Skip to content

Latest commit

 

History

History
198 lines (159 loc) · 23.8 KB

File metadata and controls

198 lines (159 loc) · 23.8 KB

Control Traceability Matrix (CTM)

FinNexus Solutions - PolicyForge Suite

Version: X.X

Use limitation: This matrix records a portfolio mapping-quality exercise. “Confirmed,” “Corrected,” and “Review Required” describe the mapping review status only; they do not evidence control design, implementation, operating effectiveness, legal applicability, or compliance. Confirm framework currency and effective dates with the control owner and Legal/Compliance before use.


How to Read This Matrix

Column Meaning
Control ID Unique control identifier as it appears in the policy document
Policy Source policy filename (short form)
Objective One-line description of what the control mandates
ISO 27001 Ref ISO/IEC 27001:2022 Annex A control(s)
NIST CSF Ref NIST CSF 2.0 subcategory/function reference
PCI DSS Ref PCI DSS v4.0.1 Requirement reference (blank if not applicable)
DPDP Act Ref India DPDP Act 2023 / Rules 2025 Section reference (blank if not applicable)
GDPR Ref EU GDPR Article reference (blank if not applicable)
Notes Flags, cross-references to other controls, or "Review" rationale
Status Mapping-quality review status; not a control-effectiveness assessment

AM - Access Management Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
AM-01 access-management Least privilege and need-to-know; no wildcard permissions in production A.5.15, A.8.2 PR.AA-05 Req 7.2 Sec 8(5) - Cross-ref: DC-03 (Restricted data access) Confirmed
AM-02 access-management Formal written access requests with manager approval before provisioning A.5.18 PR.AA-01 Req 7.2.2 - Art 32 - Confirmed
AM-03 access-management Unique user IDs mandatory; shared/generic accounts prohibited A.5.16 PR.AA-02 Req 8.2.1 Sec 8(5) - Exception process references Exception Log Confirmed
AM-04 access-management MFA mandatory for VPN, CDE, cloud consoles, CI/CD; FIDO2/TOTP required; SMS OTP deprecated for privileged A.8.5 PR.AA-03 Req 8.4, 8.5 - Art 32(1)(b) Cross-ref: PA-01 (authentication standards) Confirmed
AM-05 access-management Password standards: 14-char standard, 20-char privileged, 12-history, 10-attempt lockout, no default credentials, secrets in vault A.5.17 PR.AA-02 Req 8.3, 8.6 - Art 32 Superseded in detail by PA policy; cross-ref PA-02–PA-06 Confirmed
AM-06 access-management Quarterly recertification for CDE/production; semi-annual for corporate IT; revocation within 5 business days A.5.18 PR.AA-05 Req 7.2.4, 7.2.5 - Art 5(1)(f) - Confirmed
AM-07 access-management PAM: separate privileged accounts, JIT access, 12-month session recording, dual-control break-glass A.5.18, A.8.2 PR.AA-05, PR.AA-06 Req 7.2.6, 8.2.2 - Art 32 - Confirmed
AM-08 access-management Account disable within 4 hrs (planned) / 1 hr (for-cause) of separation; revoke all sessions, tokens, keys A.5.18, A.6.5 PR.AA-05 Req 8.3.4 Sec 8(5) - Cross-ref: AS-08 (asset return) Confirmed
AM-09 access-management Third-party access: need-to-know, MFA, unique accounts, time-limited, revoked within 5 days of contract end A.5.19, A.5.20 GV.SC-07, PR.AA-05 Req 8.2.1, 12.8 Sec 8(2) Art 28 Cross-ref: VR policy Confirmed
AM-10 access-management Service accounts: unique identity, 90-day rotation, no interactive login, vault-only secrets, quarterly inventory A.5.16, A.8.3 PR.AA-02, PR.AA-05 Req 8.6 - Art 32 Cross-ref: PA-08 (service account auth) Confirmed

