf480… | The organization uses third-party software to manage policies and procedures for information security, business code of conduct, and operating practices so that governance documents are centrally administered. | active | contextual | yes | |
| 1128311bf6f54bae… | All personnel must read, accept, and follow all PYRANA.ai policies and plans when they start work and at least annually thereafter so that policy awareness and compliance are maintained. | active | contextual | yes | |
| 0fab8cb99389bd47… | This policy applies to all PYRANA.ai assets used by personnel acting on behalf of PYRANA.ai or accessing its applications, infrastructure, systems, or data so that all relevant organizational resources are covered. | active | contextual | yes | |
| 3d02a6a7082f1edc… | This policy is guided by security requirements specific to PYRANA.ai, including compliance with applicable laws and regulations, so that the organization’s security program aligns with legal and organizational obligations. | active | contextual | yes | |
| d42565699aba2afe… | PYRANA.ai may update this policy and apply different levels of security controls to different information assets based on risk and other considerations so that protections align with asset-specific needs. | active | contextual | yes | |
| 89749be6b72c9720… | The policy’s topics and requirements must be continuously improved over time so that PYRANA.ai maintains a secure information security posture. | active | contextual | yes | |
| 006d5c343788e80d… | This Information Security Policy defines topics and requirements for protecting the security, confidentiality, integrity, and availability of PYRANA.ai applications, systems, infrastructure, and data so that organizational information assets remain protected. | active | contextual | yes | |
| 202217075b029afb… | The document is Version 3 of the incident response policy so that readers can identify the applicable revision of the policy. | active | contextual | yes | |
| 195b93b40a623049… | This incident response policy was approved on 04/07/2026 so that the document has a recorded approval date for governance and version control purposes. | active | contextual | yes | |
| dbb267f6c6fe77f2… | The document identifies Eric Tarnowski as the Secondary Signatory for this incident response policy so that the policy has an assigned secondary approver. | active | contextual | yes | |
| 53a3ac46991a655d… | The document identifies James Canterbury as the Primary Signatory for this incident response policy so that the policy has an assigned primary approver. | active | contextual | yes | |
| df871c33bf2298bc… | Upon receiving a report of a personal device incident, the CTO or designated responder must deny re-access until the user confirms the replacement or recovered device meets the Personal Device and BYOD Standard. | active | contextual | yes | |
| d8a88c8497b8ae9b… | Upon receiving a report of a personal device incident, the CTO or designated responder must remove the work account and company data from managed mobile devices so that corporate information is protected. | active | contextual | yes | |
| b3048633ba65cd2b… | Upon receiving a report of a personal device incident, the CTO or designated responder must reset the user's passwords and revoke active sessions so that compromised credentials and access are invalidated. | active | contextual | yes | |
| 326632f7da0ed47c… | Upon receiving a report of a lost, stolen, or suspected-compromised personal device, the CTO or designated responder must block the reported device from company systems so that further access is prevented. | active | contextual | yes | |
| d0dac018d716ba39… | All low-risk incidents must be periodically reviewed to identify trends, ensure documentation accuracy, and determine whether follow-up actions or preventative improvements are needed. | active | contextual | yes | |
| 714c287a4a4a9c88… | For some low-risk incidents, a brief review and notation are sufficient without a formal ticket so that minor events can be handled proportionately. | active | contextual | yes | |
| e27c1d334785860a… | The CEO must take disciplinary action when necessary if a user's activity is deemed malicious so that malicious user behavior is addressed through formal consequences. | active | contextual | yes | |
| 00f6661adcc7782d… | After an incident has been resolved, the CTO must conduct a post mortem that includes root cause analysis and documentation of lessons learned so that future incidents can be better prevented. | active | contextual | yes | |
| f84cae18e9d06e37… | An incident log entry must include disclosures identifying parties to which incident details were disclosed, such as customers, vendors, or law enforcement, so that external and internal notifications are tracked. | active | contextual | yes | |
| d2ad553169811b9d… | An incident log entry must include status values such as open, closed, or archived so that the current lifecycle state of the incident is recorded. | active | contextual | yes | |
| de4710685d6bed7e… | An incident log entry must include mitigations applied, such as a patch or re-image, so that remediation actions taken during the incident are documented. | active | contextual | yes | |
