Frameworks supported
Kovira ships with a built-in compliance dashboard. Procurement teams use this catalogue to confirm coverage before signing. Tenants map each control to platform features and collect evidence (manual or automatic) directly from their own audit log, vault, change history, and access configuration.
ISO/IEC 27001 Annex A
ISO/IEC 27001:2022 Annex A information security controls catalogue.
A.5 Organisational Controls
- A.5.1 Policies for information security
Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and interested parties, and reviewed at planned intervals.
- A.5.14 Information transfer
Information transfer rules, procedures, and agreements shall be in place for all types of transfer facilities within the organisation and between the organisation and other parties.
- A.5.15 Access control
Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
- A.5.16 Identity management
The full life cycle of identities shall be managed.
- A.5.17 Authentication information
Allocation and management of authentication information shall be controlled by a management process, including advising personnel on the appropriate handling of authentication information.
- A.5.18 Access rights
Access rights to information and other associated assets shall be provisioned, reviewed, modified, and removed in accordance with the topic-specific policy on access control.
- A.5.23 Information security for use of cloud services
Processes for acquisition, use, management, and exit from cloud services shall be established in accordance with the organisation's information security requirements.
- A.5.30 ICT readiness for business continuity
ICT readiness shall be planned, implemented, maintained, and tested based on business continuity objectives and ICT continuity requirements.
A.6 People Controls
- A.6.3 Information security awareness, education and training
Personnel of the organisation and relevant interested parties shall receive appropriate information security awareness, education, and training and regular updates of the organisation's information security policy.
- A.6.7 Remote working
Security measures shall be implemented when personnel work remotely to protect information accessed, processed, or stored outside the organisation's premises.
A.8 Technological Controls
- A.8.2 Privileged access rights
The allocation and use of privileged access rights shall be restricted and managed.
- A.8.5 Secure authentication
Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.
- A.8.7 Protection against malware
Protection against malware shall be implemented and supported by appropriate user awareness.
- A.8.10 Information deletion
Information stored in information systems, devices, or in any other storage media shall be deleted when no longer required.
- A.8.13 Information backup
Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
- A.8.15 Logging
Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected, and analysed.
- A.8.16 Monitoring activities
Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
- A.8.17 Clock synchronisation
The clocks of information processing systems used by the organisation shall be synchronised to approved time sources.
- A.8.20 Networks security
Networks and network devices shall be secured, managed, and controlled to protect information in systems and applications.
- A.8.21 Security of network services
Security mechanisms, service levels, and service requirements of network services shall be identified, implemented, and monitored.
- A.8.24 Use of cryptography
Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.
- A.8.25 Secure development life cycle
Rules for the secure development of software and systems shall be established and applied.
- A.8.26 Application security requirements
Information security requirements shall be identified, specified, and approved when developing or acquiring applications.
- A.8.28 Secure coding
Secure coding principles shall be applied to software development.
- A.8.32 Change management
Changes to information processing facilities and information systems shall be subject to change management procedures.
SOC 2 Trust Services Criteria
AICPA Trust Services Criteria covering Security (Common Criteria CC1-CC9), Availability (A), Confidentiality (C), and Privacy (P).
CC1 Control Environment
- CC1.1 Commitment to integrity and ethical values
The entity demonstrates a commitment to integrity and ethical values that supports the functioning of the system of internal control.
- CC1.4 Attracts, develops, and retains competent personnel
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
CC2 Communication and Information
- CC2.1 Quality information for internal control
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
- CC2.2 Internal communication of objectives and responsibilities
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support its functioning.
CC3 Risk Assessment
- CC3.2 Identifies and assesses risk
The entity identifies risks to the achievement of its objectives across the entity and analyses risks as a basis for determining how the risks should be managed.
- CC3.4 Assessment of changes
The entity identifies and assesses changes that could significantly impact the system of internal control.
CC4 Monitoring Activities
- CC4.1 Ongoing and separate monitoring evaluations
The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
CC5 Control Activities
- CC5.1 Selects and develops control activities
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
- CC5.2 Selects and develops general controls over technology
The entity selects and develops general control activities over technology to support the achievement of objectives.
CC6 Logical and Physical Access Controls
- CC6.1 Logical access controls
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.
- CC6.2 New user provisioning
Prior to issuing system credentials and granting system access, the entity registers and authorises new internal and external users whose access is administered by the entity.
- CC6.3 Removal of access
The entity authorises, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties.
- CC6.6 Transmission encryption
The entity implements logical access security measures to protect against threats from sources outside its system boundaries, including encryption of data in transit.
- CC6.7 Data-at-rest encryption and transmission integrity
The entity restricts the transmission, movement, and removal of information to authorised internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives. Includes encryption of data at rest.
- CC6.8 Prevention of unauthorised software
The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software to meet its objectives.
CC7 System Operations
- CC7.1 Detection and monitoring of new vulnerabilities
To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.
- CC7.2 Anomalies and security event detection
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analysed to determine whether they represent security events.
- CC7.3 Security incident response
The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.
- CC7.4 Incident remediation
The entity responds to identified security incidents by executing a defined incident response programme to understand, contain, remediate, and communicate security incidents, as appropriate.
- CC7.5 Recovery from incidents
The entity identifies, develops, and implements activities to recover from identified security incidents.
CC8 Change Management
- CC8.1 Change management
The entity authorises, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.
CC9 Risk Mitigation
- CC9.1 Risk mitigation activities
The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
- CC9.2 Vendor and business partner risk
The entity assesses and manages risks associated with vendors and business partners.
A1 Availability
- A1.1 Capacity planning
The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.
- A1.2 Environmental protection and backups
The entity authorises, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.
- A1.3 Recovery plan testing
The entity tests recovery plan procedures supporting system recovery to meet its objectives.
C1 Confidentiality
- C1.1 Identification and protection of confidential information
The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.
- C1.2 Disposal of confidential information
The entity disposes of confidential information to meet the entity's objectives related to confidentiality.
P1 Privacy Notice
- P1.1 Privacy notice
The entity provides notice to data subjects about its privacy practices to meet its objectives related to privacy.
P2 Choice and Consent
- P2.1 Privacy choice and consent
The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to data subjects, and obtains consent as required.
See the full Kovira security posture overview at /security.