OpenCase Logo

Compliance overview

Current compliance status across frameworks

Featured documents

Key security and compliance documentation

Information Security Policy
Access Control Policy
Incident Response Plan

Compliance Program

An overview of security controls in place

Access Control and Authorization

Access granting process used
Access management policy established
Employee access regularly reviewed
MFA required for critical services
Password management policy enforced
Password management policy established

Data Management and Protection

Data encrypted at rest
Data encrypted in-transit
Data inventory maintained
Data management and retention policy established

Disaster Recovery

Automated backups enabled
Business continuity and disaster recovery policy established
Data recovery process established
Disaster recovery plans tested
Recovery data isolated

Email Security

DMARC policy and verification used
Email settings block malicious content

Endpoint Security

Anti-malware deployed on end-user devices
Data encrypted on end-user devices

Infrastructure Security

Active discovery tools used
Administrator access restricted
Automated security scanning performed on infrastructure
Buckets not exposed publicly
Configuration management system established
Firewall restricts public access to infrastructure
Infrastructure changes logged
Infrastructure changes require review
Infrastructure deployed using an infrastructure-as-code tool
Production deployment access restricted
Unauthorized assets addressed and removed
Unique production database authentication enforced

Monitoring and Incident Response

Audit log management process maintained
Audit logs collected
Incident response policy established
Incident review process implemented
Infrastructure performance monitored
Log management used
Network infrastructure monitored

Organizational Security

Acceptable use policy established
Asset inventory maintained
Asset management policy established
Change management policy established
Changelog established and maintained
Code of conduct established
Company security commitments externally communicated
Data-flow diagrams maintained
External support resources available
Password manager used
Performance evaluations conducted
Physical access restricted
Policies signed by relevant personnel
Roles and responsibilities specified
Service description communicated
Software development lifecycle established
System changes externally communicated
System changes internally communicated

Risk Management

Risk management policy established
Vendor management program established

Vulnerability Management

Automated software patch management performed
Penetration testing findings remediated
Penetration testing performed within the last 12 months
Vulnerability management policy established

Have a security question?

Contact our security team or request our full compliance documentation.