Tests & Evidence
133 tests and evidence requests
133
Total
90
Passing
41
Failing
0
Pending
Test Results
| Test | Category | Owner | Frameworks | Renewal | Status |
|---|---|---|---|---|---|
Personnel computer screenlock configured (MacOS) | Computers | Emal Alwis | - | Failing | |
Company has an approved Access Control Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Asset Management Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Business Continuity and Disaster Recovery Plan | Policies | Emal Alwis | - | Failing | |
Company has an approved Code of Conduct | Policies | Emal Alwis | - | Failing | |
Company has an approved Cryptography Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Data Management Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Human Resource Security Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Incident Response Plan | Policies | Emal Alwis | - | Failing | |
Company has an approved Information Security Policy (AUP) | Policies | Emal Alwis | - | Failing | |
Company has an approved Information Security Roles and Responsibilities | Policies | Emal Alwis | - | Failing | |
Company has an approved Operations Security Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Physical Security Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Risk Management Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Secure Development Policy | Policies | Emal Alwis | - | Failing | |
Company has an approved Third-Party Management Policy | Policies | Emal Alwis | - | Failing | |
AWS accounts deprovisioned when personnel leave | Account Security | Emal Alwis | - | Passing | |
EC2 instance public ports restricted (AWS) | Infrastructure | Ignacio Orlandini | - | Passing | |
Intrusion detection system enabled (AWS) | Infrastructure | Ignacio Orlandini | - | Passing | |
Intrusion detection system notifications configured (AWS) | Infrastructure | Ignacio Orlandini | - | Passing | |
Expired SSL/TLS certificates are removed (AWS) | Infrastructure | - | - | Passing | |
RDS Multi-AZ deployment configured (AWS) | Infrastructure | - | - | Failing | |
S3 backup configured for redundancy across regions (AWS) | Data Storage | - | - | Failing | |
S3 Block Public Access feature enabled (AWS) | Infrastructure | Ignacio Orlandini | - | Failing | |
Background checks on new hires | Employees | Emal Alwis | - | Failing | |
Calendly accounts deprovisioned when personnel leave | It | Emal Alwis | - | Passing | |
Calendly accounts associated with users | It | Emal Alwis | - | Passing | |
CloudTrail trails have log file integrity validation enabled | Infrastructure | Emal Alwis | - | Passing | |
Application changes reviewed | Software Development | Ignacio Orlandini | - | Passing | |
User data is encrypted at rest | Data Storage | Emal Alwis | - | Passing | |
Checkr accounts deprovisioned when personnel leave | Account Security | Emal Alwis | - | Passing | |
Checkr accounts associated with users | Account Setup | Emal Alwis | - | Passing | |
Daily RDS database backups enabled (AWS) | Data Storage | Ignacio Orlandini | - | Passing | |
Personnel agree to Access Control Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Asset Management Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Business Continuity and Disaster Recovery Plan | Policies | Emal Alwis | - | Passing | |
Personnel agree to Code of Conduct | Policies | Emal Alwis | - | Passing | |
Personnel agree to Cryptography Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Data Management Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Human Resource Security Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Incident Response Plan | Policies | Emal Alwis | - | Passing | |
Personnel agree to Information Security Policy (AUP) | Policies | Emal Alwis | - | Passing | |
Personnel agree to Information Security Roles and Responsibilities | Policies | Emal Alwis | - | Passing | |
Personnel agree to Operations Security Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Physical Security Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Risk Management Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Secure Development Policy | Policies | Emal Alwis | - | Passing | |
