Tests & Evidence

133 tests and evidence requests

133
Total
90
Passing
41
Failing
0
Pending
Test Results
TestCategoryOwnerFrameworksRenewalStatus
Personnel computer screenlock configured (MacOS)
ComputersEmal Alwis
-
Failing
Company has an approved Access Control Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Asset Management Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Business Continuity and Disaster Recovery Plan
PoliciesEmal Alwis
-
Failing
Company has an approved Code of Conduct
PoliciesEmal Alwis
-
Failing
Company has an approved Cryptography Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Data Management Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Human Resource Security Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Incident Response Plan
PoliciesEmal Alwis
-
Failing
Company has an approved Information Security Policy (AUP)
PoliciesEmal Alwis
-
Failing
Company has an approved Information Security Roles and Responsibilities
PoliciesEmal Alwis
-
Failing
Company has an approved Operations Security Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Physical Security Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Risk Management Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Secure Development Policy
PoliciesEmal Alwis
-
Failing
Company has an approved Third-Party Management Policy
PoliciesEmal Alwis
-
Failing
AWS accounts deprovisioned when personnel leave
Account SecurityEmal Alwis
-
Passing
EC2 instance public ports restricted (AWS)
InfrastructureIgnacio Orlandini
-
Passing
Intrusion detection system enabled (AWS)
InfrastructureIgnacio Orlandini
-
Passing
Intrusion detection system notifications configured (AWS)
InfrastructureIgnacio Orlandini
-
Passing
Expired SSL/TLS certificates are removed (AWS)
Infrastructure-
-
Passing
RDS Multi-AZ deployment configured (AWS)
Infrastructure-
-
Failing
S3 backup configured for redundancy across regions (AWS)
Data Storage-
-
Failing
S3 Block Public Access feature enabled (AWS)
InfrastructureIgnacio Orlandini
-
Failing
Background checks on new hires
EmployeesEmal Alwis
-
Failing
Calendly accounts deprovisioned when personnel leave
ItEmal Alwis
-
Passing
Calendly accounts associated with users
ItEmal Alwis
-
Passing
CloudTrail trails have log file integrity validation enabled
InfrastructureEmal Alwis
-
Passing
Application changes reviewed
Software DevelopmentIgnacio Orlandini
-
Passing
User data is encrypted at rest
Data StorageEmal Alwis
-
Passing
Checkr accounts deprovisioned when personnel leave
Account SecurityEmal Alwis
-
Passing
Checkr accounts associated with users
Account SetupEmal Alwis
-
Passing
Daily RDS database backups enabled (AWS)
Data StorageIgnacio Orlandini
-
Passing
Personnel agree to Access Control Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Asset Management Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Business Continuity and Disaster Recovery Plan
PoliciesEmal Alwis
-
Passing
Personnel agree to Code of Conduct
PoliciesEmal Alwis
-
Passing
Personnel agree to Cryptography Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Data Management Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Human Resource Security Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Incident Response Plan
PoliciesEmal Alwis
-
Passing
Personnel agree to Information Security Policy (AUP)
PoliciesEmal Alwis
-
Passing
Personnel agree to Information Security Roles and Responsibilities
PoliciesEmal Alwis
-
Passing
Personnel agree to Operations Security Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Physical Security Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Risk Management Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Secure Development Policy
PoliciesEmal Alwis
-
Passing
Personnel agree to Third-Party Management Policy
PoliciesEmal Alwis
-
Passing
Personnel have computers monitored by Vanta Device Monitor or an MDM
ComputersEmal Alwis
-
Passing
Unwanted traffic filtered
InfrastructureIgnacio Orlandini
-
Passing
Firewall default disallows traffic
InfrastructureIgnacio Orlandini
-
Passing
Public SSH denied (AWS)
InfrastructureIgnacio Orlandini
-
Passing
VPC Flow Logs enabled
LoggingEmal Alwis
-
Passing
Personnel computer hard disk encryption
ComputersEmal Alwis
-
Passing
Personnel computer hard disk encryption (Rippling)
ComputersEmal Alwis
-
Passing
GitHub accounts deprovisioned when personnel leave
Account SecurityEmal Alwis
-
Passing
GitHub accounts associated with users
Account SetupEmal Alwis
-
Failing
MFA on GitHub
Account SecurityIgnacio Orlandini
-
Passing
Author is not the reviewer of pull requests
Software DevelopmentEmal Alwis
-
Passing
Ensure branch protection rules are enforced for administrators (GitHub)
Software DevelopmentIgnacio Orlandini
-
Passing
GitHub repository visibility has been set to private
Software DevelopmentEmal Alwis
-
Passing
Vulnerability scanning is enabled (GitHub)
Vulnerability ManagementEmal Alwis
-
Passing
Company completes security assessments for relevant vendors
VendorsEmal Alwis
-
Failing
HR accounts associated with users
Account SetupEmal Alwis
-
Failing
Identity provider linked to Vanta
Account SetupEmal Alwis
-
Failing
Enabled IAM User Access Keys must not be older than 90 days
InfrastructureIgnacio Orlandini
-
Failing
AWS accounts reviewed
Account SetupIgnacio Orlandini
-
Failing
