A review inventory covering 93 Annex A control topics, plus related cloud and privacy areas. The rows identify evidence to collect, not independently accepted operating controls.
No certification, approved audit schedule or completed Statement of Applicability is established by this page.
The two frameworks are complementary, not redundant. Regional procurement requirements and buyer sophistication determine which frameworks matter most to a given reviewer.
Our dual-framework approach: We map our controls to both frameworks so a reviewer in any region can map us to their internal control framework. The underlying security controls are identical. This page and the SOC 2 self-attested page are two views of the same control inventory, written in the vocabulary each framework uses. Sources: ISO/IEC 27002:2022 and ISO/IEC 27001:2022.
ISO/IEC 27002:2022 reorganized the control framework from 14 domains (in the 2013 edition) to 4 themes covering all 93 controls. Source: ISO/IEC 27002:2022.
Review organizational scope, accountable owners and dated operating records. See the itemized evidence requests below.
Review people scope, accountable owners and dated operating records. See the itemized evidence requests below.
Review physical scope, accountable owners and dated operating records. See the itemized evidence requests below.
Review technological scope, accountable owners and dated operating records. See the itemized evidence requests below.
Control summaries are reviewer navigation, not the standard's exact text or an auditor's finding. Each row identifies a required check. Evidence open means that operating effectiveness or applicability has not been established in this review.
| Control | Title | ISO Description | Our Implementation | Status |
|---|---|---|---|---|
| A.5.1 | Policies for information security | Information security policy and topic-specific policies defined, approved by management, published, communicated, and reviewed at planned intervals. | Approve a versioned information-security policy and record review ownership. | Evidence open |
| A.5.2 | Information security roles and responsibilities | Information security roles and responsibilities defined and allocated according to the information security policy. | Name accountable security owners and accepted delegates. | Evidence open |
| A.5.3 | Segregation of duties | Conflicting duties and areas of responsibility segregated to reduce opportunities for unauthorized or unintentional modification or misuse. | Test non-founder administrative recovery and document conflicting duties. | Evidence open |
| A.5.4 | Management responsibilities | Management requires all personnel to apply information security in accordance with established policy and procedures. | Record management approval and periodic security review decisions. | Evidence open |
| A.5.5 | Contact with authorities | Appropriate contacts with relevant authorities maintained. | Maintain verified authority contacts and escalation criteria. | Evidence open |
| A.5.6 | Contact with special interest groups | Appropriate contacts with special interest groups or security forums maintained. | Document relevant security-community participation and responsible owner. | Evidence open |
| A.5.7 | Threat intelligence | Information relating to information security threats collected and analyzed to produce threat intelligence. | Retain threat-intelligence reviews and resulting remediation decisions. | Evidence open |
| A.5.8 | Information security in project management | Information security integrated into project management throughout the project lifecycle. | Attach security requirements and risk decisions to project records. | Evidence open |
| A.5.9 | Inventory of information and other associated assets | Inventory of information and other associated assets maintained and identified, with ownership established. | Reconcile the source/hosting inventory with credentials, data stores and owners. | Evidence open |
| A.5.10 | Acceptable use of information and other associated assets | Rules for acceptable use and procedures for handling information and other associated assets identified, documented, and implemented. | Approve acceptable-use rules and record acknowledgement. | Evidence open |
| A.5.11 | Return of assets | Personnel and other interested parties return all organizational assets upon change or termination of employment, contract, or agreement. | Track device return, access removal and custody on departure. | Evidence open |
| A.5.12 | Classification of information | Information classified according to information security needs based on confidentiality, integrity, availability, and relevant stakeholder requirements. | Classify payloads, receipt metadata, identifiers, telemetry and exports separately. | Evidence open |
| A.5.13 | Labelling of information | Appropriate set of procedures for information labelling developed and implemented in accordance with the information classification scheme. | Verify sensitivity labels across receipt, log and export schemas. | Evidence open |
