| 520cbe2e2bee68b9… | The organization is committed to protecting employees, customers, and partners from illegal or damaging actions by others, whether those actions are taken knowingly or unknowingly, so that affected parties are safeguarded from harm. | active | contextual | yes | |
| 8794a36e17a6a8da… | The policy applies to all users of organizational information systems, including employees, contractors, and external parties who interact with systems and information controlled by the organization so that all relevant users are covered by the incident response requirements. | active | contextual | yes | |
| 39748e17c44641dd… | Management must review the incident response process document annually and update it as required so that the policy remains current and effective. | active | contextual | yes | |
| 7603064a4a75b5cc… | The document provides implementation instructions for security incident response by defining required definitions, procedures, responsibilities, and performance measures including metrics and reporting mechanisms so that the response process can be executed consistently. | active | contextual | yes | |
| 4be9a0026912e7ae… | The incident response policy establishes a formal incident management process that requires incidents to be tracked, documented, and resolved completely, accurately, and promptly so that security vulnerabilities and incidents are detected and security breaches receive a quick reaction and response. | active | contextual | yes | |
| 496510c7b4330f60… | Incident reports must be submitted promptly and include enough detail to support timely triage and response so that responders can assess and act without unnecessary delay. | active | contextual | yes | |
| 5397dbc18388de8c… | If the primary reporting channel is unavailable, the reporter must escalate the issue in order to the CTO, then the CISO, COO, and CEO so that reporting can continue through an alternate chain. | active | contextual | yes | |
| 619b5c9a6e12560f… | The designated incident reporting channels include security@pyrana.ai and the company ticketing system so that users have approved mechanisms for submitting incident reports. | active | contextual | yes | |
| fab78f7859a65ac7… | All users must report any system vulnerability, incident, or event indicating a possible incident as soon as it is discovered through the company’s designated incident reporting channels so that triage and response can begin promptly. | active | contextual | yes | |
| 775b170f2d992b87… | An Information Security Vulnerability is defined as a weakness in an information system, its security procedures, or administrative controls that could be exploited to gain unauthorized access to information or disrupt critical processing. | active | contextual | yes | |
| 7abe6f0e65934213… | If an incident is confirmed as a breach, a defined procedure must be followed to contain, investigate, resolve, and communicate information to employees, customers, partners, and other stakeholders so that breach handling is consistent. | active | contextual | yes | |
| 59cfdc551bb225d4… | If an incident is identified, it must be investigated within a period set according to its severity so that higher-severity incidents receive appropriately timed investigation. | active | contextual | yes | |
| f1870adb8dd064b1… | If a vulnerability is identified, it must be resolved within a period set according to its severity so that remediation timing is risk-based. | active | contextual | yes | |
| 87bb7c372ad902d3… | The organization must employ automated scanning and reporting mechanisms to identify possible information security vulnerabilities and incidents so that detection does not rely solely on manual reporting. | active | contextual | yes | |
| 0e31930037b55e7c… | All users must report any perceived or actual information security vulnerability or incident as soon as possible using the contact mechanisms prescribed in the document so that potential issues are surfaced quickly. | active | contextual | yes | |
| 6497b942dd7ab6ea… | When incidents and data breaches occur, the organization must respond rapidly by identifying, containing, investigating, resolving, and communicating information related to the breach so that impacts are managed promptly. | active | contextual | yes | |
| 8d33d9c03604c398… | The organization is committed to protecting employees, customers, and partners from illegal or damaging actions by others whether those actions are taken knowingly or unknowingly. | active | contextual | yes | |
| 4131c36563f5ae74… | The policy must be made readily available to all users so that everyone within scope can access the incident response requirements. | active | contextual | yes | |
| 4dc6c8b6a798d455… | This policy applies to all users of organizational information systems, including employees, contractors, and external parties who interact with systems and information controlled by the organization, so that coverage extends to all relevant users. | active | contextual | yes | |
| 8e3267fcf7817f0b… | Management must review the process document annually and update it as required so that the incident response process remains current and maintained. | active | contextual | yes | |
| e96131d64d4a5623… | The document provides implementation instructions for security incident response by defining terms, procedures, responsibilities, and performance measures including metrics and reporting mechanisms so that the response process is operationalized. | active | contextual | yes | |
| c1d66a09c61e2086… | The incident response policy establishes a formal incident management process that requires incidents to be tracked, documented, and resolved completely, accurately, and promptly so that security vulnerabilities and incidents are detected and security breaches receive quick reaction and response. | active | contextual | yes | |
| a17f1569a0cb83eb… | Incident reports must be submitted promptly and include enough detail to support timely triage and response so that responders can assess and act on reported issues without delay. | active | contextual | yes | |
| 0548da424dd82c3c… | If the primary reporting channel is unavailable, the reporter must escalate the issue in order to the CTO, then the CISO, COO, and CEO so that incident reporting can continue through an alternate chain. | active | contextual | yes | |
| d012cf84be69981b… | All users must report any system vulnerability, incident, or event indicating a possible incident as soon as it is discovered through the designated reporting channels, including security@pyrana.ai or the company ticketing system. | active | contextual | yes | |
