Audit & Assurance
Independent Assessments
Are independent audit and assurance assessments conducted according to relevant standards at least annually?
Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit?
Application & Interface Security
Application Security Baseline Requirements
Are baseline requirements to secure different applications established, documented, and maintained?
Application Vulnerability Remediation
Are application security vulnerabilities remediated following defined processes?
Business Continuity Management
Business Continuity Planning
Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
Backup and Recovery
Is cloud data periodically backed up?
Cryptography & Key Management
Encryption and Key Management
Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
Data Security & Privacy
Data Protection
Are systems, products, and business practices based on security principles by design and per industry best practices?