| af80008c84090910… | Critical vendors without a SOC 2 report that access PYRANA.ai data or affect PYRANA.ai system security must undergo a quarterly vendor risk assessment so that high-risk vendors receive compensating oversight. | active | contextual | yes | |
| 5ce0e2efa6c3011c… | At onboarding and annually thereafter, management reviews service provider or vendor SOC 2 reports to assess scope appropriateness, the impact of identified exceptions, and applicable complementary user entity controls. | active | contextual | yes | |
| 32f35844c1337153… | During onboarding, vendor responsibilities, including security commitments and responsibilities, must be documented and agreed with the vendors so that expectations are formally established. | active | contextual | yes | |
| 2c21d98924b32f3f… | Third-party access to PYRANA.ai information may be granted only after authorization and execution of the applicable agreements or contracts so that access is controlled and formally approved. | active | contextual | yes | |
| 702d56e7ee5eaeb8… | Vendors or subprocessors handling Customer Data must have written agreements containing confidentiality, security, breach-notification, return or delete, and subcontractor obligations that are at least as protective as PYRANA.ai’s customer commitments. | active | contextual | yes | |
| 4e6d79c3fc453ae1… | If PYRANA.ai confidential data is breached, the vendor is responsible for notifying PYRANA.ai without undue delay and in time to meet contractual incident notification obligations regarding incident details, recovery, and remediation. | active | contextual | yes | |
| a24227f1eb10f5ef… | Vendor contracts must clearly specify security reporting requirements stating that the vendor is responsible for maintaining the security of confidential data regardless of ownership so that accountability for data protection is explicit. | active | contextual | yes | |
| 445f3910b3cf3ca9… | Contracts involving exchange of confidential data must require vendor confidentiality agreements and identify the security policies and procedures applicable to the vendor so that confidentiality obligations are formally imposed. | active | contextual | yes | |
| a6ae47df8d67f973… | During vendor onboarding, the vendor must sign PYRANA.ai’s vendor contract, or if the vendor is an online service provider, PYRANA.ai must accept the vendor’s predefined terms of service so that the relationship is contractually established. | active | contextual | yes | |
| 9f3a396c03ca416a… | Vendor risk assessments should consider due diligence factors including distributed IT environments, legacy or longstanding suppliers, and third-party use of subcontractors so that inherited supplier risks are identified. | active | contextual | yes | |
| 0be8b216ac99fe97… | Vendor risk assessments should consider regulatory requirements because regulators mandate supervision of third-party suppliers for security, privacy, and data protection compliance so that legal obligations are met. | active | contextual | yes | |
| 66cf95f38b737d1b… | Vendor risk assessments should consider data exposure from incorrectly classified or unidentified data that could be exposed to a third party so that unintended disclosure risks are addressed. | active | contextual | yes | |
| f0b5b59a5576176f… | Vendor risk assessments should consider business continuity by evaluating availability as third-party services and solutions become integrated into the core company offering or service provided so that operational resilience is maintained. | active | contextual | yes | |
| b8e514f32571c0e5… | Vendor risk assessments should consider monitoring gaps through periodic assessments, ongoing monitoring, incident notification, offboarding, adherence, and SLA appropriateness so that oversight weaknesses are identified. | active | contextual | yes | |
| f8eafad33513a3fc… | Vendor risk assessments should consider information security by evaluating third-party controls for security, privacy, confidentiality, and availability of shared data so that data protection risks are understood. | active | contextual | yes | |
| c0f869b095d70673… | Executive management should perform a vendor risk assessment before engaging with vendors so that third-party risks are evaluated prior to establishing the relationship. | active | contextual | yes | |
| ffffa72f227f99ef… | Upon termination of vendor services, contracts must require return or destruction of all organization data unless another arrangement has been agreed upon. | active | contextual | yes | |
| ae6eeb1677975b01… | When a vendor or service provider relationship is terminated, access is removed through a termination checklist and revoked as part of the termination process. | active | contextual | yes | |
| 0cd48c58b810a21e… | PYRANA.ai includes clauses in agreements with vendors and service providers that allow termination of relationships when necessary. | active | contextual | yes | |
| fb7d3391cc4d95fe… | Corrective actions are taken as required based on assessment results so that identified vendor oversight issues are addressed. | active | contextual | yes | |
| 05ffcab7e905a068… | During the quarterly assessment of critical vendors, management also assesses performance, service delivery, and compliance with security commitments. | active | contextual | yes | |
| ee1a82709f2fb66e… | Critical vendors without a SOC 2 report that access PYRANA.ai data or affect PYRANA.ai system security must undergo a quarterly vendor risk assessment. | active | contextual | yes | |
| e4ae1bafd23dca37… | Management reviews service provider and vendor SOC 2 reports at onboarding and annually to assess scope appropriateness, the impact of identified exceptions, and applicable complementary user entity controls. | active | contextual | yes | |
| 7367061db1554cee… | Vendor responsibilities, including security commitments and responsibilities, are documented and agreed with vendors during the onboarding process so that obligations are formally established. | active | contextual | yes | |
| 8902f72208208b55… | Third-party access to PYRANA.ai information may be granted only after authorization and execution of the applicable agreements or contracts so that access is formally controlled. | active | contextual | yes | |