AU - Acceptable Use Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
AU-01 acceptable-use Business use primary; incidental personal use permissible within four stated conditions A.5.10 GV.PO-02 Req 12.3.2 - - - Confirmed
AU-02 acceptable-use Prohibits unauthorized data access/exfiltration, circumventing controls, unauthorized software, shadow IT, credential sharing, malicious code A.5.10, A.8.1 PR.AT-01, PR.DS-05 Req 12.3 Sec 8(5) Art 5, 32 Broad behavioural control Confirmed
AU-03 acceptable-use Prohibits illegal content, financial fraud, personal commercial activity, harassment, identity misrepresentation A.5.10, A.6.2 GV.PO-02 Req 12.1 - - Covers RBI/legal conduct obligations Confirmed
AU-04 acceptable-use Internet browsing: no malicious sites, no untrusted downloads, approved browsers, VPN mandatory for remote, no unencrypted public Wi-Fi for production A.8.1, A.8.23 PR.PS-01 Req 12.3 - - - Confirmed
AU-05 acceptable-use Email/collaboration: use corporate accounts, report phishing, no PII/PAD forwarding, no secrets in Slack DMs A.5.10, A.8.23 PR.AT-01 Req 12.6 Sec 8(5) Art 32 - Confirmed
AU-06 acceptable-use Endpoint use: physical security, 5-min screen lock, 1-hr lost device reporting, no non-employee use, BYOD MDM enrolment A.6.2, A.8.1 PR.PS-01 Req 12.3 - - Cross-ref: AS-04 (endpoint hardening) Confirmed
AU-07 acceptable-use GenAI restrictions: no PII/PAD/source code in public AI tools; approved AI register; AI-generated code must pass security review A.5.10, A.8.1 GV.PO-02, PR.DS-05 Req 12.3 Sec 6, 8 Art 5(1)(b), 25 FinNexus-specific fintech control; privacy-by-design angle Confirmed
AU-08 acceptable-use Cloud storage: use only sanctioned buckets, encrypted external transfers, no public buckets, bulk exports logged A.5.10, A.5.12 PR.DS-01, PR.DS-05 Req 9.4 Sec 8(5) Art 5(1)(f), 32 Cross-ref: DC-03 (Restricted data storage) Confirmed
AU-09 acceptable-use System monitoring disclosed; no employee expectation of privacy; monitoring governed by Employee Privacy Notice A.8.16, A.5.10 DE.CM-03 Req 10.1 Sec 6 (Consent) Art 5, 6(1)(f) DPDP Act consent transparency obligation Confirmed
AU-10 acceptable-use Obligation to report violations; non-retaliation policy; suspected breaches escalated to Legal/Compliance A.6.4, A.5.24 RS.CO-02 Req 12.1 Sec 8(6) Art 33 - Confirmed