Personnel agree to Third-Party Management Policy | Policies | Emal Alwis | - | Passing | |
Personnel have computers monitored by Vanta Device Monitor or an MDM | Computers | Emal Alwis | - | Passing | |
Unwanted traffic filtered | Infrastructure | Ignacio Orlandini | - | Passing | |
Firewall default disallows traffic | Infrastructure | Ignacio Orlandini | - | Passing | |
Public SSH denied (AWS) | Infrastructure | Ignacio Orlandini | - | Passing | |
VPC Flow Logs enabled | Logging | Emal Alwis | - | Passing | |
Personnel computer hard disk encryption | Computers | Emal Alwis | - | Passing | |
Personnel computer hard disk encryption (Rippling) | Computers | Emal Alwis | - | Passing | |
GitHub accounts deprovisioned when personnel leave | Account Security | Emal Alwis | - | Passing | |
GitHub accounts associated with users | Account Setup | Emal Alwis | - | Failing | |
MFA on GitHub | Account Security | Ignacio Orlandini | - | Passing | |
Author is not the reviewer of pull requests | Software Development | Emal Alwis | - | Passing | |
Ensure branch protection rules are enforced for administrators (GitHub) | Software Development | Ignacio Orlandini | - | Passing | |
GitHub repository visibility has been set to private | Software Development | Emal Alwis | - | Passing | |
Vulnerability scanning is enabled (GitHub) | Vulnerability Management | Emal Alwis | - | Passing | |
Company completes security assessments for relevant vendors | Vendors | Emal Alwis | - | Failing | |
HR accounts associated with users | Account Setup | Emal Alwis | - | Failing | |
Identity provider linked to Vanta | Account Setup | Emal Alwis | - | Failing | |
Enabled IAM User Access Keys must not be older than 90 days | Infrastructure | Ignacio Orlandini | - | Failing | |
AWS accounts reviewed | Account Setup | Ignacio Orlandini | - | Failing | |
CloudTrail enabled | Logging | Ignacio Orlandini | - | Passing | |
IMDSv1 is disabled on EC2 Instances | Infrastructure | Ignacio Orlandini | - | Failing | |
Cloud infrastructure linked to Vanta | Infrastructure | Ignacio Orlandini | - | Passing | |
Service accounts used | Account Security | Emal Alwis | - | Passing | |
Root infrastructure account unused | Account Security | Ignacio Orlandini | - | Passing | |
Old infrastructure accounts disabled (AWS) | Account Security | Ignacio Orlandini | - | Passing | |
No user account has a policy attached directly | Account Security | Ignacio Orlandini | - | Passing | |
Clocks on infrastructure system synchronized | Infrastructure | Ignacio Orlandini | - | Passing | |
Intercom accounts deprovisioned when personnel leave | Account Security | Emal Alwis | - | Passing | |
Intercom accounts associated with users | Account Setup | Emal Alwis | - | Failing | |
Company uses Vanta for continuous security monitoring | Infrastructure | Ignacio Orlandini | - | Passing | |
Password policy configured for infrastructure | Account Security | Ignacio Orlandini | - | Passing | |
Inventory items have descriptions | Infrastructure | Ignacio Orlandini | - | Passing | |
Inventory items have active owners | Infrastructure | Emal Alwis | - | Failing | |
Inventory list tracks resources that contain user data | Infrastructure | Emal Alwis | - | Passing | |
Load balancer used (AWS) | Infrastructure | Ignacio Orlandini | - | Passing | |
Load balancers redirect HTTP to HTTPS (AWS) | Infrastructure | Ignacio Orlandini | - | Passing | |
Load balancer unhealthy host count monitored (AWS) | Monitoring Alerts | Emal Alwis | - | Passing | |
Load balancer latency monitored | Monitoring Alerts | Emal Alwis | - | Passing | |
Load balancer server errors monitored (AWS) | Monitoring Alerts | Emal Alwis | - | Passing | |
S3 server access logs enabled | Logging | Ignacio Orlandini | - | N/A | |
Server logs retained for 365 days (AWS) | Logging | Ignacio Orlandini | - | Failing | |
Malware detection on computers (Rippling) | Computers | Emal Alwis | - | Passing | |