| A.5.14 | Information transfer | Formal transfer policies, procedures, and controls in place to protect information transferred within the organization and to external parties. | Test transport for edge, origin and outbound calls; the legacy IP lookup uses HTTP. | Evidence open |
| A.5.15 | Access control | Rules to control physical and logical access to information and other associated assets established and implemented. | Review deployed authorization, administrator membership and least privilege. | Evidence open |
| A.5.16 | Identity management | Full lifecycle of identities managed. Identities uniquely assigned. Shared identities prohibited except when approved and documented. | Reconcile identity lifecycle and service-account ownership. | Evidence open |
| A.5.17 | Authentication information | Allocation and management of authentication information controlled by a management process. | Application signing keys enter process memory; no KMS custody is established. | Evidence open |
| A.5.18 | Access rights | Access rights to information and other associated assets provisioned, reviewed, modified, and removed following access control policy. | Record access approvals, review decisions and deprovisioning tests. | Evidence open |
| A.5.19 | Information security in supplier relationships | Processes and procedures defined and implemented to manage information security risks associated with use of supplier products or services. | Confirm the complete processor inventory and supplier risk assessments. | Evidence open |
| A.5.20 | Addressing security in supplier agreements | Relevant security requirements established and agreed with each supplier based on the type of supplier relationship. | Obtain executed agreements, data roles and service-specific transfer terms. | Evidence open |
| A.5.21 | Managing security in the ICT supply chain | Processes and procedures defined and implemented to manage information security risks associated with ICT products and services supply chain. | Review dependencies, build provenance and supplier change risks. | Evidence open |
| A.5.22 | Monitoring, review and change management of supplier services | Organization regularly monitors, reviews and manages changes to supplier services. | Retain supplier monitoring results and approved change decisions. | Evidence open |
| A.5.23 | Information security for use of cloud services | Processes for acquisition, use, management, and exit from cloud services established in accordance with information security requirements. | Four reviewed Render services use Oregon compute; storage and edge differ. | Evidence open |
| A.5.24 | Information security incident management planning and preparation | Organization plans and prepares for managing information security incidents by defining incident management processes, roles, and responsibilities. | Approve the incident outline, contacts and notification decision process. | Evidence open |
| A.5.25 | Assessment and decision on information security events | Organization assesses information security events and decides if they are classified as incidents. | Define incident severity criteria and retain triage decisions. | Evidence open |
| A.5.26 | Response to information security incidents | Information security incidents responded to in accordance with documented procedures. | Exercise response actions and notification delivery against agreed commitments. | Evidence open |
| A.5.27 | Learning from information security incidents | Knowledge gained from information security incidents used to strengthen and improve security controls. | Record root causes, corrective actions and approved follow-up dates. | Evidence open |
| A.5.28 | Collection of evidence | Organization establishes and implements procedures for identification, collection, acquisition and preservation of evidence. | Define evidence custody, integrity checks and lawful collection limits. | Evidence open |
| A.5.29 | Information security during disruption | Organization plans how to maintain information security at an appropriate level during disruption. | Verify access and security controls during a founder-unavailability drill. | Evidence open |
| A.5.30 | ICT readiness for business continuity | ICT readiness planned, implemented, maintained, and tested based on business continuity objectives and ICT continuity requirements. | Document recovery objectives and test restoration with retained evidence. | Evidence open |
| A.5.31 | Legal, statutory, regulatory, and contractual requirements | Legal, statutory, regulatory, and contractual requirements relevant to information security identified, documented, and kept up to date. | Verify entity, applicable laws, contracts and approved retention schedules. | Evidence open |
| A.5.32 | Intellectual property rights | Organization implements appropriate procedures to protect intellectual property rights. | Maintain license obligations and signed intellectual-property assignments. | Evidence open |
