Controls we've adopted
63 of 82 adopted controls are passing their tests. Evidence stays private; auditors review it in a separate, access-controlled view.
As of (just now)
Identity and access
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| IAM-01 | Single sign-on for business applications Workforce access to business applications is authenticated centrally so that sign-in policy, MFA and revocation apply from one identity provider. | Passing | (29 d ago) | Quarterly |
| IAM-02 | Multi-factor authentication A stolen or guessed password alone is not enough to access any workforce account. | Not passing | (7 h ago) | Quarterly |
| IAM-03 | Password manager Shared and non-SSO credentials are stored and shared in a controlled vault rather than in documents, chat or browsers. | Passing | (29 d ago) | Annually |
| IAM-04 | Least-privilege access People and processes hold only the access their role requires, limiting the damage a compromised or misused account can do. | Passing | (29 d ago) | Quarterly |
| IAM-05 | Role-based access control Permissions are assigned consistently through defined roles so access can be reasoned about, reviewed and revoked as a unit. | Passing | (29 d ago) | Annually |
| IAM-06 | Administrative access restricted Administrative control over core systems is held by a small, named set of people so that privileged actions are attributable and the attack surface is small. | Passing | (29 d ago) | Quarterly |
| IAM-07 | Access request and approval No access is provisioned without a recorded business justification and approval from someone accountable for the system. | Not yet tested | (29 d ago) | Quarterly |
| IAM-08 | Password configuration standards Systems that still rely on passwords resist guessing and reuse attacks. | Passing | (7 h ago) | Annually |
| IAM-09 | Periodic user access review Access that is no longer needed or was granted in error is found and removed on a regular cycle. | Passing | (29 d ago) | Quarterly |
Data protection
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| DATA-01 | Data classification Everyone handling information knows how sensitive it is and which handling rules apply. | Passing | Not yet | Annually |
| DATA-02 | Encryption at rest Confidential data cannot be read from storage media, snapshots or backups by someone who obtains them outside the application. | Passing | Not yet | Quarterly |
| DATA-03 | Encryption in transit Confidential data cannot be read or altered while it moves across networks. | Passing | (7 h ago) | Quarterly |
| DATA-04 | Data retention schedule Data is kept only as long as there is a business, contractual or legal reason, reducing exposure from stale records. | Passing | Not yet | Annually |
| DATA-05 | Secure data disposal Data that has reached the end of its retention period, or that a subject or customer asks to be deleted, cannot be recovered afterward. | Passing | Not yet | Annually |
| DATA-06 | Encryption standard and documentation Encryption is applied consistently with approved algorithms so that weak or outdated cryptography is not introduced. | Not yet tested | Not yet | Annually |
| DATA-12 | Automated backups Production data can be recovered after deletion, corruption or loss of a system. | Passing | (29 d ago) | Quarterly |
| DATA-13 | Off-site encrypted backup copies A regional outage or compromise of the production account does not destroy every copy of production data. | Passing | (29 d ago) | Quarterly |
| DATA-14 | Backup retention Backups are kept long enough to recover from problems that are discovered late. | Passing | (29 d ago) | Quarterly |
| DATA-15 | Backup restore testing Backups are proven to be usable within the recovery time and recovery point objectives before they are needed. | Passing | Not yet | Annually |
Cloud infrastructure
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| CLOUD-01 | TLS certificates on public endpoints Public endpoints always present a valid certificate, so users are not exposed to interception or outage from an expired certificate. | Passing | (29 d ago) | Monthly |
| CLOUD-02 | Infrastructure as code Infrastructure and deployment configuration are reproducible, reviewed and traceable rather than changed by hand. | Passing | (29 d ago) | Quarterly |
| CLOUD-03 | Network firewalls and security groups Only intended network traffic can reach cloud resources, and administrative ports are not exposed to the internet. | Passing | Not yet | Quarterly |
| CLOUD-04 | Host and container hardening Compute that FintastIQ manages exposes as little attack surface as possible. | Passing | Not yet | Annually |
| CLOUD-05 | Managed infrastructure auto-patching Known vulnerabilities in managed infrastructure are fixed promptly without relying on manual patching. | Not yet tested | Not yet | Quarterly |
| CLOUD-06 | Separate environments Development and testing activity cannot affect production systems or expose production data. | Passing | (29 d ago) | Quarterly |
Product delivery
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| PDP-01 | Agile development process Product work is planned, prioritized and tracked so that changes are traceable to an agreed purpose. | Passing | (4 mo ago) | Quarterly |
