CS-007
Third-party components are scanned for known vulnerabilities prior to release, with a defined remediation SLA.
Third-party components are scanned for known vulnerabilities prior to release, with a defined remediation SLA.
Application logs are retained for a minimum of 12 months and are tamper-evident, supporting incident detection and analysis.
A documented and tested business continuity plan exists for the application.
Data in transit between application tiers is encrypted using TLS 1.2 or higher.
Data at rest containing personal or business-critical data is encrypted using an approved algorithm.
All privileged accounts are reviewed for continued necessity at least quarterly.
Access to production systems requires multi-factor authentication.