Cybersecurity Infrastructure features explained
for Compliance and Risk Management
Every feature we track for Cybersecurity Infrastructure products, with a description of what each one means.
Application Security
Practices and tools to secure applications handling financial data, from development to deployment.
- API Security Tools
- Protects APIs from unauthorized access and attacks.
- Application Penetration Testing
- Regular testing of application defenses by ethical hackers.
- Code Review Automation
- Automated scanning and review of codebases for security issues.
- Dynamic Application Security Testing (DAST)
- Tests running applications for vulnerabilities.
- Sandboxing Capabilities
- Runs applications in isolated environments to limit possible attacks.
- Secure Coding Standards Enforcement
- Mandates use of published secure coding guidelines.
- Secure Software Development Lifecycle (SDLC)
- Integrates security checkpoints at each phase of application development.
- Security Configuration Management
- Ensures secure default configurations for all applications.
- Static Application Security Testing (SAST)
- Analyzes source code for vulnerabilities during development.
- Third-Party Library Scanning
- Checks for vulnerabilities in third-party dependencies.
- Vulnerability Patch Frequency
- How often identified vulnerabilities are patched.
- Web Application Firewall (WAF)
- Protects web applications from common threats (e.g., OWASP Top 10).
Authentication & Access Controls
Systems and processes for verifying user identities and controlling access to sensitive information.
- Account Lockout Mechanism
- Temporarily locks user accounts after a set number of failed login attempts.
- Adaptive Authentication
- Adjusts authentication requirements based on risk factors.
- Audit Logging of Access Attempts
- Maintains an immutable record of all access attempts.
- Device Authentication
- Restricts access based on registered devices.
- Granular Permissions
- Enables fine-tuned access controls down to module or record level.
- Multi-Factor Authentication (MFA)
- Requires more than one method of authentication to verify a user's identity.
- Password Policy Enforcement
- Enforces complexity, rotation, and reuse rules for passwords.
- Privileged Access Management
- Provides special controls for administrator or sensitive access.
- Role-Based Access Control (RBAC)
- Assigns system access based on user roles and responsibilities.
- Session Timeout
- Automates the termination of sessions after inactivity.
- Single Sign-On (SSO)
- Allows users to access multiple applications using one set of login credentials.
- Time-based Access Restrictions
- Limits system access to specific time windows.
- User Provisioning/Deprovisioning Automation
- Automates account creation and removal to prevent orphaned access.
Business Continuity and Disaster Recovery
Capabilities for maintaining and restoring business functions during and after unexpected disruptions.
- Alternate Communication Channels
- Provides backup communications (e.g., phone, messaging).
- Automated Backups
- Schedules and maintains regular data backups.
- Backup Frequency
- How often data backups are performed.
- Backup Retention Policy
- Policies for how long backups are retained.
- Data Center Redundancy
- Ensures backup systems are located geographically apart.
- Disaster Recovery Plan Documentation
- Maintains comprehensive documentation for recovery procedures.
- Failover Systems
- Automatic switching to redundant resources during outages.
- Ransomware Recovery Tools
- Capabilities to recover data in the event of ransomware attacks.
- Recovery Point Objective (RPO)
- Maximum allowable data loss measured in time.
- Recovery Time Objective (RTO)
- Maximum allowable downtime for critical systems.
- Tabletop Testing Frequency
- How often disaster recovery plans are tested via scenarios.
Compliance and Regulatory Controls
Measures ensuring adherence to legal and industry compliance standards in financial advisory.
- Audit-ready Reporting
- Generates reports immediately usable in compliance audits.
- Automated Compliance Monitoring
- Continuously checks systems for compliance with defined standards.
- Automated Incident Reporting
- Files regulatory notifications of security incidents per jurisdiction.
- Automated Regulatory Updates
- Monitors and integrates regulatory change notifications.
- Breach Notification Timeliness
- Average time from breach discovery to notification.