DC - Data Classification & Handling Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
DC-01 data-classification-handling All data must be classified at creation; ambiguous data defaults to Confidential; Public classification requires CISO approval A.5.12 ID.AM-05 Req 9.4.2 Sec 8(5) Art 5(1)(f) Foundational control for DC policy Confirmed
DC-02 data-classification-handling Restricted/Confidential data must carry classification labels in docs, email subjects, DB fields, and physical documents A.5.13 PR.DS-01 Req 9.4.2 - - - Confirmed
DC-03 data-classification-handling Restricted data: encrypted-at-rest storage, TLS 1.2+ in transit, least-privilege access, DPA before sharing, pseudonymize before vendor sharing A.5.14, A.8.10, A.8.24 PR.DS-01, PR.DS-02 Req 3.1–3.7, 4.1–4.2 Sec 4, 6, 8 Art 9, 25, 32 Highest-control tier; CDE sub-scope to PCI DSS Confirmed
DC-04 data-classification-handling Confidential data: managed systems only, TLS or encrypted email, DPA/NDA for third-party sharing A.5.14, A.8.10 PR.DS-01, PR.DS-05 Req 9.4 - Art 5, 32 - Confirmed
DC-05 data-classification-handling Internal data: FinNexus personnel only; no external sharing without reclassification or NDA A.5.14 PR.DS-05 - - - - Confirmed
DC-06 data-classification-handling Public data: free distribution only after formal approval through DC-01; Marketing/Legal control external publishing A.5.12 ID.AM-05 - - - - Confirmed
DC-07 data-classification-handling Data minimization: collect only what's required; PIA for new personal data fields; retention schedule mandatory A.5.9, A.8.10 PR.DS-01 Req 3.2 Sec 4, 8(7) Art 5(1)(c), 5(1)(e) DPDP Act purpose limitation; GDPR data minimization Confirmed
DC-08 data-classification-handling Secure disposal: crypto-shredding or NIST SP 800-88 Rev. 2 sanitization for digital; cross-cut shred + CoD for physical; hardware cleared before reuse A.8.10 PR.DS-03 Req 3.2, 9.4.6 Sec 8(7) Art 5(1)(e), 17 - Corrected
DC-09 data-classification-handling Production Restricted data prohibited in dev/test without CISO+Compliance approval, anonymization, and exception log entry A.8.31 PR.DS-01 Req 3.3.2 Sec 6, 8 Art 25, 32 Exception references Exception Log Confirmed
DC-10 data-classification-handling Cross-border transfers: DPDP Act permissible country list or contractual mechanism; GDPR Chapter V SCCs required A.5.14 GV.SC-07 - Sec 16 Art 44–49 Dual-jurisdiction transfer control Confirmed
DC-11 data-classification-handling Special category data (Aadhaar, PAN, biometrics, GDPR Art 9 data): field-level encryption, audit logging, DPO approval for collection A.5.12, A.8.24 PR.DS-01 - Sec 8 Art 9, 35 KYC/AML fintech relevance Confirmed

IR - Incident Response Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
IR-01 incident-response All personnel must report suspected incidents within 2 hours; no self-remediation without IT Security authorization A.5.24 RS.MA-02 Req 12.10.1 - - - Confirmed
IR-02 incident-response Triage and classify SEV level: within 1 hr for SEV-1/2, within 4 hrs for SEV-3/4; CISO escalated on SEV-1/2 A.5.25 RS.AN-03 Req 12.10.1 - - Severity taxonomy in Section 3 Confirmed
IR-03 incident-response Containment within 2 hrs of SEV-1 classification; authorized to isolate endpoints, revoke credentials, suspend services A.5.26 RS.MA-03 Req 12.10.1 - - - Confirmed
IR-04 incident-response Evidence preservation: do not alter logs/images; take forensic snapshots before eradication A.5.28 RS.AN-03 Req 12.10.1 - - Chain-of-custody requirement implied Confirmed
IR-05 incident-response Eradication and recovery: root cause eliminated, CISO approves recovery plan, 14-day enhanced monitoring post-recovery A.5.27 RS.MA-04 Req 12.10.1 - - - Confirmed
IR-06 incident-response Regulatory breach notification: DPBI within 72 hrs; GDPR supervisory authority within 72 hrs; IT provides technical details within 24 hrs A.5.24 RS.CO-02 - Sec 8(6) Art 33, 34 - Corrected
IR-07 incident-response External communications: only authorized spokespersons; all statements reviewed by Legal; no staff social media disclosure A.5.24 RS.CO-02 - - - - Confirmed
IR-08 incident-response Post-Incident Review within 5 business days of SEV-1/2 closure; root cause, timeline, lessons learned, distributed to CISO/Engineering/Legal A.5.27 RS.IM-01 Req 12.10.6 - - - Confirmed
IR-09 incident-response Annual tabletop exercise; involves IT Security, Engineering, Legal, HR; lessons incorporated within 30 days A.5.25 RS.CO-01 Req 12.10.2 - - - Confirmed
IR-10 incident-response Third-party incident coordination: vendor DPAs must mandate 24-hr notification to FinNexus of breach affecting FinNexus data A.5.24, A.5.26 GV.SC-08 - - Art 33 Cross-ref: VR-07 (vendor incident notification) Confirmed

