Frameworks supported

Kovira ships with a built-in compliance dashboard. Procurement teams use this catalogue to confirm coverage before signing. Tenants map each control to platform features and collect evidence (manual or automatic) directly from their own audit log, vault, change history, and access configuration.

ISO/IEC 27001 Annex A

ISO · v2022 · 25 controls

ISO/IEC 27001:2022 Annex A information security controls catalogue.

A.5 Organisational Controls

  • A.5.1 Policies for information security

    Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and interested parties, and reviewed at planned intervals.

  • A.5.14 Information transfer

    Information transfer rules, procedures, and agreements shall be in place for all types of transfer facilities within the organisation and between the organisation and other parties.

  • A.5.15 Access control

    Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.

  • A.5.16 Identity management

    The full life cycle of identities shall be managed.

  • A.5.17 Authentication information

    Allocation and management of authentication information shall be controlled by a management process, including advising personnel on the appropriate handling of authentication information.

  • A.5.18 Access rights

    Access rights to information and other associated assets shall be provisioned, reviewed, modified, and removed in accordance with the topic-specific policy on access control.

  • A.5.23 Information security for use of cloud services

    Processes for acquisition, use, management, and exit from cloud services shall be established in accordance with the organisation's information security requirements.

  • A.5.30 ICT readiness for business continuity

    ICT readiness shall be planned, implemented, maintained, and tested based on business continuity objectives and ICT continuity requirements.

A.6 People Controls

  • A.6.3 Information security awareness, education and training

    Personnel of the organisation and relevant interested parties shall receive appropriate information security awareness, education, and training and regular updates of the organisation's information security policy.

  • A.6.7 Remote working

    Security measures shall be implemented when personnel work remotely to protect information accessed, processed, or stored outside the organisation's premises.

A.8 Technological Controls

  • A.8.2 Privileged access rights

    The allocation and use of privileged access rights shall be restricted and managed.

  • A.8.5 Secure authentication

    Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.

  • A.8.7 Protection against malware

    Protection against malware shall be implemented and supported by appropriate user awareness.

  • A.8.10 Information deletion

    Information stored in information systems, devices, or in any other storage media shall be deleted when no longer required.

  • A.8.13 Information backup

    Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.

  • A.8.15 Logging

    Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected, and analysed.

  • A.8.16 Monitoring activities

    Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.

  • A.8.17 Clock synchronisation

    The clocks of information processing systems used by the organisation shall be synchronised to approved time sources.

  • A.8.20 Networks security

    Networks and network devices shall be secured, managed, and controlled to protect information in systems and applications.

  • A.8.21 Security of network services

    Security mechanisms, service levels, and service requirements of network services shall be identified, implemented, and monitored.

  • A.8.24 Use of cryptography

    Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.

  • A.8.25 Secure development life cycle

    Rules for the secure development of software and systems shall be established and applied.

  • A.8.26 Application security requirements

    Information security requirements shall be identified, specified, and approved when developing or acquiring applications.

  • A.8.28 Secure coding

    Secure coding principles shall be applied to software development.

  • A.8.32 Change management

    Changes to information processing facilities and information systems shall be subject to change management procedures.

SOC 2 Trust Services Criteria

AICPA · v2017 (rev. 2022) · 30 controls

AICPA Trust Services Criteria covering Security (Common Criteria CC1-CC9), Availability (A), Confidentiality (C), and Privacy (P).

CC1 Control Environment

  • CC1.1 Commitment to integrity and ethical values

    The entity demonstrates a commitment to integrity and ethical values that supports the functioning of the system of internal control.

  • CC1.4 Attracts, develops, and retains competent personnel

    The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

CC2 Communication and Information

  • CC2.1 Quality information for internal control

    The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

  • CC2.2 Internal communication of objectives and responsibilities

    The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support its functioning.

CC3 Risk Assessment

  • CC3.2 Identifies and assesses risk

    The entity identifies risks to the achievement of its objectives across the entity and analyses risks as a basis for determining how the risks should be managed.

  • CC3.4 Assessment of changes

    The entity identifies and assesses changes that could significantly impact the system of internal control.

CC4 Monitoring Activities

  • CC4.1 Ongoing and separate monitoring evaluations

    The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

CC5 Control Activities

  • CC5.1 Selects and develops control activities

    The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

  • CC5.2 Selects and develops general controls over technology

    The entity selects and develops general control activities over technology to support the achievement of objectives.

CC6 Logical and Physical Access Controls

  • CC6.1 Logical access controls

    The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.

  • CC6.2 New user provisioning

    Prior to issuing system credentials and granting system access, the entity registers and authorises new internal and external users whose access is administered by the entity.

  • CC6.3 Removal of access

    The entity authorises, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties.

  • CC6.6 Transmission encryption

    The entity implements logical access security measures to protect against threats from sources outside its system boundaries, including encryption of data in transit.

  • CC6.7 Data-at-rest encryption and transmission integrity

    The entity restricts the transmission, movement, and removal of information to authorised internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives. Includes encryption of data at rest.

  • CC6.8 Prevention of unauthorised software

    The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software to meet its objectives.

CC7 System Operations

  • CC7.1 Detection and monitoring of new vulnerabilities

    To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.

  • CC7.2 Anomalies and security event detection

    The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analysed to determine whether they represent security events.

  • CC7.3 Security incident response

    The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.

  • CC7.4 Incident remediation

    The entity responds to identified security incidents by executing a defined incident response programme to understand, contain, remediate, and communicate security incidents, as appropriate.

  • CC7.5 Recovery from incidents

    The entity identifies, develops, and implements activities to recover from identified security incidents.

CC8 Change Management

  • CC8.1 Change management

    The entity authorises, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.

CC9 Risk Mitigation

  • CC9.1 Risk mitigation activities

    The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.

  • CC9.2 Vendor and business partner risk

    The entity assesses and manages risks associated with vendors and business partners.

A1 Availability

  • A1.1 Capacity planning

    The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.

  • A1.2 Environmental protection and backups

    The entity authorises, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.

  • A1.3 Recovery plan testing

    The entity tests recovery plan procedures supporting system recovery to meet its objectives.

C1 Confidentiality

  • C1.1 Identification and protection of confidential information

    The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.

  • C1.2 Disposal of confidential information

    The entity disposes of confidential information to meet the entity's objectives related to confidentiality.

P1 Privacy Notice

  • P1.1 Privacy notice

    The entity provides notice to data subjects about its privacy practices to meet its objectives related to privacy.

P2 Choice and Consent

  • P2.1 Privacy choice and consent

    The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to data subjects, and obtains consent as required.

See the full Kovira security posture overview at /security.