| 867ca0ab48056cd1… | PYRANA.ai may assign a vulnerability severity level that differs from scanner-generated or externally determined levels when internal knowledge of technical architecture and real-world impact or exploitability justifies a different assessment. | active | contextual | yes | |
| c0c76a9bec657a2e… | The engineering department must evaluate the severity of vulnerabilities, and if a vulnerability is determined to be critical or high risk, a service ticket must be created for follow-up action. | active | contextual | yes | |
| 927154832ee01da8… | Senior management must be informed about each security incident so that root causes, remediation steps, and lessons learned can be evaluated to prevent similar incidents in the future. | active | contextual | yes | |
| 747cbd15ce9d2ea9… | The incident response procedure must be tested at least once per year to verify the organization’s readiness to execute it. | active | contextual | yes | |
| 657d22f0f31d28b2… | The organization must review incident response procedures at least once per year for currency and update them as required so that it can appropriately plan and prepare for incidents. | active | contextual | yes | |
| 27575d9c2193be78… | All information security incidents must be handled through the defined incident management procedures so that incidents are tracked, documented, and resolved completely, accurately, and in a timely manner. | active | contextual | yes | |
| ed3c20f32cf6ef5a… | Information and artifacts associated with security incidents, including files, logs, and screen captures, must be preserved when they may need to be used as evidence of a crime. | active | contextual | yes | |
| 9112e89df001baa6… | Failure to report information security incidents is a security violation and must be reported to the CEO for disciplinary action. | active | contextual | yes | |
| e717bd33a40b335b… | Users must be trained on incident and vulnerability reporting procedures and on their responsibility to report information security incidents so that reporting obligations are understood and followed. | active | contextual | yes | |
| bb072be13bd5fac8… | Incident reports must include sufficient detail to support timely triage and response when users submit reports about vulnerabilities or security incidents. | active | contextual | yes | |
| 968e216d4c439cfb… | If the primary incident reporting channel is unavailable, the reporter must escalate the issue in order to the CTO, then the CISO, COO, and CEO so that the incident is still communicated through an alternate path. | active | contextual | yes | |
| e383f916815f0527… | The company’s designated incident reporting channels include security@pyrana.ai and the company ticketing system for reporting system vulnerabilities and information security incidents. | active | contextual | yes | |
| b72dc7d7377c72c8… | An information security incident is defined as a suspected, attempted, successful, or imminent threat involving unauthorized access, use, disclosure, breach, modification, or destruction of information, interference with information technology operations, or a significant violation of information security policy. | active | contextual | yes | |
| b95e9c19f6991e54… | A system vulnerability is a weakness in an information system, its security procedures, or its administrative controls that could be exploited to gain unauthorized access to information or to disrupt critical processing. | active | contextual | yes | |
| 6f675a53cc1038c9… | Incident notifications should identify the affected systems as part of the information provided during reporting. | active | contextual | yes | |
| 0d2f4919c3301ab5… | Incident notifications should include any known evidence of the incident as part of the initial report. | active | contextual | yes | |
| 97211f45c4e469a6… | Incident notifications should explain how the incident was discovered so that responders understand the detection context. | active | contextual | yes | |
| e9e590eec859c3ff… | Incident notifications should identify the person who discovered the incident as part of the required report details. | active | contextual | yes | |
| 95bb3ce0c7895d3e… | Incident notifications should include the date, time, and location of the incident to support reporting and response. | active | contextual | yes | |
| f7aaffe8901542d8… | Incident notifications should include a description of the incident as part of the required reporting information. | active | contextual | yes | |
| 381313bb8f75c21a… | When an information security incident is identified or detected, users must report it using the reporting channels described in the policy. | active | contextual | yes | |
| 52ac3fc5a553d8ba… | Vulnerabilities assessed by PYRANA.ai as low severity must be remediated within 90 days. | active | contextual | yes | |
| 3994208f5114aa4c… | Vulnerabilities assessed by PYRANA.ai as medium severity must be remediated within 30 to 60 days. | active | contextual | yes | |
| d62ca1be8a441919… | Vulnerabilities assessed by PYRANA.ai as high severity must be remediated within 7 to 14 days. | active | contextual | yes | |
| 7800d3b56d59ac5c… | Vulnerabilities assessed by PYRANA.ai as critical must be remediated within 24 to 72 hours. | active | contextual | yes | |
| 43da628e0b6d1b0f… | Tickets for vulnerabilities are assigned to the relevant system, application, or platform owners for further investigation or remediation. | active | contextual | yes | |