| A.5.33 | Protection of records | Records protected from loss, destruction, falsification, unauthorized access, and unauthorized release in accordance with legal, regulatory, contractual, and business requirements. | Identify authoritative stores, replica handling and backup protection. | Evidence open |
| A.5.34 | Privacy and protection of personally identifiable information | Organization identifies and meets requirements for preserving privacy and protection of PII according to applicable laws and regulations. | Carnac processes text; site telemetry includes identifiers and browsing metadata. | Evidence open |
| A.5.35 | Independent review of information security | Organization's approach to managing information security and its implementation reviewed independently at planned intervals or when significant changes occur. | No independent audit report or executed engagement was supplied. | Evidence open |
| A.5.36 | Compliance with policies, rules, and standards for information security | Compliance with information security policies, rules, and standards regularly reviewed and, if necessary, corrective actions taken. | Collect policy-compliance checks, exceptions and corrective-action records. | Evidence open |
| A.5.37 | Documented operating procedures | Operating procedures for information processing facilities documented and made available to personnel who need them. | Approve operating procedures and demonstrate that delegates can execute them. | Evidence open |
| Control | Title | ISO Description | Our Implementation | Status |
|---|---|---|---|---|
| A.6.1 | Screening | Background verification checks carried out on all candidates for employment and contractors prior to engagement, proportional to role and risk. | Verify screening scope and records for authorized personnel. | Evidence open |
| A.6.2 | Terms and conditions of employment | Employment contractual agreements state personnel's and organization's responsibilities for information security. | Obtain accepted employment or contractor security obligations. | Evidence open |
| A.6.3 | Information security awareness, education, and training | Personnel and relevant interested parties receive appropriate information security awareness, education, and training. | Retain training completion records and role-specific security instruction. | Evidence open |
| A.6.4 | Disciplinary process | Formal and communicated disciplinary process in place to take action against personnel who have committed an information security policy violation. | Approve the personnel policy and its applicable escalation process. | Evidence open |
| A.6.5 | Responsibilities after termination or change of employment | Information security responsibilities and duties that remain valid after termination or change of employment defined, communicated, and enforced. | Verify post-termination duties and tested access revocation. | Evidence open |
| A.6.6 | Confidentiality or non-disclosure agreements | Confidentiality or NDA requirements reflecting the organization's needs for protection of information identified, documented, reviewed regularly, and signed by personnel and other interested parties. | Review executed confidentiality agreements and their coverage. | Evidence open |
| A.6.7 | Remote working | Security measures implemented when personnel work remotely to protect information accessed, processed, or stored outside the organization's premises. | Assess workstation, network and remote-access configurations. | Evidence open |
| A.6.8 | Information security event reporting | Organization provides a mechanism for personnel to report observed or suspected information security events through appropriate channels and in a timely manner. | Test event-reporting channels and record escalation ownership. | Evidence open |
| Control | Title | ISO Description | Our Implementation | Status |
|---|---|---|---|---|
| A.7.1 | Physical security perimeters | Security perimeters defined and used to protect areas containing information and other associated assets. | Document workstation and hosting physical-security responsibility boundaries. | Evidence open |
| A.7.2 | Physical entry | Secure areas protected by appropriate entry controls and access points. | Verify authorized physical entry arrangements within Hive's own scope. | Evidence open |
| A.7.3 | Securing offices, rooms, and facilities | Physical security designed and applied to offices, rooms, and facilities. | Assess office equipment and workspace protection. | Evidence open |
| A.7.4 | Physical security monitoring | Premises monitored continuously for unauthorized physical access. | Confirm monitoring scope without publishing private location details. | Evidence open |
| A.7.5 | Protecting against physical and environmental threats | Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats, designed and implemented. | Collect environmental protection and power-continuity test records. | Evidence open |
| A.7.6 | Working in secure areas | Security measures for working in secure areas designed and implemented. | Document secure-work-area practices and permitted access. | Evidence open |