| e09f84f0e39928fd… | Vendors or subprocessors handling Customer Data must have written agreements containing confidentiality, security, breach-notification, return/delete, and subcontractor obligations that are at least as protective as PYRANA.ai’s customer commitments. | active | contextual | yes | |
| 12501d278695d6b1… | If PYRANA.ai confidential data is breached, the vendor is responsible for notifying PYRANA.ai without undue delay so that contractual incident notification obligations for incident details, recovery, and remediation can be met. | active | contextual | yes | |
| 90d1c23e64701c6f… | Vendor contracts must clearly identify security reporting requirements stating that the vendor is responsible for maintaining the security of confidential data regardless of ownership. | active | contextual | yes | |
| 8153ac79e6ce1b05… | Contracts involving exchange of confidential data must require vendor confidentiality agreements and must identify the security policies and procedures that apply to the vendor. | active | contextual | yes | |
| 73a856e728f718ea… | At vendor onboarding, the vendor must sign PYRANA.ai’s vendor contract, or if the vendor is an online service provider, PYRANA.ai must accept the vendor’s pre-defined terms of service. | active | contextual | yes | |
| 606fbbbd3583fb72… | The vendor risk assessment process includes due diligence for distributed IT environments, legacy or longstanding suppliers, and third-party use of subcontractors so that supplier complexity risks are assessed. | active | contextual | yes | |
| 734b8fa51da1473c… | The vendor risk assessment process includes regulatory requirements because regulators mandate supervision of third-party suppliers for security, privacy, and data protection compliance. | active | contextual | yes | |
| feb7aea64d0a021a… | The vendor risk assessment process includes evaluating data exposure risks from incorrectly classified data and unidentified data that could be exposed to the third party. | active | contextual | yes | |
| 1a80133475cc6725… | The vendor risk assessment process includes business continuity considerations about service availability as third-party services and solutions become more integrated into the core company offering or service provided. | active | contextual | yes | |
| 2ecad7608d7fbd4d… | The vendor risk assessment process includes monitoring gaps such as periodic assessments, ongoing monitoring, incident notification, offboarding, adherence, and SLA appropriateness so that oversight weaknesses are identified. | active | contextual | yes | |
| cd459e6303adbeaa… | The vendor risk assessment process includes information security review of third-party controls for security, privacy, confidentiality, and availability of shared data so that data protection risks are identified. | active | contextual | yes | |
| baff9f1fa3d8c6e0… | Executive management should perform a vendor risk assessment before engaging with vendors so that third-party risks are evaluated prior to the relationship beginning. | active | contextual | yes | |
| f4b43026d97781b5… | The risk assessment process should consider due diligence factors, including distributed IT environments, legacy or longstanding suppliers, and the third party’s use of subcontractors. | active | contextual | yes | |
| 74c3fdb953f1d732… | The risk assessment process should consider regulatory requirements because regulators mandate supervision of third-party suppliers for security, privacy, and data protection compliance. | active | contextual | yes | |
| 36f11ee8de0dde0c… | The risk assessment process should consider data exposure risk, including incorrectly classified data and unidentified data that could be exposed to the third party. | active | contextual | yes | |
| 2d9ebbebcbbf6f06… | The risk assessment process should consider business continuity risk, including availability considerations as third-party services and solutions become more integrated into the core company offering or service provided. | active | contextual | yes | |
| 142b2459d35db02a… | The risk assessment process should consider monitoring gaps, including periodic assessments, ongoing monitoring, incident notification, offboarding, adherence, and the appropriateness of service level agreements. | active | contextual | yes | |
| 95c4e79d128373d1… | The risk assessment process should consider information security risk, including assessment of third-party controls related to security, privacy, confidentiality, and availability of shared data. | active | contextual | yes | |
| b966c1365f03d69c… | Executive management must review identified risks together with mitigation strategies or determine whether the risks are acceptable before engaging with vendors. | active | contextual | yes | |
| 8e5b885e9bb47854… | Before outsourcing any PYRANA.ai process or service to a third party or allowing third-party access to organizational information or systems, the involved risks must be clearly identified and documented. | active | contextual | yes | |
| 1866b9d665a637f1… | When selecting a service provider or substantially amending or renewing a contract or outsourcing agreement, PYRANA.ai is expected to undertake a due diligence process that fully assesses outsourcing risks and addresses all relevant aspects of the service provider, including qualitative and quantitative factors. | active | contextual | yes | |
| c86a4b8d74d12151… | PYRANA.ai conducts internal due diligence to determine the nature and scope of the business activity to be outsourced and its relationship to the rest of the in-scope activities. | active | contextual | yes | |
| d26cf4e15be94f28… | Before granting third-party access to the PYRANA.ai network and systems, the organization must conduct a risk assessment of network connectivity so that access-related network risks are evaluated first. | active | contextual | yes | |
| abf94f9deec87030… | Third-party risk assessments are performed to ensure PYRANA.ai business data is properly protected from unauthorized access, use, and modification. | active | contextual | yes | |
| 79f0e5b532f7e819… | Risk assessments for third parties must be repeated on an annual basis so that gaps between third-party security controls and PYRANA.ai information security standards or regulatory requirements are identified over time. | active | contextual | yes | |