Purpose
Maintain the information security management practices that support confidentiality, integrity and availability. Bitkaya applies information security controls to all critical business and control systems, including platforms and tools used for client onboarding, sanctions screening, transaction monitoring, compliance case handling, and regulatory support.
Scope
This procedure applies to security ownership, risk assessment, monitoring, incident handling, privacy and training expectations for the IT environment. Because compliance systems may contain screening results, internal classifications, escalation notes, UTR-related materials, and legally sensitive information, access must be tightly controlled and logged.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm security framework owner and review cycle | Verify that ISM principles are CBCS-aligned and proportionate to Bitkaya’s startup profile, focusing on essential ISO 27001 control areas such as access control, encryption, and incident management. | security risk assessment |
| 2 | Verify security controls | Ensure confidentiality of client and compliance-sensitive data; integrity of screening and monitoring outputs; secure authentication and access management; protection against unauthorized alteration of rules, settings, or workflows; logging and traceability of system use and key actions; and resilience against cyber threats and operational misuse. | incident or monitoring record |
| 3 | Confirm protection of private keys and wallet infrastructure | Verify security measures emphasize protection of private keys, wallet infrastructure, and client data through multi-factor authentication, hardware keys, and encrypted storage. | access control and logging evidence |
| 4 | Verify access control for compliance systems | Ensure access to compliance systems containing screening results, internal classifications, escalation notes, UTR-related materials, and legally sensitive information is tightly controlled and logged. Review security risks, incidents and monitoring outputs. | access control and logging evidence for compliance-sensitive systems |
| 5 | Verify outsourced security services | Where non-core technical services are outsourced (e.g., penetration testing, vulnerability scanning), verify reliance on certified providers with vendor oversight rather than in-house duplication. | vendor oversight record for outsourced security services |
| 6 | Confirm policies, standards and training coverage | Verify policies, standards, and training are simplified but cover all mandatory CBCS ISM objectives for confidentiality, integrity, and availability. | training or attestation record |
| 7 | Record updates, remediation and escalation actions | Retain evidence of assessments, responses and follow-up. | incident or monitoring record |
| 8 | Escalate unresolved security gaps | Escalate to management and Compliance. | escalation or remediation record |
Evidence
- security risk assessment
- incident or monitoring record
- access control and logging evidence for compliance-sensitive systems
- vendor oversight record for outsourced security services (penetration testing, vulnerability scanning)
- training or attestation record where relevant
Relationships
- Requirement: REQ-IT-002 Maintain Information Security Management
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-002 Ensure Information Security Management Is Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-002.