| cae46e4a1dcc0a16… | An information security incident is defined as a suspected, attempted, successful, or imminent threat involving unauthorized access, use, disclosure, breach, modification, or destruction of information, interference with IT operations, or significant violation of security policy. | active | contextual | yes | |
| de1a6533e9ae451b… | An information security vulnerability is defined as a weakness in an information system, security procedures, or administrative controls that could be exploited to gain unauthorized access to information or disrupt critical processing. | active | contextual | yes | |
| 09daabcfa5ea043e… | If an incident is confirmed as a breach, a defined procedure must be followed to contain, investigate, resolve, and communicate information to employees, customers, partners, and other stakeholders so that breach handling is consistent and complete. | active | contextual | yes | |
| a39fad2f9567bfbc… | If an incident is identified, it must be investigated within a period determined by its severity so that higher-severity incidents receive appropriately timely investigation. | active | contextual | yes | |
| 27e042c6e7dd8e5a… | If a vulnerability is identified, it must be resolved within a period determined by its severity so that remediation urgency matches the risk level. | active | contextual | yes | |
| 71982ec25ed994fa… | The organization must employ automated scanning and reporting mechanisms to identify possible information security vulnerabilities and incidents so that potential security issues can be detected systematically. | active | contextual | yes | |
| 99dbb714bad73c83… | All users must report any perceived or actual information security vulnerability or incident as soon as possible using the contact mechanisms prescribed in the document so that potential issues are surfaced quickly for response. | active | contextual | yes | |
| 92a3482edf8c2af7… | The policy recognizes that incidents and data breaches are likely to occur, and when they do the organization is committed to responding rapidly by identifying, containing, investigating, resolving, and communicating information about the breach. | active | contextual | yes | |
| 2411d200651165e3… | The organization is committed to protecting employees, customers, and partners from illegal or damaging actions by others, whether those actions are taken knowingly or unknowingly. | active | contextual | yes | |
| 06efd2c6a9de8e6a… | A key objective of the Information Security Management Team is to detect information security weaknesses and vulnerabilities so that incidents and breaches can be prevented wherever possible. | active | contextual | yes | |
| b3ee2e16d00ee109… | The policy must be made readily available to all users so that covered individuals can access the incident response requirements and reporting expectations. | active | contextual | yes | |
| c7f93315eb66d2f7… | The policy applies to all users of organizational information systems, including employees, contractors, and external parties who interact with systems and information controlled by the organization so that all relevant users are covered by the same incident response rules. | active | contextual | yes | |
| a3487ebbda420c0b… | Management must review the incident response process document annually and update it as required so that the policy remains current and effective over time. | active | contextual | yes | |
| e3e4e7ef929222ca… | The document provides implementation instructions for security incident response by defining relevant terms, procedures, responsibilities, and performance measures including metrics and reporting mechanisms so that the response process can be consistently executed. | active | contextual | yes | |
| cd22aba307a3bcfd… | The incident response policy establishes controls for a formal incident management process that requires incidents to be tracked, documented, and resolved completely, accurately, and promptly so that security vulnerabilities and incidents are detected and security breaches receive quick reaction and response. | active | contextual | yes | |
| d41cd9a15719163f… | The Vendor Management Policy document is version 2 so that the current revision of the policy is explicitly identified. | active | contextual | yes | |
| e0d04498031fd6df… | The Vendor Management Policy was approved on 03/10/2026 so that the document records its formal approval date. | active | contextual | yes | |
| 9fb8266ecef38661… | The Vendor Management Policy document identifies Eric Tarnowski as the Secondary Signatory so that the policy records an authorized secondary approver. | active | contextual | yes | |
| bb5bd7d6ac442cb4… | The Vendor Management Policy document identifies James Canterbury as the Primary Signatory so that the policy records an authorized primary approver. | active | contextual | yes | |
| 0edce8c66f1137a7… | PYRANA.ai performs exit reviews on vendors to verify compliance with termination clauses when vendor relationships end so that contractual termination obligations are confirmed. | active | contextual | yes | |
| edfd558110b395a2… | PYRANA.ai must agree on appropriate provisions with vendors to preserve the security of information and systems if a contract is terminated or transferred to another supplier so that security continues during supplier transition or exit. | active | contextual | yes | |
| 95974895fa67ac76… | Procurement and contract managers designated by PYRANA.ai management must immediately ensure termination of a vendor’s access to PYRANA.ai systems and, when relevant, facilities housing those systems so that terminated vendors cannot continue physical or logical access. | active | contextual | yes | |
| 7f6fe9cd7f2f2aec… | Upon termination of vendor services, contracts must require the return or destruction of all organization data unless another arrangement is agreed so that PYRANA.ai data is not retained improperly after service termination. | active | contextual | yes | |
| 20f3f432a6bdf071… | When a vendor or service provider is terminated, PYRANA.ai removes the vendor’s access through a termination checklist and revokes access as part of the termination process so that terminated parties no longer retain system access. | active | contextual | yes | |
| 60dfdb5527b91a1d… | PYRANA.ai includes contractual clauses in agreements with vendors and service providers to allow termination of relationships when necessary so that the organization can end vendor engagements under defined conditions. | active | contextual | yes | |