MFA on infrastructure provider | Account Security | Ignacio Orlandini | - | Passing | |
MFA on infrastructure root accounts (AWS) | Account Security | Ignacio Orlandini | - | Passing | |
SQL database CPU monitored | Monitoring Alerts | Emal Alwis | - | Failing | |
SQL database freeable memory monitored (AWS) | Monitoring Alerts | Emal Alwis | - | Passing | |
Database IO monitored (AWS) | Monitoring Alerts | Emal Alwis | - | Passing | |
SQL database free storage space monitored (AWS) | Monitoring Alerts | Emal Alwis | - | Passing | |
RDS instance IP restricted (AWS) | Infrastructure | Emal Alwis | - | Passing | |
Critical vulnerabilities identified in packages are addressed (GitHub Repo) | Vulnerability Management | Ignacio Orlandini | - | Failing | |
High vulnerabilities identified in packages are addressed (GitHub Repo) | Vulnerability Management | Ignacio Orlandini | - | Failing | |
Low vulnerabilities identified in packages are addressed (GitHub Repo) | Vulnerability Management | Emal Alwis | - | Failing | |
Medium vulnerabilities identified in packages are addressed (GitHub Repo) | Vulnerability Management | Emal Alwis | - | Failing | |
Password manager records | Computers | Emal Alwis | - | Passing | |
Password manager records (Rippling) | Computers | Emal Alwis | - | Failing | |
SSL/TLS on admin page of infrastructure console | Monitoring Alerts | Ignacio Orlandini | - | Passing | |
Risk Assessment exercise completed annually | Risk Analysis | Jack Hawkins | - | Failing | |
Screenlock configured (Rippling) | Computers | Emal Alwis | - | Passing | |
Security awareness training selected | Employees | Emal Alwis | - | Passing | |
General security awareness training records tracked | Employees | Jack Hawkins | - | Failing | |
Segment accounts associated with users | Account Setup | Emal Alwis | - | Passing | |
Sentry accounts deprovisioned when personnel leave | It | Emal Alwis | - | Passing | |
Sentry accounts associated with users | It | Emal Alwis | - | Passing | |
Sentry integration has active alerts | Monitoring Alerts | Andrew Pos | - | Passing | |
Serverless function error rate monitored (AWS) | Monitoring Alerts | Emal Alwis | - | Passing | |
Server CPU monitored (AWS) | Monitoring Alerts | Ignacio Orlandini | - | Failing | |
Slack accounts deprovisioned when personnel leave | Account Security | Emal Alwis | - | Passing | |
Slack accounts associated with users | Account Setup | Emal Alwis | - | Passing | |
MFA on Slack | Account Security | Emal Alwis | - | N/A | |
Messaging queue message age monitored | Monitoring Alerts | Emal Alwis | - | Passing | |
Strong SSL/TLS ciphers used | Infrastructure | Ignacio Orlandini | - | Passing | |
SSL configuration has no known issues | Infrastructure | Ignacio Orlandini | - | Passing | |
SSL/TLS certificate has not expired | Infrastructure | Ignacio Orlandini | - | Passing | |
SSL/TLS enforced on company website | Infrastructure | Ignacio Orlandini | - | Passing | |
User data in S3 is encrypted at rest (AWS) | Data Storage | Ignacio Orlandini | - | Passing | |
Storage buckets versioned | Data Storage | Ignacio Orlandini | - | Passing | |
Personnel agree to company policy: EQUAL EMPLOYMENT OPPORTUNITY AND PROHIBITION ON AND PREVENTION OF DISCRIMINATION, HARASSMENT AND RETALIATION | Policies | Emal Alwis | - | Passing | |
Company has approved its policy: EQUAL EMPLOYMENT OPPORTUNITY AND PROHIBITION ON AND PREVENTION OF DISCRIMINATION, HARASSMENT AND RETALIATION | Policies | Emal Alwis | - | Failing | |
Personnel have unique SSH keys | Computers | Ignacio Orlandini | - | Passing | |
Offboarding completed for terminated personnel within SLA | Employees | Emal Alwis | - | Failing | |
Vendors list maintained | Vendors | Ignacio Orlandini | - | Passing | |
Vendors assigned risk levels | Vendors | Emal Alwis | - | Passing | |
Vendors have authentication method specified | Vendors | Jack Hawkins | - | Passing | |
Company has a version control system | Software Development | Ignacio Orlandini | - | Passing | |
Zoom accounts associated with users | It | Emal Alwis | - | Passing |