Controls
Comprehensive overview of the security control frameworks we run — grouped by category so you can jump straight to the domain you care about.
Control Environment
Security awareness training implemented
Employees are required to complete security awareness training within 30 days of being hired and at least once a year thereafter.
Compliance with policies, rules and standards for information security
The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.
Code of Conduct acknowledged by contractors
The company mandates that contractor agreements either include a code of conduct or refer to the company’s own code of conduct.
Board meetings conducted
The board of directors meets at least once a year and keeps formal minutes of its meetings. It includes members who are independent of the company.
Security policies established and reviewed
The company’s information security policies and procedures are formally documented and reviewed at least once a year.
Employee background checks performed
The company conducts background screenings for all new hires.
Performance evaluations conducted
Managers are required to conduct performance evaluations for their direct reports at least once a year.
Code of Conduct acknowledged by employees and enforced
Employees are required to acknowledge the code of conduct upon hiring. Any violations may result in disciplinary action as outlined in the company’s disciplinary policy.
Board oversight briefings conducted
Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.
Communication and Information
System changes communicated
The company notifies authorized internal users of system changes.
Security policies established and reviewed
The company’s information security policies and procedures are formally documented and reviewed at least once a year.
System changes externally communicated
The company informs customers of critical system changes that could impact their processing.
Code of Conduct acknowledged by employees and enforced
Employees are required to acknowledge the code of conduct upon hiring. Any violations may result in disciplinary action as outlined in the company’s disciplinary policy.
Third-party agreements established
The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.
Risk Assessment
Infrastructure performance monitored
The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.
Compliance with policies, rules and standards for information security
The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.
Risk assessment objectives specified
The company defines its objectives to support the identification and assessment of risks associated with achieving them.
Annual risk assessment performed annually
The company performs the risk assessment process at least annually and whenever significant changes occur in the environment, such as acquisitions, mergers, or relocations.
Risk management program established
The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.
Risks assessments performed
The company performs risk assessments at least annually. This process includes identifying threats and changes (environmental, regulatory, and technological) that may affect service commitments, formally assessing the related risks, and considering how potential fraud could impact the achievement of objectives.
Change management procedures enforced
The company requires changes to software and infrastructure components to be authorized, documented, tested, reviewed, and approved before being implemented in the production environment.
Monitoring Activities
Nonconformity and corrective action
When a nonconformity is identified, the organization: 1. Responds to the issue by: a) Taking action to control and correct it b) Addressing any resulting consequences 2. Assesses the need for action to prevent recurrence or occurrence elsewhere by: a) Reviewing the nonconformity b) Identifying its root causes c) Determining whether similar issues exist or could potentially arise 3. Implements necessary corrective actions 4. Evaluates the effectiveness of those actions 5. Updates the information security management system as needed Corrective actions are proportionate to the impact of the nonconformities. Documented information is retained to demonstrate: 1. The nature of the nonconformities and the actions taken 2. The results of any corrective actions
Board oversight briefings conducted
Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.
Control Activities
Documentation change control
System documentation shall be subject to revision and change control procedures that maintain an audit trail documenting time-sequenced development and modifications.
Operational system checks
Operational system checks shall be used, as appropriate, to enforce permitted sequencing of steps and events.
Compliance with policies, rules and standards for information security
The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.
Risk management program established
The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.
Development lifecycle established
The company has a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, maintenance, and changes (including emergency changes) of information systems and related technology requirements.
Security policies established and reviewed
The company’s information security policies and procedures are formally documented and reviewed at least once a year.
Logical and Physical Access Controls
Network firewalls utilized
The company uses firewalls configured to block unauthorized access.
Physical access processes established
The company has processes for granting, modifying, and revoking physical access to data centers based on authorization from control owners.
Data transmission encrypted
The company uses secure transmission protocols to encrypt confidential and sensitive data when it is transmitted over public networks.
Intrusion detection system utilized
The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.
System access limitation
System access shall be restricted to authorized individuals.
Data deletion requests handled
The company validates deletion requests, and once confirmed, flags and deletes the requested information in accordance with applicable laws and regulations.
Password policy enforced
The company requires passwords for in-scope system components to be configured in accordance with its policy.
Authority checks
Authority checks shall restrict system use, electronic signing, access to operations or system input/output devices, record alteration, and performance of the operation at hand to authorized individuals.
Firewall access restricted
The company limits privileged access to the firewall to authorized users who have a valid business need.
Data encryption utilized
The company encrypts datastores containing sensitive customer data at rest.
Network segmentation implemented
The company’s network is segmented to block unauthorized access to customer data.
Security patches installed within one month
The company installs critical security patches within one month of their release, as determined by the risk ranking process defined in VPM-4.
Securely dispose of data
The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.
Production data segmented
The company purges or removes customer data containing confidential information from the application environment in accordance with best practices when customers discontinue the service.