| A.7.7 | Clear desk and clear screen | Clear desk rules applied to papers and removable storage media, and clear screen rules applied to information processing facilities. | Verify clear-screen and unattended-device controls. | Evidence open |
| A.7.8 | Equipment siting and protection | Equipment sited securely and protected. | Assess equipment placement and protection against loss or damage. | Evidence open |
| A.7.9 | Security of assets off-premises | Off-premises assets protected. | Verify device encryption, remote recovery and off-premises custody. | Evidence open |
| A.7.10 | Storage media | Storage media managed through its full life cycle of acquisition, use, transportation, and disposal according to classification scheme and handling requirements. | Inventory removable media and approved handling/disposal methods. | Evidence open |
| A.7.11 | Supporting utilities | Information processing facilities protected from failures in supporting utilities. | Document utility dependencies and tested backup arrangements. | Evidence open |
| A.7.12 | Cabling security | Cables carrying power, data, or supporting information services protected from interception, interference, or damage. | Assess cabling protection within the operating scope. | Evidence open |
| A.7.13 | Equipment maintenance | Equipment maintained correctly to ensure continued availability and integrity. | Record maintenance authority, service access and return checks. | Evidence open |
| A.7.14 | Secure disposal or re-use of equipment | Items of equipment containing storage media verified to ensure sensitive data and licensed software removed or securely overwritten prior to disposal or re-use. | Require disposal records and verification of approved sanitization. | Evidence open |
| Control | Title | ISO Description | Our Implementation | Status |
|---|---|---|---|---|
| A.8.1 | User endpoint devices | Information stored on, processed by, or accessible via user endpoint devices protected. | Verify device encryption, patching, malware protection and inventory. | Evidence open |
| A.8.2 | Privileged access rights | Allocation and use of privileged access rights restricted and managed. | Check administrator MFA and access membership for each active platform. | Evidence open |
| A.8.3 | Information access restriction | Access to information and application system functions restricted in accordance with the access control policy. | Test tenant binding and object-level authorization across endpoints. | Evidence open |
| A.8.4 | Access to source code | Read and write access to source code, development tools, and software libraries managed appropriately to prevent unauthorized changes. | Review repository permissions and accepted change-review rules. | Evidence open |
| A.8.5 | Secure authentication | Secure authentication technologies and procedures implemented based on information access restrictions. | Test each authentication path and service credential lifecycle. | Evidence open |
| A.8.6 | Capacity management | Use of resources monitored and adjusted in line with current and expected capacity requirements. | Measure capacity, saturation alerts and service-specific limits. | Evidence open |
| A.8.7 | Protection against malware | Protection against malware implemented and supported by appropriate user awareness. | Collect endpoint protection configuration and update records. | Evidence open |
| A.8.8 | Management of technical vulnerabilities | Information about technical vulnerabilities of information systems obtained in a timely manner; exposure evaluated; appropriate measures taken. | Record vulnerability reviews, remediation and exception ownership. | Evidence open |
| A.8.9 | Configuration management | Configurations (including security configurations) of hardware, software, services, and networks established, documented, implemented, monitored, and reviewed. | Reconcile deployed settings with reviewed configuration baselines. | Evidence open |
| A.8.10 | Information deletion | Information stored in information systems, devices, or other storage media deleted when no longer required. | Approve class-specific deletion methods; signed statements do not prove all-copy erasure. | Evidence open |
| A.8.11 | Data masking | Data masking used in accordance with the organization's topic-specific policy on access control and other related policies and business requirements, with applicable legislation. | Test masking of identifiers, submitted text and upstream error details. | Evidence open |
| A.8.12 | Data leakage prevention | Data leakage prevention measures applied to systems, networks, and other devices that process, store, or transmit sensitive information. | Review payload egress, telemetry fields and export authorization. | Evidence open |
| A.8.13 | Information backup | Backup copies of information, software, and systems maintained and tested regularly in accordance with the agreed backup policy. | No approved backup schedule or restoration test was supplied. | Evidence open |
