To help determine that only authorized changes are deployed, Entity’s key personnel are notified when changes are deployed to the production environment
The entity systems generate information that is reviewed and evaluated to determine impacts to the functioning of internal controls.
Entity uses Sprinto, a continuous monitoring system, to alert the security team to update the access levels of team members whose roles have changed
Entity has a documented Encryption Policy, and makes it available for all staff on the company employee portal
Entity has a documented Acceptable Usage Policy, and makes it available for all staff on the company employee portal
Entity has a documented Endpoint Security Policy, and makes it available for all staff on the company employee portal