| 5eed9dcb699ee3f3… | An incident log entry must include evidence so that supporting material for the incident and response is retained in the official record. | active | contextual | yes | |
| 36946cb9d5819cc8… | An incident log entry must include the root cause, such as source address, website malware, or vulnerability, so that the origin of the incident is documented. | active | contextual | yes | |
| 6ba50a433fcbf55c… | An incident log entry must include the incident severity level so that the seriousness of the event is recorded for response and review purposes. | active | contextual | yes | |
| 6cb2597b0ab29c09… | An incident log entry must include a description of the incident so that the event being handled is clearly identified in the official record. | active | contextual | yes | |
| 9a1b3cdd71eac60f… | All technical steps taken during an incident must be documented in the organization's incident log so that the response record is complete and auditable. | active | contextual | yes | |
| c6d26a0c5209db5f… | This incident response policy document is version 3 so that the current revision level of the policy is explicitly identified. | active | contextual | yes | |
| a9956d3bd7ed1814… | This incident response policy document was approved on 04/07/2026 so that its formal approval date is recorded in the document metadata. | active | contextual | yes | |
| 4060258c7216fcb7… | Eric Tarnowski is identified as the Secondary Signatory for this policy document so that the document records its secondary signatory authority. | active | contextual | yes | |
| a66bd9f53b3ed954… | James Canterbury is identified as the Primary Signatory for this policy document so that the document records its principal signatory authority. | active | contextual | yes | |
| 8445a382810fe413… | The CTO or designated responder must deny re-access to company systems until the user confirms that the replacement or recovered device meets the Personal Device and BYOD Standard so that only compliant devices regain access. | active | contextual | yes | |
| 5b74e7a8519670d5… | Upon receiving a report of a compromised personal device, the CTO or designated responder must remove the work account and company data from managed mobile devices so that organizational data is no longer present on the device. | active | contextual | yes | |
| c43c69afc566e14b… | Upon receiving a report of a compromised personal device, the CTO or designated responder must reset the user's passwords and revoke active sessions so that existing access tokens and credentials are invalidated. | active | contextual | yes | |
| 8d1649e2e063232c… | Users must report any lost, stolen, or suspected-compromised personal device used for company work immediately and no later than 24 hours after discovery, following the reporting chain defined in this policy. | active | contextual | yes | |
| e08108e59354b28c… | External authorities that may be contacted include law enforcement agencies, data protection authorities, relevant regulatory bodies, affected customers, and third-party service providers as part of incident response communications. | active | contextual | yes | |
| fb61658652c9281a… | All low-risk incidents must be periodically reviewed so that trends can be identified, documentation accuracy ensured, and follow-up actions or preventative improvements determined. | active | contextual | yes | |
| 7eab92915d1c2434… | Some low-risk incidents may be handled with only a brief review and notation without a formal ticket when the circumstances do not require fuller tracking. | active | contextual | yes | |
| cecde66db020e1e4… | When a low-risk incident is identified, the responsible team member must record it in the designated tracking system and create a ticket when appropriate so that the event is documented consistently. | active | contextual | yes | |
| 97d73f885d592d49… | Low-risk severity incidents are handled through streamlined processes focused on documentation and routine review because they generally pose minimal impact to operations, security, or compliance. | active | contextual | yes | |
| 822a80f2fd0849da… | The CEO must take disciplinary action when necessary if a user's activity is deemed malicious so that malicious user behavior is formally addressed. | active | contextual | yes | |
| 256a43a77b55b938… | The CTO must notify all users of the incident, provide additional training if necessary, and present lessons learned so that future occurrences can be prevented. | active | contextual | yes | |
| cfc8272e29135682… | The CEO may contact external authorities, including law enforcement, private investigation firms, and government organizations, depending on incident severity as part of the response to the incident. | active | contextual | yes | |
| 45091352b7ba8f82… | After an incident is resolved, the CTO must conduct a post mortem that includes root cause analysis and documentation of lessons learned so that future incidents can be better prevented and understood. | active | contextual | yes | |
| fbd8743ee02902a9… | The incident log must include disclosures identifying parties to whom incident details were disclosed, such as customers, vendors, or law enforcement, so that external and internal notifications are tracked. | active | contextual | yes | |