| A.8.14 | Redundancy of information processing facilities | Information processing facilities implemented with redundancy sufficient to meet availability requirements. | One countersigner worker has a persistent disk; failover is not established. | Evidence open |
| A.8.15 | Logging | Logs recording activities, exceptions, faults, and other relevant events produced, stored, protected, and analyzed. | Site/legacy telemetry includes personal data; review log fields and retention. | Evidence open |
| A.8.16 | Monitoring activities | Networks, systems, and applications monitored for anomalous behavior; appropriate actions taken to evaluate potential information security incidents. | Test alert rules, recipient delivery and coverage gaps. | Evidence open |
| A.8.17 | Clock synchronization | Clocks of information processing systems synchronized to approved time sources. | Verify clock configuration and measured timestamp accuracy. | Evidence open |
| A.8.18 | Use of privileged utility programs | Use of utility programs that might be capable of overriding system and application controls restricted and tightly controlled. | Review privileged tools, authorized operators and auditability. | Evidence open |
| A.8.19 | Installation of software on operational systems | Procedures and measures implemented to securely manage software installation on operational systems. | Review deployment permissions, immutable revision records and rollback tests. | Evidence open |
| A.8.20 | Networks security | Networks and network devices secured, managed, and controlled to protect information in systems and applications. | Test edge controls and direct-origin exposure. | Evidence open |
| A.8.21 | Security of network services | Security mechanisms, service levels, and service requirements of network services identified, implemented, and monitored. | Check per-host TLS, HSTS and outbound transport configuration. | Evidence open |
| A.8.22 | Segregation of networks | Groups of information services, users, and information systems segregated in networks. | Verify network separation and tenant isolation rather than assuming it. | Evidence open |
| A.8.23 | Web filtering | Access to external websites managed to reduce exposure to malicious content. | Review endpoint filtering needs and deployed coverage. | Evidence open |
| A.8.24 | Use of cryptography | Rules for effective use of cryptography, including cryptographic key management, defined and implemented. | Ed25519 and ML-DSA-65 paths are software signing; no applicable validation certificate supplied. | Evidence open |
| A.8.25 | Secure development lifecycle | Rules for secure development of software and systems established and applied. | Attach security review and test evidence to the actual release. | Evidence open |
| A.8.26 | Application security requirements | Information security requirements identified, specified, and approved when developing or acquiring applications. | Specify authentication, data handling and failure-state requirements per endpoint. | Evidence open |
| A.8.27 | Secure system architecture and engineering principles | Principles for engineering secure systems established, documented, maintained, and applied to any information system development and integration activities. | Review trust boundaries, stored data and fail-open behavior. | Evidence open |
| A.8.28 | Secure coding | Secure coding principles applied to software development. | Inspect injection, encoding, secret handling and dependency risks. | Evidence open |
| A.8.29 | Security testing in development and acceptance | Security testing processes defined and implemented in the development lifecycle. | Run scoped positive/negative tests and preserve results. | Evidence open |
| A.8.30 | Outsourced development | Organization supervises and monitors the activities related to outsourced system development. | Verify development agreements, access limits and code ownership. | Evidence open |
| A.8.31 | Separation of development, test, and production environments | Development, testing, and production environments separated and secured. | Inspect environment separation and use synthetic test data. | Evidence open |
| A.8.32 | Change management | Changes to information processing facilities and information systems subject to change management procedures. | Match approved changes to deployed revisions and rollback plans. | Evidence open |
| A.8.33 | Test information | Test information appropriately selected, protected, and managed. | Review test-data origin, access, retention and disposal. | Evidence open |
| A.8.34 | Protection of information systems during audit testing | Audit tests and other assurance activities involving assessment of operational systems planned and agreed upon to minimize disruptions to business processes. | Authorize audit scope and avoid live personal data or secret collection. | Evidence open |
The 93 Annex A topic rows cover organizational, people, physical and technological areas. Coverage in this table is not control acceptance or certification.
