Version: X.X
Use limitation: This matrix records a portfolio mapping-quality exercise. “Confirmed,” “Corrected,” and “Review Required” describe the mapping review status only; they do not evidence control design, implementation, operating effectiveness, legal applicability, or compliance. Confirm framework currency and effective dates with the control owner and Legal/Compliance before use.
| Column | Meaning |
|---|---|
| Control ID | Unique control identifier as it appears in the policy document |
| Policy | Source policy filename (short form) |
| Objective | One-line description of what the control mandates |
| ISO 27001 Ref | ISO/IEC 27001:2022 Annex A control(s) |
| NIST CSF Ref | NIST CSF 2.0 subcategory/function reference |
| PCI DSS Ref | PCI DSS v4.0.1 Requirement reference (blank if not applicable) |
| DPDP Act Ref | India DPDP Act 2023 / Rules 2025 Section reference (blank if not applicable) |
| GDPR Ref | EU GDPR Article reference (blank if not applicable) |
| Notes | Flags, cross-references to other controls, or "Review" rationale |
| Status | Mapping-quality review status; not a control-effectiveness assessment |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| AM-01 | access-management | Least privilege and need-to-know; no wildcard permissions in production | A.5.15, A.8.2 | PR.AA-05 | Req 7.2 | Sec 8(5) | - | Cross-ref: DC-03 (Restricted data access) | Confirmed |
| AM-02 | access-management | Formal written access requests with manager approval before provisioning | A.5.18 | PR.AA-01 | Req 7.2.2 | - | Art 32 | - | Confirmed |
| AM-03 | access-management | Unique user IDs mandatory; shared/generic accounts prohibited | A.5.16 | PR.AA-02 | Req 8.2.1 | Sec 8(5) | - | Exception process references Exception Log | Confirmed |
| AM-04 | access-management | MFA mandatory for VPN, CDE, cloud consoles, CI/CD; FIDO2/TOTP required; SMS OTP deprecated for privileged | A.8.5 | PR.AA-03 | Req 8.4, 8.5 | - | Art 32(1)(b) | Cross-ref: PA-01 (authentication standards) | Confirmed |
| AM-05 | access-management | Password standards: 14-char standard, 20-char privileged, 12-history, 10-attempt lockout, no default credentials, secrets in vault | A.5.17 | PR.AA-02 | Req 8.3, 8.6 | - | Art 32 | Superseded in detail by PA policy; cross-ref PA-02–PA-06 | Confirmed |
| AM-06 | access-management | Quarterly recertification for CDE/production; semi-annual for corporate IT; revocation within 5 business days | A.5.18 | PR.AA-05 | Req 7.2.4, 7.2.5 | - | Art 5(1)(f) | - | Confirmed |
| AM-07 | access-management | PAM: separate privileged accounts, JIT access, 12-month session recording, dual-control break-glass | A.5.18, A.8.2 | PR.AA-05, PR.AA-06 | Req 7.2.6, 8.2.2 | - | Art 32 | - | Confirmed |
| AM-08 | access-management | Account disable within 4 hrs (planned) / 1 hr (for-cause) of separation; revoke all sessions, tokens, keys | A.5.18, A.6.5 | PR.AA-05 | Req 8.3.4 | Sec 8(5) | - | Cross-ref: AS-08 (asset return) | Confirmed |
| AM-09 | access-management | Third-party access: need-to-know, MFA, unique accounts, time-limited, revoked within 5 days of contract end | A.5.19, A.5.20 | GV.SC-07, PR.AA-05 | Req 8.2.1, 12.8 | Sec 8(2) | Art 28 | Cross-ref: VR policy | Confirmed |
| AM-10 | access-management | Service accounts: unique identity, 90-day rotation, no interactive login, vault-only secrets, quarterly inventory | A.5.16, A.8.3 | PR.AA-02, PR.AA-05 | Req 8.6 | - | Art 32 | Cross-ref: PA-08 (service account auth) | Confirmed |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| AU-01 | acceptable-use | Business use primary; incidental personal use permissible within four stated conditions | A.5.10 | GV.PO-02 | Req 12.3.2 | - | - | - | Confirmed |
| AU-02 | acceptable-use | Prohibits unauthorized data access/exfiltration, circumventing controls, unauthorized software, shadow IT, credential sharing, malicious code | A.5.10, A.8.1 | PR.AT-01, PR.DS-05 | Req 12.3 | Sec 8(5) | Art 5, 32 | Broad behavioural control | Confirmed |
| AU-03 | acceptable-use | Prohibits illegal content, financial fraud, personal commercial activity, harassment, identity misrepresentation | A.5.10, A.6.2 | GV.PO-02 | Req 12.1 | - | - | Covers RBI/legal conduct obligations | Confirmed |
