Purpose
Translate the CBCS information security guidance into a testable BCMS requirement for a managed information security framework.
Normative
Bitkaya shall maintain an information security management framework that protects information assets, addresses confidentiality, integrity and availability, performs ongoing risk assessment, monitors security events, manages incidents and protects customer information.
Descriptive
This requirement reflects the information security guidance, including management oversight, framework design, risk assessment, monitoring, incident response, privacy, training and audit expectations.
Source reference: Provisions and Guidelines for Information Security Management.
Assurance Assertions
- Information security governance and risk management are documented.
- Security monitoring and incident handling are defined and reviewed.
- Customer information is protected under approved controls.
Relationships
- Source: SRC-IT-001 CBCS IT Governance, Security, Continuity and Testing Guidelines
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-002 Maintain Information Security Management
- Control: CTRL-IT-002 Ensure Information Security Management Is Maintained
- Systems: not yet assigned; tracked under ISS-COMP-001, ISS-TRAIN-001
- Publications: PUB-TRAIN-001 Compliance Framework Onboarding for New Employees, PUB-TRAIN-002 Compliance Department Training, PUB-TRAIN-005 IT Compliance Training
Assurance
- Source verified: yes
- Implementation linked: yes
- Wording unambiguous: review
History
- 2026-07-26: Created from SRC-IT-001.
- 2026-07-26: Linked to the IT process, procedure and control set.
- 2026-07-26: Added the missing IT policy metadata mapping.