Cloud extensions organize the shared-responsibility review. Render compute is verified in Oregon for four services; edge, storage and processor scope differ. review evidence.
| Control | Title | Our Cloud Posture (Cloudflare + Render + AWS S3) | Status |
|---|---|---|---|
| CLD.6.3.1 | Shared roles & responsibilities | Allocate cloud security responsibilities in the actual agreement. | Evidence open |
| CLD.8.1.5 | Removal of cloud service customer assets | Approve deletion across cloud stores, replicas, backups and customer exports. | Evidence open |
| CLD.9.5.1 | Segregation in virtual computing environments | Test tenant isolation and provider-managed separation assumptions. | Evidence open |
| CLD.9.5.2 | Virtual machine hardening | Review runtime hardening and the provider/customer responsibility boundary. | Evidence open |
| CLD.12.1.5 | Administrator operational security | Verify cloud administrator access, MFA and audited recovery. | Evidence open |
| CLD.12.4.5 | Monitoring of cloud services | Collect cloud monitoring configuration and alert-delivery tests. | Evidence open |
| CLD.13.1.4 | Alignment of security management for virtual and physical networks | Assess edge, service origin and outbound network controls together. | Evidence open |
| CLD.6.3.1 (CSP) | Information security policy for cloud services | Approve the cloud-service security policy and data-handling scope. | Evidence open |
Privacy roles and applicable requirements depend on the contracting entity, service and agreement. This page does not establish ISO 27701 alignment. See the privacy notice.
Identify necessary fields and permitted purposes for each endpoint. Carnac receives readable request/output text; hashing-only paths differ.
Rights requests require identity checks and an applicable-law review. The privacy notice distinguishes GDPR response timing from general service targets.
Verify controller/processor roles and executed processing agreements for the relevant entity and customer.
Do not assume hashes-only storage or PII-free logs. Review classification metadata, telemetry, inspection records, backups and exports separately.
Verify processor agreements, onward recipients, regions and customer notice terms.
Assess whether a privacy impact review or DPIA is required and retain the decision and mitigation evidence.
Supplier assurance remains a review task, not a completed alignment claim. Hosting and supplier scope.
Reconcile configured data paths with all active recipients and their approved purposes.
Collect supplier review records, current assurance reports and region/backup evidence.
Verify executed terms for incidents, audit rights, deletion, onward transfers and liability.
ISO/IEC 42001:2023 is the international standard for AI management systems (AIMS), published December 2023. It covers AI governance, risk management, and the responsible development and use of AI systems. Source: ISO/IEC 42001:2023.
Document AI system roles, model authority and human decision points. A multi-model design alone does not establish a management-system control.
Define the meaning and limitations of any provenance labels; test that receipt fields match the service output.
Review the actual model-provider path and data flow. Carnac's optional semantic reader uses a configured compute endpoint.
Verify review gates, exception handling and audit records. No ISO 42001 certification or approved completion date is established.
These technical review topics supplement the control inventory. They do not imply that an ISO certificate guarantees, excludes or validates any particular implementation.
The reviewed services do not all use hybrid signatures.
Ed25519 and ML-DSA-65 have separate service and verifier boundaries.
Typed API, receipt/Carnac and countersigner paths use Ed25519. The dedicated signer implements ML-DSA-65 in software.
signing boundaries. A self-test is not a CAVP or CMVP certificate.
Algorithm disclosure must identify the exact service, revision and signing path.
A standards name does not establish a validated module or protected key boundary.
Inspected keys enter application memory from environment values, local files or generated key material.
review evidence records the software custody matrix and remaining configuration checks.
No hardware entropy provenance or validated entropy-source evidence was supplied.
A software assertion about entropy is not a hardware attestation.
Key generation and entropy sources require per-path review, especially optional QPuF modes.
Do not infer NIST validation from metadata, algorithm labels or a self-test page.
Customer-held verification depends on the receipt format, verifier code and trusted issuer key.
Independent operation must be demonstrated without a required Hive lookup.
Retain signed bytes, dependencies, keys and any optional inclusion evidence before an outage.
Use the browser verifier only for its supported format and test dependencies.
Deployed source revisions were reviewed; that is not a SLSA level determination.