VR - Vendor & Third-Party Risk Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
VR-01 vendor-third-party-risk Centralized vendor inventory in VMS; records risk tier, business owner, data types, compliance status A.5.19 GV.SC-04 Req 12.8.1 - - - Confirmed
VR-02 vendor-third-party-risk Pre-procurement risk assessment required for Tier 1/2 vendors; no contract until CISO-approved A.5.21 GV.SC-06 Req 12.8.3 - - - Confirmed
VR-03 vendor-third-party-risk Tier 1 vendors must supply SOC 2 Type II / ISO 27001 cert / PCI AOC or complete SIG questionnaire A.5.21 GV.SC-06 Req 12.8.4 - - - Confirmed
VR-04 vendor-third-party-risk DPA required for vendors processing personal data; cardholder data vendors acknowledge PCI DSS Req 12.8.2 responsibility A.5.20 GV.SC-07 Req 12.8.2 Sec 8(2) Art 28 Cross-ref: AM-09 (vendor access) Confirmed
VR-05 vendor-third-party-risk Right to Audit clause in all Tier 1 contracts; Compliance Lead may invoke proactively on failed certifications A.5.22 GV.SC-06 Req 12.8.2, 12.8.4 - Art 28(3)(h) - Corrected
VR-06 vendor-third-party-risk Tier 1 vendors re-assessed annually; Tier 2 biennially; verify security posture and least-privilege access A.5.22 GV.SC-06 Req 12.8.4 - - - Confirmed
VR-07 vendor-third-party-risk Vendor breach notification to FinNexus within 24 hrs; IT Security integrates into IR plan; Legal directs regulatory notifications A.5.22 GV.SC-06 - Sec 8(6) Art 33(2) Cross-ref: IR-10 Confirmed
VR-08 vendor-third-party-risk Vendor offboarding: access revoked within 4 hrs; Certificate of Destruction for Restricted/Confidential data within 30 days A.5.22, A.8.10 ID.AM-08 Req 12.8.5 Sec 8(7) Art 28(3)(g) - Corrected
VR-09 vendor-third-party-risk Sub-processors require FinNexus written approval; Tier 1 vendors maintain sub-processor list; primary vendor liable for sub-processor failures A.5.20 GV.SC-07 - - Art 28(2), 28(4) - Confirmed
VR-10 vendor-third-party-risk Software supply chain: CI/CD blocks CVSS 7.0+ components; API connections require TLS 1.2+ and OAuth 2.0/mTLS A.8.30, A.8.32, A.5.21 GV.SC-06 Req 6.3.2 - - - Corrected

PA - Password & Authentication Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
PA-01 password-authentication MFA mandatory for all interactive access; FIDO2/WebAuthn or TOTP required; SMS/voice OTP deprecated A.8.5 PR.AA-01 Req 8.4.2 - - Cross-ref: AM-04 Confirmed
PA-02 password-authentication Password length: 14-char standard, 20-char privileged; length prioritized over arbitrary composition rules A.8.5 PR.AA-01 Req 8.3.6 - - - Confirmed
PA-03 password-authentication 12-password history enforced in AD/IdP; no reuse across systems or for personal external accounts A.8.5 PR.AA-01 Req 8.3.7 - - - Confirmed
PA-04 password-authentication No arbitrary time-based password expiration; force-reset on confirmed compromise; service account/API keys rotate every 90 days A.8.5 PR.AA-01 Req 8.3.9 - - Aligns with NIST SP 800-63B guidance Confirmed
PA-05 password-authentication Account lockout after 10 consecutive failures; 30-min lockout duration; customer platforms must rate-limit + CAPTCHA A.8.5 PR.AA-01 Req 8.3.4 - - Cross-ref: AM-05 (lockout requirement) Confirmed
PA-06 password-authentication No default or hardcoded passwords; defaults changed pre-deployment; CI/CD secret scanning active A.8.5 PR.AA-01 Req 8.2.2 - - Cross-ref: AM-05 (no default credentials) Confirmed
PA-07 password-authentication Privileged accounts require hardware-bound FIDO2 key; no shared privileged logins; CDE requires PAM step-up auth A.8.2 PR.AA-01 Req 8.2.1 - - Cross-ref: AM-07 (PAM) Confirmed
PA-08 password-authentication Service accounts: mTLS/OAuth 2.0/restricted tokens; no interactive login; credentials dynamically injected via Vault/Secrets Manager A.8.5 PR.AA-01 Req 8.2.7 - - Cross-ref: AM-10 Confirmed
PA-09 password-authentication Password storage: Argon2id/bcrypt/PBKDF2 (≥600K iterations) with unique salt; no MD5/SHA-1; TLS 1.2+ for transmission A.8.24 PR.DS-01 Req 8.3.2 - - - Confirmed
PA-10 password-authentication Continuous monitoring against known-compromised password databases (e.g., HIBP); force reset on match A.8.5 PR.AA-01 Req 8.3.6 - - DPDP Act 2023/GDPR may apply if monitoring involves employee personal data Review Required
PA-11 password-authentication Session timeout: corporate IdP 12-hr idle; customer financial apps 15-min idle; sessions invalidated on password change/logout/suspension A.8.5 PR.AA-01 Req 8.2.8 - - - Confirmed