Visitor procedures enforced
The company requires visitors to sign in, wear a visitor badge, and be escorted by an authorized employee when accessing the data center or other secure areas.
Access reviews conducted
The company performs access reviews at least quarterly for in-scope system components to ensure access is appropriately restricted. Required changes are tracked to completion.
Remote access encrypted enforced
The company restricts remote access to production systems to authorized employees using an approved encrypted connection.
Asset disposal procedures utilized
The company ensures electronic media containing confidential information is purged or destroyed following best practices, with certificates of destruction issued for each device.
Data center access reviewed
The company reviews data center access at least once a year.
Access control procedures established
The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access
Malicious software protection implemented
The company has implemented procedures to guard against, detect, and report malicious software.
System Operations
Intrusion detection system utilized
The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.
Infrastructure performance monitored
The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.
Incident response plan tested
The company tests its incident response plan at least once a year.
Incident response policies established
The company has documented security and privacy incident response policies and procedures, which are communicated to authorized users.
Vulnerability and system monitoring procedures established
The company’s formal policies define requirements for the following IT and engineering functions: 1. Vulnerability management 2. System monitoring
Incident management procedures followed
The company’s security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management in accordance with its security incident response policy and procedures.
Continuity and disaster recovery plans tested
The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.
Vulnerabilities scanned and remediated
Host-based vulnerability scans are conducted at least quarterly on all externally facing systems, with critical and high-risk vulnerabilities tracked through to remediation.
Log management utilized
The company uses a log management tool to detect events that could potentially affect its ability to meet security objectives.
Change Management
Documentation change control
System documentation shall be subject to revision and change control procedures that maintain an audit trail documenting time-sequenced development and modifications.
Production deployment access restricted
The company restricts production change migrations to authorized personnel only.
Development lifecycle established
The company has a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, maintenance, and changes (including emergency changes) of information systems and related technology requirements.
Change management procedures enforced
The company requires changes to software and infrastructure components to be authorized, documented, tested, reviewed, and approved before being implemented in the production environment.
Risk Mitigation
Vendor management program established
The company has a vendor management program in place that includes: 1. Critical third-party vendor inventory 2. Vendor security and privacy requirements 3. Review of critical third-party vendors at least annually
Continuity and disaster recovery plans tested
The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.
Risk management program established
The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.
Risks assessments performed
The company performs risk assessments at least annually. This process includes identifying threats and changes (environmental, regulatory, and technological) that may affect service commitments, formally assessing the related risks, and considering how potential fraud could impact the achievement of objectives.
Third-party agreements established
The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.
Additional Criteria for Availability
Production data backups conducted
The company performs periodic backups of production data, storing the backups in a separate location from the production environment.
Infrastructure performance monitored
The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.
Incident response plan tested
The company tests its incident response plan at least once a year.
Production multi-availability zones established
The company employs a multi-location strategy for production environments to enable operations to resume at alternate data centers if a facility becomes unavailable.
Database replication utilized
The company’s databases are replicated in real time to a secondary data center, with alerts set up to notify administrators of any replication failures.
Continuity and disaster recovery plans tested
The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.
Environmental monitoring devices implemented
The company uses environmental monitoring devices configured to automatically alert management in the event of environmental incidents.
Additional Criteria for Confidentiality
Data deletion requests handled
The company validates deletion requests, and once confirmed, flags and deletes the requested information in accordance with applicable laws and regulations.
Data encryption utilized
The company encrypts datastores containing sensitive customer data at rest.
Data classification policy established
The company has a data classification policy to ensure confidential data is properly secured and accessible only to authorized personnel.
Securely dispose of data
The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.
Production data segmented
The company purges or removes customer data containing confidential information from the application environment in accordance with best practices when customers discontinue the service.
Asset disposal procedures utilized
The company ensures electronic media containing confidential information is purged or destroyed following best practices, with certificates of destruction issued for each device.
Additional Criteria for Processing integrity
Production data backups conducted
The company performs periodic backups of production data, storing the backups in a separate location from the production environment.
Establish and maintain a data management process
The organization establishes and maintains a documented data management process that addresses, at a minimum: 1. Data sensitivity 2. Data owner 3. Data handling 4. Data retention limits 5. Data disposal requirements The organization aligns these elements with enterprise sensitivity and retention standards and reviews and updates the documentation annually or upon significant changes that could impact this control.
Operational system checks
Operational system checks shall be used, as appropriate, to enforce permitted sequencing of steps and events.
Compliance with policies, rules and standards for information security
The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.
Processing data inputs validated
The company’s system evaluates data inputs for compliance with input requirements and generates on-screen alerts when issues with transaction inputs or processing are detected.
System validation
Persons who use closed systems to create, modify, maintain, or transmit electronic records shall validate those systems for accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.
Customer data retained
The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.