Source lineage is distinct from reproducible build and runtime integrity evidence.
No applicable build-level assessment or complete attestation chain was supplied.
Build provenance scope and acceptance tests remain to be established; earlier target dates are withdrawn.
Incident transparency requires an approved publication policy and actual records.
Contractual and legal notification obligations need case-specific review.
The security page contains an outline, not a verified five-day publication SLA.
A payment transaction is distinct from a receipt signature or evidence anchor.
Anchoring, if selected, needs a defined commitment, destination and verification method.
No promise is made that every receipt or commercial transaction is anchored.
Verify signature authenticity separately from payment or inclusion evidence; retain trusted keys and checkpoints.
A signed deletion record authenticates the signer's statement and identified scope.
It does not prove that all backups, replicas, caches or exports were removed.
No universal deletion endpoint, 72-hour all-copy guarantee or dual-signature deletion format is established.
retention inventory lists open schedule, hold, method and verification requirements.
A self-test exercises code; CAVP validates algorithm implementations and CMVP validates modules. No applicable Hive certificate was supplied.
| Standard | Name | Our Posture | Status |
|---|---|---|---|
| FIPS 140-3 | Cryptographic Module Validation | No applicable Hive module certificate, approved operating environment or validated custody boundary was supplied. | Not established |
| FIPS 203 | ML-KEM (Module-Lattice-Based KEM) | ML-KEM is key encapsulation, not signing. No deployment or approved migration date was established. | Not established |
| FIPS 204 | ML-DSA (Module-Lattice-Based DSA) | The dedicated signer implements ML-DSA-65 in application memory. Other reviewed signing services use Ed25519; no universal hybrid format. | Not established |
| FIPS 205 | SLH-DSA (SPHINCS+) | No deployed SLH-DSA path or approved adoption schedule was established. | Not established |
| NIST SP 800-90B | Entropy Source Validation | No applicable entropy-source validation report or certificate was supplied. | Not established |
| NIST SP 800-208 | Stateful Hash-Based Signatures (XMSS, LMS) | No deployed XMSS or LMS path was established; review state management before any adoption. | Not established |
This thematic cross-reference is a navigation aid, not equivalence, applicability approval or a substitute for an auditor's mapping.
| SOC 2 Criteria | SOC 2 Topic | ISO 27002:2022 Controls | Notes |
|---|---|---|---|
| CC6.1 | Logical and physical access controls | A.8.2 + A.8.3 + A.5.15 + A.5.16 + A.5.18 | Privileged access, information access restriction, access control policy, identity management, access rights |
| CC6.2 | Prior to issuance of system credentials and prior to user access | A.5.17 + A.5.16 + A.6.1 + A.6.2 | Authentication information management, identity management, screening, terms of employment |
| CC7.4 | Incident response | A.5.24 + A.5.25 + A.5.26 + A.5.27 + A.5.28 | Incident planning, event assessment, incident response, learning from incidents, evidence collection |
| CC8.1 | Change management | A.8.32 + A.8.19 + A.8.25 + A.8.31 | Change management, software installation, secure SDLC, separation of environments |
| CC9.1 | Vendor and business partner risk management | A.5.19 + A.5.20 + A.5.21 + A.5.22 | Supplier information security, supplier agreements, ICT supply chain, supplier monitoring |
| CC5.2 | Cryptographic controls | A.8.24 | Use of cryptography; algorithm policy, key management, rotation cadence |
| A1.2 | Availability: Recovery objectives | A.8.13 + A.8.14 + A.5.29 + A.5.30 | Backup, redundancy, security during disruption, ICT readiness for continuity |
| P4.1 | Privacy: Data subject rights | A.5.34 + ISO 27701 | PII protection mapped to ISO 27701 privacy extensions; data subject rights endpoints |
The table identifies records to request, not evidence already held or available under NDA. Public review observations are in the review evidence.