| 1027ef5f3796bfe4… | PYRANA.ai’s assessed vulnerability severity may differ from levels generated by scanning software or external researchers because internal knowledge of technical architecture and real-world impact or exploitability is used. | active | contextual | yes | |
| d27e562368165569… | The engineering department must evaluate the severity of vulnerabilities, and if a vulnerability is determined to be critical or high risk, a service ticket must be created. | active | contextual | yes | |
| 7f36c5ed57117bc5… | Senior management must be informed about each security incident so that root causes, remediation steps, and lessons learned can be evaluated to prevent similar future incidents. | active | contextual | yes | |
| f173398762c8d8a1… | All critical security incidents, including data breaches, must be logged and tracked in the ticketing system and communicated to affected parties. | active | contextual | yes | |
| f4eff92ac39eaf50… | The incident response procedure must be tested at least once per year. | active | contextual | yes | |
| b6a7966a926ce09b… | The organization must review incident response procedures at least once per year for currency and update them as required to maintain preparedness. | active | contextual | yes | |
| aba9ce0b5d4f8014… | All information security incidents must be handled through the defined incident management procedures so that incidents are tracked, documented, and resolved completely, accurately, and timely. | active | contextual | yes | |
| d905a9821047ea89… | Information and artifacts related to security incidents, such as files, logs, and screen captures, must be preserved when they may be needed as evidence of a crime. | active | contextual | yes | |
| 2d97de333b47fff8… | Failure to report information security incidents is a security violation and will be reported to the CEO for disciplinary action. | active | contextual | yes | |
| a7fbbab753df02e0… | Users must be trained on incident and vulnerability reporting procedures and on their responsibilities to report such events. | active | contextual | yes | |
| f5cf4bac6ad6a71c… | Incident reports must be submitted promptly and include enough detail to support timely triage and response. | active | contextual | yes | |
| 2a5e78d710d3cf70… | If the primary reporting channel is unavailable, the reporter must escalate the issue in order to the CTO, then the CISO, COO, and CEO. | active | contextual | yes | |
| 0b6e60ccccd19386… | The company’s designated incident reporting channels include security@pyrana.ai and the company ticketing system for reporting vulnerabilities and incidents. | active | contextual | yes | |
| 977d9d3e8b8a09fa… | All users must report any system vulnerability, incident, or event indicating a possible incident as soon as it is discovered through the company’s designated incident reporting channels so that timely response can begin. | active | contextual | yes | |
| 58fec192f7c916b2… | An information security incident is defined as a suspected, attempted, successful, or imminent threat involving unauthorized access, use, disclosure, breach, modification, destruction, operational interference, or significant policy violation. | active | contextual | yes | |
| 75bd069c0a2d5f06… | A vulnerability is a weakness in an information system, security procedures, or administrative controls that can be exploited to gain unauthorized access to information or disrupt critical processing. | active | contextual | yes | |
| ad7ed767945593e9… | If the primary reporting channel is unavailable and escalation beyond the CTO is needed, the reporter must escalate next to the CISO, then the COO, and finally the CEO in that order so that leadership notification follows the mandated sequence. | active | contextual | yes | |
| e696248323517f69… | If the primary reporting channel is unavailable, the reporter must escalate the issue first to the CTO so that incident notification continues through the defined escalation path. | active | contextual | yes | |
| 0cd215c423ecedcc… | An information security incident is a suspected, attempted, successful, or imminent threat involving unauthorized access, use, disclosure, breach, modification, or destruction of information, interference with IT operations, or a significant violation of information security policy. | active | contextual | yes | |
| aefa971cca0f7f5c… | An information security vulnerability is a weakness in an information system, security procedures, or administrative controls that could be exploited to gain unauthorized access to information or disrupt critical processing. | active | contextual | yes | |
| 12bd9ed6d35e30e1… | When an incident is confirmed as a breach, responders must follow a defined procedure to contain, investigate, resolve, and communicate information to employees, customers, partners, and other stakeholders so that breach handling is complete and coordinated. | active | contextual | yes | |
| c01cdfc07151f72f… | Identified incidents must be investigated within a period determined by their severity so that higher-severity incidents receive timely attention. | active | contextual | yes | |
| 1b6e01da9b0512a1… | Identified vulnerabilities must be resolved within a period determined by their severity so that remediation timing is prioritized according to risk level. | active | contextual | yes | |
| 9cf1e9d722e1f198… | When incidents and data breaches occur, the organization must respond rapidly by identifying, containing, investigating, resolving, and communicating information about the breach so that the event is managed effectively. | active | contextual | yes | |