Objective
Ensure custody systems, access, keys, logs, backups and recovery protect client assets from unauthorized access, tampering, misuse and loss. Technology safeguards must prevent unauthorized access, tampering, misuse, or loss involving client assets and related operational records.
Control Activity
Technology maintains secure authentication, role-based access restrictions, least privilege, privileged access control, protected key and wallet administration, secure logging and auditability, backup and recovery capability, and resilience and incident-response arrangements for safeguarding systems supporting custody, wallet administration, payment processing, reconciliation, and linked compliance controls. Where compliance-related controls are embedded in asset movement workflows, the integrity of those controls is also protected. Periodic user and privileged access reviews remove unnecessary access. Recovery and access continuity are tested before relying on the arrangement.
Verification Requirements
- Verify that an inventory of safeguarding systems, accounts, wallets, keys, privileged roles and integrations is maintained.
- Verify that secure authentication is applied to all safeguarding systems.
- Verify that role-based access restrictions and least privilege are enforced.
- Verify that privileged access control protects high-risk administrative functions.
- Verify that key generation, storage, use, backup, rotation, recovery and destruction are protected, with protected key and wallet administration.
- Verify that secure logging and auditability are implemented, with access, configuration, authorization and asset-movement events logged securely and material anomalies reviewed.
- Verify that periodic user and privileged access reviews are performed and unnecessary access is promptly removed.
- Verify that the integrity of embedded screening, restriction and approval controls is protected, including where compliance-related controls are embedded in asset movement workflows.
- Verify that backup and recovery capability, redundancy, and resilience and incident-response arrangements are maintained.
- Verify that recovery and access continuity are tested and failures are remediated before relying on the arrangement.
Evidence
- Expected evidence: System, wallet, key and privileged-access inventory
- Expected evidence: Access approvals and periodic reviews
- Expected evidence: Key-management and event logs
- Expected evidence: Backup, recovery and incident tests
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample access and key controls and inspect recovery-test results and remediation
- Testing frequency: continuous logging, periodic access review and scheduled recovery testing
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved SAFU Manual.