| PDP-02 | Change management process Production changes are reviewed, tested and approved before release, and can be traced afterward. | Passing | (23 d ago) | Quarterly |
| PDP-03 | Peer review and approval of changes A second person checks every change before it can reach production, catching errors and unauthorized code. | Not passing | (7 h ago) | Quarterly |
| PDP-04 | Automated testing and CI checks Changes that break types, tests, lint rules or security checks cannot be merged. | Passing | (29 d ago) | Quarterly |
| PDP-05 | Production deployment access No individual can place code into production outside the reviewed and gated pipeline. | Passing | (29 d ago) | Quarterly |
| PDP-06 | Source control All code and infrastructure definitions are versioned, access-controlled and recoverable. | Passing | (4 mo ago) | Annually |
| PDP-14 | Security impact analysis of changes Significant changes do not weaken security or privacy without someone deciding that knowingly. | Passing | (4 mo ago) | Annually |
Applications
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| APP-01 | Developer secure coding and encryption guidance Developers know how to avoid common vulnerabilities and how to use cryptography and secrets correctly. | Passing | (4 mo ago) | Annually |
| APP-02 | Static code analysis Insecure code patterns are found before and after merge. | Not yet tested | (3 mo ago) | Monthly |
Monitoring and vulnerability management
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| MON-01 | Centralized logging Security-relevant logs from every account and system are collected in one protected location so events can be correlated and investigated. | Not yet tested | (3 mo ago) | Quarterly |
| MON-02 | Security event logging Activity needed to detect and reconstruct security events is captured in every environment. | Passing | (4 mo ago) | Quarterly |
| MON-03 | Security event review Suspicious activity is noticed and acted on promptly instead of sitting unread in logs. | Not yet tested | (3 mo ago) | Weekly |
| MON-04 | Penetration testing Exploitable weaknesses in the products and infrastructure are found by an independent tester before an attacker finds them. | Not passing | (7 h ago) | Annually |
| MON-05 | Vulnerability scanning Known vulnerabilities in cloud workloads, images and dependencies are detected on a regular cadence. | Not yet tested | (3 mo ago) | Monthly |
| MON-06 | Patch management and remediation SLAs Identified vulnerabilities are fixed within time limits matched to their severity, limiting the window of exposure. | Not yet tested | (3 mo ago) | Monthly |
People
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| PEOPLE-01 | Background checks People given access to customer data have been screened for risks relevant to that trust before they start. | Not yet tested | (4 mo ago) | Annually |
| PEOPLE-02 | Confidentiality agreements Everyone who handles company or customer information is legally bound to keep it confidential. | Passing | Not yet | Annually |
| PEOPLE-03 | Termination checklist Departing personnel lose access and return company property, so no orphaned access or assets remain. | Passing | (7 h ago) | Quarterly |
| PEOPLE-04 | Policy acknowledgment Personnel know the policies that apply to them and have confirmed they will follow them. | Passing | (4 mo ago) | Annually |
| PEOPLE-05 | Performance reviews Managers evaluate each person's work at least yearly, including how they meet their security responsibilities. | Passing | (29 d ago) | Annually |
| PEOPLE-06 | Security awareness training Personnel can recognize and respond to common security threats and know their obligations. | Not passing | (7 h ago) | Annually |
| PEOPLE-07 | Disciplinary and sanctions process Policy violations have predictable consequences, which deters misconduct and supports fair handling. | Passing | Not yet | Annually |
| PEOPLE-08 | Job descriptions Each role's duties, including its security responsibilities, are defined in writing so expectations and access needs are clear. | Not yet tested | Not yet | Annually |
| PEOPLE-09 | Organizational chart and reporting lines Reporting lines and decision authority are documented so accountability for security and operations is clear. | Passing | Not yet | Annually |
| PEOPLE-15 | Code of conduct Personnel share a written standard for integrity and ethical behavior. | Passing | Not yet | Annually |
Vendors
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| VEND-01 | Vendor inventory FintastIQ knows every third party it relies on, what data each receives and who is accountable for it. | Passing | Not yet | Annually |
| VEND-02 | Vendor agreements Vendors that handle FintastIQ or customer data are contractually bound to protect it. | Passing | Not yet | Annually |
| VEND-03 | Vendor risk assessment Risks from a new vendor are understood and accepted before it receives data or access. | Passing | Not yet | Annually |
| VEND-04 | Vendor monitoring Changes in a critical vendor's security posture are caught after onboarding, not just at the start. | Not passing | (7 h ago) | Annually |
IT and endpoints
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| IT-01 | Acceptable use Personnel know the permitted and prohibited uses of company devices, accounts and tools, including AI tools. | Passing | Not yet | Annually |
