PDF Source Sections
- Section 8 (Security & Risk Management), Section 13.4.2 (Technical and Organizational Security Measures)
Objective
Ensure personal data has proportionate security, authorized access and timely, evidence-based incident response.
Control Activity
Technology and Compliance review sensitive-data access and security monitoring periodically and jointly assess privacy consequences, notification duties and remediation for material data incidents. The review verifies that: the eight technical, organizational, and procedural measures from Section 8 are implemented (encryption in transit and at rest, role-based access controls, secure authentication, system logging and monitoring, segregation of duties where appropriate, periodic review of access rights, secure storage and transmission of screening and case-management records, incident escalation and breach handling procedures); the Section 13.4.2 additional safeguards are in place (multi-factor authentication for privileged users, restricted access to AML/CFT and transaction data, outsourced vulnerability testing to certified third parties) with controls proportionate to system criticality and data sensitivity; access to sanctions screening, internal compliance escalations, wallet identifiers, transaction monitoring, and regulatory reporting data is restricted strictly to those with an operational, legal, or control need to know per Section 8; and false positives, alerts, case notes, escalation rationale, restrictive measures, UTR records, and related supporting documentation are handled with heightened confidentiality and control per Section 8.
Evidence
- Expected evidence: Security configuration verifying all eight Section 8 measures and Section 13.4.2 additional safeguards (MFA, restricted AML/CFT access, outsourced vulnerability testing)
- Expected evidence: Periodic access reviews and logs verifying need-to-know restriction for compliance-sensitive records per Section 8
- Expected evidence: Incident triage, assessment and escalation with heightened confidentiality for compliance-sensitive records (false positives, alerts, case notes, escalation rationale, UTR records) per Section 8
- Expected evidence: Notifications, remediation and closure evidence
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample sensitive systems, access and incidents for all eight Section 8 measures, Section 13.4.2 additional safeguards (MFA, vulnerability testing), approved need-to-know access, heightened confidentiality for compliance-sensitive records, logging, timely assessment, notification decision and verified remediation
- Testing frequency: quarterly access review and per material incident
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-28: Enriched with verification requirements from PDF sections 8 and 13.4.2 — added all eight Section 8 security measures, MFA for privileged users, outsourced vulnerability testing, compliance-sensitive record handling, and need-to-know access restriction.
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.