Purpose

Maintain the information security management practices that support confidentiality, integrity and availability. Bitkaya applies information security controls to all critical business and control systems, including platforms and tools used for client onboarding, sanctions screening, transaction monitoring, compliance case handling, and regulatory support.

Scope

This procedure applies to security ownership, risk assessment, monitoring, incident handling, privacy and training expectations for the IT environment. Because compliance systems may contain screening results, internal classifications, escalation notes, UTR-related materials, and legally sensitive information, access must be tightly controlled and logged.

Steps

#ActionDetailsEvidence
1Confirm security framework owner and review cycleVerify that ISM principles are CBCS-aligned and proportionate to Bitkaya’s startup profile, focusing on essential ISO 27001 control areas such as access control, encryption, and incident management.security risk assessment
2Verify security controlsEnsure confidentiality of client and compliance-sensitive data; integrity of screening and monitoring outputs; secure authentication and access management; protection against unauthorized alteration of rules, settings, or workflows; logging and traceability of system use and key actions; and resilience against cyber threats and operational misuse.incident or monitoring record
3Confirm protection of private keys and wallet infrastructureVerify security measures emphasize protection of private keys, wallet infrastructure, and client data through multi-factor authentication, hardware keys, and encrypted storage.access control and logging evidence
4Verify access control for compliance systemsEnsure access to compliance systems containing screening results, internal classifications, escalation notes, UTR-related materials, and legally sensitive information is tightly controlled and logged. Review security risks, incidents and monitoring outputs.access control and logging evidence for compliance-sensitive systems
5Verify outsourced security servicesWhere non-core technical services are outsourced (e.g., penetration testing, vulnerability scanning), verify reliance on certified providers with vendor oversight rather than in-house duplication.vendor oversight record for outsourced security services
6Confirm policies, standards and training coverageVerify policies, standards, and training are simplified but cover all mandatory CBCS ISM objectives for confidentiality, integrity, and availability.training or attestation record
7Record updates, remediation and escalation actionsRetain evidence of assessments, responses and follow-up.incident or monitoring record
8Escalate unresolved security gapsEscalate to management and Compliance.escalation or remediation record

Evidence

  • security risk assessment
  • incident or monitoring record
  • access control and logging evidence for compliance-sensitive systems
  • vendor oversight record for outsourced security services (penetration testing, vulnerability scanning)
  • training or attestation record where relevant

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from REQ-IT-002.