| IT-02 | Workstation disk encryption Data on a lost or stolen workstation cannot be read. | Not yet tested | Not yet | Quarterly |
| IT-03 | Workstation operating system updates Workstations run supported operating systems with current security updates. | Not yet tested | (7 h ago) | Monthly |
| IT-04 | Asset inventory Every company device is accounted for and assigned to a responsible person. | Passing | Not yet | Quarterly |
| IT-05 | System inventory All systems and applications in use are known, owned and classified so they can be secured and assessed. | Passing | Not yet | Quarterly |
Physical security
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| PHYS-01 | Datacenter physical security Facilities housing production systems and customer data are physically protected against unauthorized entry. | Passing | Not yet | Annually |
Customers
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| CUST-01 | Customer support channel Customers can report problems and security concerns through a known channel that is tracked to resolution. | Passing | (4 mo ago) | Quarterly |
| CUST-02 | Master services agreement Security, confidentiality, availability and data commitments to customers are stated in a binding agreement. | Passing | Not yet | Annually |
| CUST-03 | Documentation site Customers have accurate public information about how the system works and what they are responsible for. | Passing | Not yet | Annually |
| CUST-04 | Release notifications Customers learn about releases and material changes that affect how they use the service or their security. | Not yet tested | Not yet | Quarterly |
Governance and business operations
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| BIZ-01 | Business continuity and disaster recovery plan FintastIQ can keep critical services running or restore them within agreed time and data-loss targets after a disruption. | Passing | (3 mo ago) | Annually |
| BIZ-02 | Incident response plan Security incidents are handled consistently and quickly, limiting damage and meeting notification obligations. | Passing | (3 mo ago) | Annually |
| BIZ-03 | Security incident tracking Every security incident is recorded and followed to closure, so none is lost and patterns can be analyzed. | Passing | (7 h ago) | Quarterly |
| BIZ-04 | Risk management program Risks to the business, its information and its clients are identified and treated consistently against a stated appetite. | Passing | Not yet | Annually |
| BIZ-05 | Risk register Identified risks stay visible, owned and actively managed between annual assessments. | Passing | (4 mo ago) | Quarterly |
| BIZ-06 | Fraud risk assessment Opportunities and pressures for fraud are identified so that controls can prevent or detect it. | Passing | (4 mo ago) | Annually |
| BIZ-07 | Control selection The set of controls in operation is justified by assessed risks and by the requirements of adopted frameworks. | Passing | Not yet | Annually |
| BIZ-08 | Control reviews Weaknesses in control design or operation are found within a quarter rather than at audit time. | Passing | Not yet | Quarterly |
| BIZ-09 | Corrective action tracking Control deficiencies and audit findings are remediated by accountable owners within committed dates. | Passing | Not yet | Quarterly |
| BIZ-10 | Cyber insurance Financial losses from a cyber incident are transferred in part to an insurer. | Not passing | Not yet | Annually |
| BIZ-11 | Board of directors oversight A governing body with independence from day-to-day management holds management accountable for security and compliance. | Passing | Not yet | Annually |
| BIZ-12 | Board meetings and security reporting The governing body receives regular, specific information on security, risk and compliance so it can exercise oversight. | Passing | Not yet | Annually |
| BIZ-13 | Internal support channels Staff can get IT and security help and report problems through known channels, so issues are raised and handled rather than ignored. | Passing | (29 d ago) | Annually |
| BIZ-14 | Information security program and policy Leadership sets the direction, scope and objectives of information security in an approved policy that staff must follow. | Passing | Not yet | Annually |
| BIZ-15 | Security roles and responsibilities Responsibility and authority for security are clearly assigned, and conflicting duties are separated to reduce the risk of error or abuse. | Passing | Not yet | Annually |
| BIZ-20 | Business continuity and DR testing The continuity and recovery plan is proven workable, and gaps are found in a test rather than in a real outage. | Passing | Not yet | Annually |
| BIZ-21 | Incident response testing The incident response plan and the people who run it are exercised, so a real incident is handled without improvisation. | Passing | (4 mo ago) | Annually |
Legal and privacy
| Code | Control | Status | Last tested | Frequency |
|---|---|---|---|---|
| LEGAL-01 | Privacy policy Individuals receive an accurate public account of how FintastIQ handles their personal data, avoiding deceptive or incomplete disclosures. | Passing | Not yet | Annually |