AS - Asset Management Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
AS-01 asset-management Centralized ITSM + CSPM inventory; cloud assets auto-discovered every 24 hrs; records ID, status, classification, owner, location A.5.9 ID.AM-01, ID.AM-02 Req 2.4 - - Policy cites Req 2.4 (not 12.5.1 as in earlier CTM draft) Confirmed
AS-02 asset-management Named owner for every asset; orphaned assets quarantined/decommissioned within 72 hrs A.5.9 ID.AM-03 Req 2.4 - - - Confirmed
AS-03 asset-management Assets used for authorized business purposes only; no unauthorized software/EDR bypass; BYOD requires MDM enrolment for Restricted/Confidential access A.5.10 PR.AT-01 - Sec 8 - Cross-ref: AU-02(c) (unauthorized software) Confirmed
AS-04 asset-management Endpoints: MDM pre-deployment; BitLocker/FileVault; host firewall; EDR; 15-min auto-lock A.8.1, A.8.9 PR.AA-03 Req 8.2 - - Cross-ref: AU-06 (5-min lock in AU policy) - reconcile timeout Confirmed
AS-05 asset-management Cloud assets provisioned via approved IaC only; no manual prod deployments; IaC static security analysis in CI/CD A.8.8 PR.IP-01 Req 2.2 - - - Confirmed
AS-06 asset-management Software from approved portal or documented IT ticket; semi-annual review of endpoint fleet for shadow IT A.8.19 ID.AM-02 Req 2.4 - - - Confirmed
AS-07 asset-management Physical security: devices secured when unattended; MDM tracks location; 30-day no-check-in triggers auto-wipe A.7.10 PR.DS-01 Req 9.3 - - - Confirmed
AS-08 asset-management Asset return by end of final day; for-cause: 1-hr retrieval; ITSM logged within 24 hrs of return A.5.11 PR.IP-03 - - Art 32 Cross-ref: AM-08 (access revocation) Confirmed
AS-09 asset-management Secure decommissioning per DC-08: crypto wipe or physical destruction; cloud teardown via IaC with storage deletion and IAM revocation; CoD retained A.8.10 PR.DS-03 Req 9.4.6 Sec 8(7) - - Confirmed
AS-10 asset-management Lost/stolen: report within 12 hrs; MDM remote wipe + VPN certificate revocation; Legal notified if Restricted data involved A.5.24 RS.CO-02 - Sec 8(6) Art 33 Cross-ref: IR-01 (incident reporting) Confirmed