CloudTrail enabled
LoggingIgnacio Orlandini
-
Passing
IMDSv1 is disabled on EC2 Instances
InfrastructureIgnacio Orlandini
-
Failing
Cloud infrastructure linked to Vanta
InfrastructureIgnacio Orlandini
-
Passing
Service accounts used
Account SecurityEmal Alwis
-
Passing
Root infrastructure account unused
Account SecurityIgnacio Orlandini
-
Passing
Old infrastructure accounts disabled (AWS)
Account SecurityIgnacio Orlandini
-
Passing
No user account has a policy attached directly
Account SecurityIgnacio Orlandini
-
Passing
Clocks on infrastructure system synchronized
InfrastructureIgnacio Orlandini
-
Passing
Intercom accounts deprovisioned when personnel leave
Account SecurityEmal Alwis
-
Passing
Intercom accounts associated with users
Account SetupEmal Alwis
-
Failing
Company uses Vanta for continuous security monitoring
InfrastructureIgnacio Orlandini
-
Passing
Password policy configured for infrastructure
Account SecurityIgnacio Orlandini
-
Passing
Inventory items have descriptions
InfrastructureIgnacio Orlandini
-
Passing
Inventory items have active owners
InfrastructureEmal Alwis
-
Failing
Inventory list tracks resources that contain user data
InfrastructureEmal Alwis
-
Passing
Load balancer used (AWS)
InfrastructureIgnacio Orlandini
-
Passing
Load balancers redirect HTTP to HTTPS (AWS)
InfrastructureIgnacio Orlandini
-
Passing
Load balancer unhealthy host count monitored (AWS)
Monitoring AlertsEmal Alwis
-
Passing
Load balancer latency monitored
Monitoring AlertsEmal Alwis
-
Passing
Load balancer server errors monitored (AWS)
Monitoring AlertsEmal Alwis
-
Passing
S3 server access logs enabled
LoggingIgnacio Orlandini
-
N/A
Server logs retained for 365 days (AWS)
LoggingIgnacio Orlandini
-
Failing
Malware detection on computers (Rippling)
ComputersEmal Alwis
-
Passing
MFA on infrastructure provider
Account SecurityIgnacio Orlandini
-
Passing
MFA on infrastructure root accounts (AWS)
Account SecurityIgnacio Orlandini
-
Passing
SQL database CPU monitored
Monitoring AlertsEmal Alwis
-
Failing
SQL database freeable memory monitored (AWS)
Monitoring AlertsEmal Alwis
-
Passing
Database IO monitored (AWS)
Monitoring AlertsEmal Alwis
-
Passing
SQL database free storage space monitored (AWS)
Monitoring AlertsEmal Alwis
-
Passing
RDS instance IP restricted (AWS)
InfrastructureEmal Alwis
-
Passing
Critical vulnerabilities identified in packages are addressed (GitHub Repo)
Vulnerability ManagementIgnacio Orlandini
-
Failing
High vulnerabilities identified in packages are addressed (GitHub Repo)
Vulnerability ManagementIgnacio Orlandini
-
Failing
Low vulnerabilities identified in packages are addressed (GitHub Repo)
Vulnerability ManagementEmal Alwis
-
Failing
Medium vulnerabilities identified in packages are addressed (GitHub Repo)
Vulnerability ManagementEmal Alwis
-
Failing
Password manager records
ComputersEmal Alwis
-
Passing
Password manager records (Rippling)
ComputersEmal Alwis
-
Failing
SSL/TLS on admin page of infrastructure console
Monitoring AlertsIgnacio Orlandini
-
Passing
Risk Assessment exercise completed annually
Risk AnalysisJack Hawkins
-
Failing
Screenlock configured (Rippling)
ComputersEmal Alwis
-
Passing
Security awareness training selected
EmployeesEmal Alwis
-
Passing
General security awareness training records tracked
EmployeesJack Hawkins
-
Failing
Segment accounts associated with users
Account SetupEmal Alwis
-
Passing
Sentry accounts deprovisioned when personnel leave
ItEmal Alwis
-
Passing
Sentry accounts associated with users
ItEmal Alwis
-
Passing
Sentry integration has active alerts
Monitoring AlertsAndrew Pos
-
Passing
Serverless function error rate monitored (AWS)
Monitoring AlertsEmal Alwis
-
Passing
Server CPU monitored (AWS)
Monitoring AlertsIgnacio Orlandini
-
Failing
Slack accounts deprovisioned when personnel leave
Account SecurityEmal Alwis
-
Passing
Slack accounts associated with users
Account SetupEmal Alwis
-
Passing
MFA on Slack
Account SecurityEmal Alwis
-
N/A
Messaging queue message age monitored
Monitoring AlertsEmal Alwis
-
Passing
Strong SSL/TLS ciphers used
InfrastructureIgnacio Orlandini
-
Passing
SSL configuration has no known issues
InfrastructureIgnacio Orlandini
-
Passing
SSL/TLS certificate has not expired
InfrastructureIgnacio Orlandini
-
Passing
SSL/TLS enforced on company website
InfrastructureIgnacio Orlandini
-
Passing
User data in S3 is encrypted at rest (AWS)
Data StorageIgnacio Orlandini
-
Passing
Storage buckets versioned
Data StorageIgnacio Orlandini
-
Passing
Personnel agree to company policy: EQUAL EMPLOYMENT OPPORTUNITY AND PROHIBITION ON AND PREVENTION OF DISCRIMINATION, HARASSMENT AND RETALIATION
PoliciesEmal Alwis
-
Passing
Company has approved its policy: EQUAL EMPLOYMENT OPPORTUNITY AND PROHIBITION ON AND PREVENTION OF DISCRIMINATION, HARASSMENT AND RETALIATION
PoliciesEmal Alwis
-
Failing
Personnel have unique SSH keys
ComputersIgnacio Orlandini
-
Passing
Offboarding completed for terminated personnel within SLA
EmployeesEmal Alwis
-
Failing
Vendors list maintained
VendorsIgnacio Orlandini
-
Passing
Vendors assigned risk levels
VendorsEmal Alwis
-
Passing
Vendors have authentication method specified
VendorsJack Hawkins
-
Passing
Company has a version control system
Software DevelopmentIgnacio Orlandini
-
Passing
Zoom accounts associated with users
ItEmal Alwis
-
Passing