- Compliance Checklist Management
- Tracks and manages compliance requirements and status.
- Consent Management Tools
- Captures, manages, and documents client consent under CCPA/GDPR/etc.
- Data Subject Request Management
- Assists with requests under privacy laws (e.g., access, delete, rectify).
- GDPR Compliance
- Meets the General Data Protection Regulation requirements.
- PCI DSS Compliance
- Meets the Payment Card Industry Data Security Standards.
- Policy Management Tools
- Enables creation, approval, and enforcement of compliance policies.
- SOC 2 Reporting
- Supports System and Organization Controls (SOC) 2 compliance.
Data Encryption
Methods and policies that protect sensitive client and organizational data from unauthorized access.
- At-rest Encryption
- Ensures all stored data is encrypted on disk.
- Automatic Key Rotation
- Regular automatic change of encryption keys.
- Database Encryption
- Encrypts entire databases or selected fields.
- Encrypted Backups
- Ensures all backup data is also encrypted.
- Encryption Algorithm Strength
- Bit length or standard of encryption (e.g., AES-256).
- Encryption Policy Management
- Defines and enforces data encryption standards.
- End-to-End Encryption
- Secures data from the origin to the intended recipient.
- Hardware Security Module (HSM) Integration
- Leverages physical devices for additional encryption security.
- In-transit Encryption
- Encrypts data as it travels across networks.
- Key Management System
- Manages and rotates cryptographic keys securely.
- Pseudonymization Options
- Enables privacy-preserving techniques alongside encryption.
- Regulatory-Compliant Encryption
- Aligns with PCI DSS, GDPR, and similar standards.
- Tokenization Support
- Replaces sensitive data with non-sensitive placeholders.
Endpoint Security
Technologies that protect laptops, desktops, and mobile devices used to access sensitive financial data.
- Antivirus & Antimalware
- Detects and removes malicious software from endpoints.
- Application Whitelisting/Blacklisting
- Restricts which applications can run on endpoints.
- Browser Security Controls
- Secures web browsing on endpoints.
- Device Encryption
- Encrypts hard drives and storage on endpoints.
- Endpoint Detection and Response (EDR)
- Monitors endpoints for suspicious activity to respond rapidly to incidents.
- Endpoint Health Checks
- Ensures only compliant endpoints can access network resources.
- Mobile Device Management (MDM)
- Centralizes control and monitoring of mobile endpoints.
- Patch Management Automation
- Automates installation of software security patches.
- Phishing Protection
- Detects and blocks phishing attempts delivered to endpoints.
- Real-time Threat Monitoring
- Provides continuous monitoring for endpoint threats.
- Remote Device Wipe
- Allows administrators to erase sensitive data from lost/stolen devices.
- USB/Peripheral Control
- Restricts use of removable storage and peripheral devices.
Network Security
Measures and systems to protect computer networks from unauthorized access, misuse, or theft.
- Automated Threat Blocking
- Ability to automatically block threats detected on the network.
- DDoS Protection
- Protects networks and services against Distributed Denial of Service attacks.
- DNS Filtering
- Prevents access to malicious domains and controls web access.
- Firewall Protection
- Implements barriers between trusted and untrusted networks to control traffic.
- Intrusion Detection System (IDS)
- Monitors network traffic for suspicious activity and potential threats.
- Intrusion Prevention System (IPS)
- Actively prevents network threats identified by monitoring systems.
- Logging and Audit Trails
- Maintains detailed logs of network activity for forensic analysis.
- Network Access Control (NAC)
- Restricts device and user access based on compliance with policies.
- Network Monitoring Frequency
- How frequently the network is actively monitored for threats.
- Network Segmentation
- Divides networks into segments to restrict access and reduce attack surfaces.
- Secure VPN Access
- Allows remote users secure and encrypted access to internal systems.
- Traffic Encryption
- Encrypts data communicated within and between networks.
