Objective
Ensure the information security management framework remains current, risk-based and reviewable. Bitkaya applies information security controls to all critical business and control systems, including platforms and tools used for client onboarding, sanctions screening, transaction monitoring, compliance case handling, and regulatory support.
Control Activity
Review security ownership, risk assessment, monitoring and incident handling evidence. Verify security controls ensure: confidentiality of client and compliance-sensitive data; integrity of screening and monitoring outputs; secure authentication and access management; protection against unauthorized alteration of rules, settings, or workflows; logging and traceability of system use and key actions; and resilience against cyber threats and operational misuse. Confirm that access to compliance systems containing screening results, internal classifications, escalation notes, UTR-related materials, and legally sensitive information is tightly controlled and logged. Verify ISM principles are CBCS-aligned and proportionate to Bitkaya’s startup profile, focusing on essential ISO 27001 control areas (access control, encryption, incident management). Confirm security measures emphasize protection of private keys, wallet infrastructure, and client data through multi-factor authentication, hardware keys, and encrypted storage. Where non-core technical services are outsourced (penetration testing, vulnerability scanning), verify reliance on certified providers with vendor oversight. Confirm policies, standards, and training cover all mandatory CBCS ISM objectives for confidentiality, integrity, and availability. Escalate unresolved security weaknesses and retain proof of follow-up and closure.
Evidence
- Expected evidence: security risk assessment
- Expected evidence: monitoring or incident record
- Expected evidence: access control and logging evidence for compliance-sensitive systems (screening results, internal classifications, escalation notes, UTR-related materials, legally sensitive information)
- Expected evidence: vendor oversight record for outsourced security services (penetration testing, vulnerability scanning)
- Expected evidence: training or privacy record where relevant
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample security updates and confirm assessment, monitoring and escalation evidence exists. Verify access to compliance systems is tightly controlled and logged. Confirm MFA, hardware keys, and encrypted storage are in place for private keys, wallet infrastructure, and client data.
- Testing frequency: annual and after material security event
Relationships
- Requirement: REQ-IT-002 Maintain Information Security Management
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-002 Maintain Information Security Management
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-002.