Your access
6 documents here are available on request. Ask and we will pass them on.
Security and compliance summary
Certifications and frameworks
ISO/IEC 27001:2022
Measures
RefMeasureMappingStatus
Application security
SDL-02App Security Testing & DisclosureA - 8.29 · A - 8.33 · A - 8.4Implemented
SDL-05Infrastructure as Code SecurityA - 8.27 · A - 8.28Implemented
SDL-01Secure SDLC FrameworkA - 8.25 · A - 8.26 · A - 8.30 · A - 8.31Implemented
Asset management
ASM-04Data & Information ClassificationA - 5.10 · A - 5.11 · A - 5.12 · A - 8.11Implemented
Continuity management
DAT-03Backup & Recovery IntegrityA - 8.13Implemented
ASM-02Configuration & Baseline ManagementA - 8.6 · A - 8.9Implemented
BCM-03Recovery Testing & ImprovementA - 8.14Implemented
Governance
GRC-01Information Security GovernanceA - 5.2 · A - 5.3 · A - 5.4 · A - 5.5 · A - 5.6 · C - 4.1 · C - 4.2 · C - 4.3 · C - 4.4 · C - 5.1 · C - 5.3 · C - 7.1 · C - 7.4Implemented
Human resources security
PEO-02HR Security ControlsA - 6.1 · A - 6.2 · A - 6.4 · A - 6.5 · A - 6.6 · C - 7.2Implemented
PEO-01Security Awareness & TrainingA - 6.3 · C - 7.3Implemented
Identity and access management
IAM-04Access Reviews & RecertificationA - 5.18Implemented
IAM-01Identity Lifecycle ManagementA - 5.16Implemented
IAM-03Privileged & Role-Based Access ControlA - 8.2Implemented
IAM-05Secrets & Service Account ManagementA - 5.17Implemented
IAM-02Strong Authentication & MFAA - 5.15 · A - 8.18 · A - 8.3 · A - 8.5Implemented
Improvement
GRC-06Internal Audit & AssuranceA - 5.35 · A - 8.34 · C - 10.1 · C - 10.2 · C - 9.2.1 · C - 9.2.2Implemented
Information Protection
DAT-02Data Loss Prevention (DLP)A - 8.12Implemented
DAT-06Data Privacy & Subject RightsA - 5.34Implemented
DAT-04Data Retention & Secure DisposalA - 8.10Implemented
DAT-05Secure CommunicationsA - 5.14 · A - 8.23Implemented
Information security events management
DET-01Centralized LoggingA - 8.15 · A - 8.17 · A - 8.7Implemented
IR-02Incident Investigation & ForensicsA - 5.26 · A - 5.28Implemented
IR-01Incident Response ProgramA - 5.24 · A - 5.25 · A - 6.8Implemented
Information security in Supplier relationships
SUP-04Cloud & Outsourced Service GovernanceA - 5.23Implemented
SUP-02Contractual Security RequirementsA - 5.20Implemented
SUP-03Ongoing Supplier MonitoringA - 5.22Implemented
SDL-03Software Supply Chain SecurityA - 5.21Implemented
SUP-01Supplier Security Due DiligenceA - 5.19Implemented
Legal and Compliance
GRC-04Compliance & Regulatory ManagementA - 5.31 · A - 5.32 · A - 5.33 · A - 5.36Implemented
Operation
GRC-03Risk Management ProgramA - 5.8 · C - 6.1 · C - 6.1.1 · C - 6.1.2 · C - 6.1.3 · C - 6.2 · C - 8.1 · C - 8.2 · C - 8.3Implemented
Performance evaluation
GRC-05Security Metrics & ReportingC - 6.2 · C - 9.1 · C - 9.3.1 · C - 9.3.2 · C - 9.3.3Implemented
Secure configuration
DAT-01Cryptography & Key ManagementA - 8.24Implemented
VUL-02Security Configuration HardeningA - 8.7 · A - 8.9Implemented
Support
GRC-02Policy & Standards ManagementA - 5.1 · A - 5.13 · A - 5.37 · C - 5.2 · C - 7.5 · C - 7.5.1 · C - 7.5.2 · C - 7.5.3Implemented
Systems and networks security
ASM-03Network & Connectivity ManagementA - 8.20 · A - 8.21 · A - 8.22Implemented
IAM-07Remote Access SecurityA - 6.7 · A - 8.23Implemented
VUL-01Vulnerability & Patch ManagementA - 8.7 · A - 8.8Implemented
DET-03Endpoint & Network Detection (XDR)—Implemented
Documents
Metrics
KPI-035Acuna Uptime
ColumnOn Target
DailyHigher is better
Contact
- Security
- helpme@acuna.ai
- Privacy
- privacy@acuna.ai