- Wireless Security Controls
- Protects wireless communications via protocols and strong authentication.
- Zero Trust Network Architecture
- Reduces reliance on perimeter security by enforcing strict access controls everywhere.
Physical Security
Onsite measures and technologies that safeguard hardware, facilities, and physical access to data.
- Access Control Systems
- Restricts physical access to authorized personnel only.
- Alarm Systems
- Detects and alerts to unauthorized entry or incidents.
- Biometric Access Controls
- Uses fingerprints or facial recognition to authorize personnel.
- Environment Monitoring
- Detects fire, water, or temperature threats to IT environments.
- Equipment Disposal Procedures
- Ensures secure destruction or wiping of retired equipment.
- Onsite Security Staffing
- Employs dedicated personnel for facility security.
- Physical Asset Tagging
- Tags and inventories critical devices for monitoring.
- Physical Penetration Testing
- Regularly tests the effectiveness of physical security defenses.
- Secure Area Designation
- Defines and enforces areas with restricted access.
- Security Surveillance Cameras
- Monitors facilities with video recording for incident review.
- Visitor Log Management
- Tracks all external personnel entering secure areas.
Security Awareness and Training
Programs and systems for educating staff about cyber risks and proper security protocols.
- Customizable Training Content
- Adapts content to organization roles and needs.
- Executive & Board Training Programs
- Tailored programs for senior leadership.
- Incident Response Training
- Teaches staff their responsibilities in event of breach.
- Knowledge Assessment Quizzes
- Tests user retention and comprehension after training.
- Mandatory Security Training
- All staff must complete initial and periodic security training.
- Multilingual Training Support
- Offers content in multiple languages.
- Phishing Simulation Exercises
- Regular simulated attacks to train staff in recognizing threats.
- Security Policy Acknowledgement
- Staff must confirm understanding/compliance with policies.
- Social Engineering Awareness
- Includes modules on social engineering tactics and response.
- Training Completion Tracking
- Monitors which users have completed required courses.
- Training Frequency
- How often training must be renewed.
User Monitoring and Incident Detection
Tools and procedures for tracking user activity and rapidly detecting incidents or breaches.
- Alert Resolution Time
- Average time to resolve security alerts.
- Anomaly Detection Algorithms
- Uses machine learning or heuristics to spot unusual behavior.
- Automated Incident Response
- Initiates response playbooks or actions upon detection.
- Data Loss Prevention (DLP)
- Monitors for, and prevents, the unauthorized movement of sensitive data.
- Privilege Escalation Detection
- Detects when a user tries to gain unauthorized access.
- Real-time Alerting
- Notifies security teams instantly of potential security incidents.
- Reporting Dashboard
- Provides graphical reports and summaries of user and incident data.
- Security Information and Event Management (SIEM)
- Centralizes analysis of security events and alerts.
- Session Recording
- Captures user sessions for review and auditing.
- User Activity Logging
- Records all user actions on sensitive systems.
- User Behavior Analytics (UBA)
- Analyzes statistical user behavior to find security issues.
Vendor and Third-Party Risk Management
Processes and controls for managing risks introduced by external partners and service providers.
- Continuous Vendor Monitoring
- Regularly reviews vendors for changing risk.
- Contractual Security Clauses
- Mandates specific security obligations in contracts.
- Data Sharing Agreements
- Specifies how client data is shared, used, and protected.
- Due Diligence Documentation Retention
- How long vendor risk assessment records are kept.
- Fourth-Party Risk Visibility
- Tracks risk due to your vendors’ suppliers.
- Integration Security Testing
- Validates the security of vendor software/API integrations.
- Shared Responsibility Matrix
- Defines security responsibilities among parties.
- Third-Party Security Assessments
- Evaluates vendors’ security postures before partnership.
- Vendor Breach Notification Time
- Time required for vendors to disclose breaches.
- Vendor Onboarding Controls
- Standard procedures to ensure secure onboarding.