BC - Business Continuity & Backup Policy

Control ID Policy / Control Objective ISO/IEC 27001:2022 NIST CSF 2.0 PCI DSS v4.0.1 DPDP Act / Rules GDPR Evidence / Rationale Status
BC-01 business-continuity-backup Annual BIA or upon major architectural change; classifies systems into criticality tiers; CISO approves A.5.29 ID.RA-04 - - - NIST ref is ID.RA-04 per policy; RC.RP-01 also applicable Confirmed
BC-02 business-continuity-backup Backup schedules: Tier 1 every 15 min, 30-day hot/1-year cold; Tier 2 daily incremental, 60-day; Tier 3 weekly, 30-day A.8.13 PR.DS-11 Req 10.7.2 - - - Confirmed
BC-03 business-continuity-backup All backups: AES-256 at rest, TLS 1.2+/1.3 in transit; KMS physically and logically separated from backup storage A.8.24 PR.DS-01 Req 3.5 - Art 32 - Confirmed
BC-04 business-continuity-backup Tier 1 and 2 backups in WORM immutable storage for first 30 days; auto-replicated to geographically separate cloud region A.8.13 PR.DS-11 - - Art 32(1)(c) Ransomware resilience control Confirmed
BC-05 business-continuity-backup Restoration testing: Tier 1 quarterly, Tier 2 semi-annually; verify recoverability within RTO; results reviewed by IT Security Lead A.5.30, A.8.13 RC.RP-03 Req 10.7.3 - - - Confirmed
BC-06 business-continuity-backup Tier 1 platforms: Multi-AZ with active-active or auto active-passive failover; single-zone failure cannot exceed 4-hr RTO A.8.14 PR.IR-03 - - - - Corrected
BC-07 business-continuity-backup DRP documented for Tier 1/2; updated annually or within 30 days of major infra change; includes IR contacts and manual fallbacks A.5.30 RC.RP-01 - - - - Confirmed
BC-08 business-continuity-backup Alternate workspace: redundant load-balanced VPN gateways; critical personnel issued failover-configured laptops A.5.30 PR.IR-03, PR.AA-05 - - - - Corrected
BC-09 business-continuity-backup Bi-annual tabletop exercise; simulates ransomware or cloud region failure; lessons in risk register, remediated within 90 days A.5.30 RC.RP-03 - Sec 8 - - Confirmed
BC-10 business-continuity-backup Tier 1 vendors contractually required: 99.9% uptime SLA, compliant DRP; reviewed in annual vendor risk cycle A.5.21, A.5.22 GV.SC-06 - - - Cross-ref: VR-06 (vendor re-assessment) Confirmed
BC-11 business-continuity-backup Declared disaster: CISO notifies internal stakeholders and Board within 1 hr; Legal engaged immediately if Restricted data/funds affected A.5.24 RC.CO-03 - Sec 8(6) Art 33 Cross-ref: IR-06 (regulatory notification) Confirmed

Summary Statistics

Policy Controls Mapped With PCI DSS Ref With DPDP Act / Rules Ref With GDPR Ref "Review" Flags
AM - Access Management 10 10 4 5 0
AU - Acceptable Use 10 7 5 5 0
DC - Data Classification 11 8 7 9 0
IR - Incident Response 10 6 2 4 0
VR - Vendor/Third-Party Risk 10 6 2 5 0
PA - Password & Authentication 11 11 0 0 1
AS - Asset Management 10 5 3 2 0
BC - Business Continuity 11 4 3 3 0
TOTAL 83 57 26 33 1

Open Review Items

The following cells were flagged Review and require manual verification by the Compliance team before the mapping is relied on for an audit evidence package:

Flag Location Issue
PA-10 DPDP Act 2023/GDPR PA - Password & Authentication Pending DPO/Legal review - do not close without formal sign-off.

Revision History

Version Date Author Summary of Changes
1.0 DD.MM.YY Compliance Lead / IT Security Lead Initial skeleton matrix.
2.0 DD.MM.YY IT Security Lead Full rebuild - all 83 safeguard IDs extracted and mapped from final policy files; Review flags added; cross-references linked.
2.1 DD.MM.YY Compliance Lead Applied audit corrections (BC-08, IR-06, VR-05, VR-08, BC-06, VR-10); removed resolved review flags.