| Control | Evidence Type | Location / Description | Last Reviewed |
|---|---|---|---|
| A.5.1 | Policy document | Request policy document with scope, owner and dated results. Availability not verified. | Open |
| A.5.7 | Threat intel log | Request threat intel log with scope, owner and dated results. Availability not verified. | Open |
| A.5.9 | Asset register | Request asset register with scope, owner and dated results. Availability not verified. | Open |
| A.5.15 | Access matrix | Request access matrix with scope, owner and dated results. Availability not verified. | Open |
| A.5.17 | Credential policy | Request credential policy with scope, owner and dated results. Availability not verified. | Open |
| A.5.19 | Sub-processor DPAs | Request sub-processor dpas with scope, owner and dated results. Availability not verified. | Open |
| A.5.24 | IR Runbook | Request ir runbook with scope, owner and dated results. Availability not verified. | Open |
| A.5.28 | Evidence procedures | Request evidence procedures with scope, owner and dated results. Availability not verified. | Open |
| A.5.31 | Legal register | Request legal register with scope, owner and dated results. Availability not verified. | Open |
| A.5.35 | Audit engagement | Request audit engagement with scope, owner and dated results. Availability not verified. | Open |
| A.6.1 | Screening records | Request screening records with scope, owner and dated results. Availability not verified. | Open |
| A.6.2 | Contract templates | Request contract templates with scope, owner and dated results. Availability not verified. | Open |
| A.6.6 | NDA log | Request nda log with scope, owner and dated results. Availability not verified. | Open |
| A.7.5 | UPS receipt | Request ups receipt with scope, owner and dated results. Availability not verified. | Open |
| A.7.9 | MDM config | Request mdm config with scope, owner and dated results. Availability not verified. | Open |
| A.8.2 | FIDO2 config | Request fido2 config with scope, owner and dated results. Availability not verified. | Open |
| A.8.5 | Auth event log | Request auth event log with scope, owner and dated results. Availability not verified. | Open |
| A.8.7 | AV configuration | Request av configuration with scope, owner and dated results. Availability not verified. | Open |
| A.8.8 | Vuln records | Request vuln records with scope, owner and dated results. Availability not verified. | Open |
| A.8.13 | Backup log | Request backup log with scope, owner and dated results. Availability not verified. | Open |
| A.8.15 | Log samples | Request log samples with scope, owner and dated results. Availability not verified. | Open |
| A.8.19 | Deploy records | Request deploy records with scope, owner and dated results. Availability not verified. | Open |
| A.8.21 | HSTS + CSP | Request hsts + csp with scope, owner and dated results. Availability not verified. | Open |
| A.8.24 | ACVP results | Request acvp results with scope, owner and dated results. Availability not verified. | Open |
| A.8.25 | SAST results | Request sast results with scope, owner and dated results. Availability not verified. | Open |
| A.8.31 | Env separation | Request env separation with scope, owner and dated results. Availability not verified. | Open |
| B.1 | PQ implementation | Request pq implementation with scope, owner and dated results. Availability not verified. | Open |
| B.4 | Verifier code | Request verifier code with scope, owner and dated results. Availability not verified. | Open |
| B.7 | On-chain anchors | Request on-chain anchors with scope, owner and dated results. Availability not verified. | Open |
| B.8 | Deletion certs | Request deletion certs with scope, owner and dated results. Availability not verified. | Open |
Engagements, external assessments and dates require owner approval. No completed agreement or approved certification schedule was supplied.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.
Use this inventory to scope a review and request evidence. Decisions remain with the responsible reviewer and the applicable contract.
Use this inventory to identify the services and control records your review needs. It is not an independent assurance report.
Compare the evidence requests with your own requirements and separately determine applicability and acceptance.
Request the specific records and control IDs at security@thehiveryiq.com. Availability and delivery dates require confirmation.
Reference this page as a source-and-evidence review, not a certification or guarantee of operating effectiveness.
Request the control records you need or discuss the scope of a security review.
Document availability and review timing must be confirmed for the request.