| AU-04 | acceptable-use | Internet browsing: no malicious sites, no untrusted downloads, approved browsers, VPN mandatory for remote, no unencrypted public Wi-Fi for production | A.8.1, A.8.23 | PR.PS-01 | Req 12.3 | - | - | - | Confirmed |
| AU-05 | acceptable-use | Email/collaboration: use corporate accounts, report phishing, no PII/PAD forwarding, no secrets in Slack DMs | A.5.10, A.8.23 | PR.AT-01 | Req 12.6 | Sec 8(5) | Art 32 | - | Confirmed |
| AU-06 | acceptable-use | Endpoint use: physical security, 5-min screen lock, 1-hr lost device reporting, no non-employee use, BYOD MDM enrolment | A.6.2, A.8.1 | PR.PS-01 | Req 12.3 | - | - | Cross-ref: AS-04 (endpoint hardening) | Confirmed |
| AU-07 | acceptable-use | GenAI restrictions: no PII/PAD/source code in public AI tools; approved AI register; AI-generated code must pass security review | A.5.10, A.8.1 | GV.PO-02, PR.DS-05 | Req 12.3 | Sec 6, 8 | Art 5(1)(b), 25 | FinNexus-specific fintech control; privacy-by-design angle | Confirmed |
| AU-08 | acceptable-use | Cloud storage: use only sanctioned buckets, encrypted external transfers, no public buckets, bulk exports logged | A.5.10, A.5.12 | PR.DS-01, PR.DS-05 | Req 9.4 | Sec 8(5) | Art 5(1)(f), 32 | Cross-ref: DC-03 (Restricted data storage) | Confirmed |
| AU-09 | acceptable-use | System monitoring disclosed; no employee expectation of privacy; monitoring governed by Employee Privacy Notice | A.8.16, A.5.10 | DE.CM-03 | Req 10.1 | Sec 6 (Consent) | Art 5, 6(1)(f) | DPDP Act consent transparency obligation | Confirmed |
| AU-10 | acceptable-use | Obligation to report violations; non-retaliation policy; suspected breaches escalated to Legal/Compliance | A.6.4, A.5.24 | RS.CO-02 | Req 12.1 | Sec 8(6) | Art 33 | - | Confirmed |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| DC-01 | data-classification-handling | All data must be classified at creation; ambiguous data defaults to Confidential; Public classification requires CISO approval | A.5.12 | ID.AM-05 | Req 9.4.2 | Sec 8(5) | Art 5(1)(f) | Foundational control for DC policy | Confirmed |
| DC-02 | data-classification-handling | Restricted/Confidential data must carry classification labels in docs, email subjects, DB fields, and physical documents | A.5.13 | PR.DS-01 | Req 9.4.2 | - | - | - | Confirmed |
| DC-03 | data-classification-handling | Restricted data: encrypted-at-rest storage, TLS 1.2+ in transit, least-privilege access, DPA before sharing, pseudonymize before vendor sharing | A.5.14, A.8.10, A.8.24 | PR.DS-01, PR.DS-02 | Req 3.1–3.7, 4.1–4.2 | Sec 4, 6, 8 | Art 9, 25, 32 | Highest-control tier; CDE sub-scope to PCI DSS | Confirmed |
| DC-04 | data-classification-handling | Confidential data: managed systems only, TLS or encrypted email, DPA/NDA for third-party sharing | A.5.14, A.8.10 | PR.DS-01, PR.DS-05 | Req 9.4 | - | Art 5, 32 | - | Confirmed |
| DC-05 | data-classification-handling | Internal data: FinNexus personnel only; no external sharing without reclassification or NDA | A.5.14 | PR.DS-05 | - | - | - | - | Confirmed |
| DC-06 | data-classification-handling | Public data: free distribution only after formal approval through DC-01; Marketing/Legal control external publishing | A.5.12 | ID.AM-05 | - | - | - | - | Confirmed |
| DC-07 | data-classification-handling | Data minimization: collect only what's required; PIA for new personal data fields; retention schedule mandatory | A.5.9, A.8.10 | PR.DS-01 | Req 3.2 | Sec 4, 8(7) | Art 5(1)(c), 5(1)(e) | DPDP Act purpose limitation; GDPR data minimization | Confirmed |
| DC-08 | data-classification-handling | Secure disposal: crypto-shredding or NIST SP 800-88 Rev. 2 sanitization for digital; cross-cut shred + CoD for physical; hardware cleared before reuse | A.8.10 | PR.DS-03 | Req 3.2, 9.4.6 | Sec 8(7) | Art 5(1)(e), 17 | - | Corrected |
| DC-09 | data-classification-handling | Production Restricted data prohibited in dev/test without CISO+Compliance approval, anonymization, and exception log entry | A.8.31 | PR.DS-01 | Req 3.3.2 | Sec 6, 8 | Art 25, 32 | Exception references Exception Log | Confirmed |
| DC-10 | data-classification-handling | Cross-border transfers: DPDP Act permissible country list or contractual mechanism; GDPR Chapter V SCCs required | A.5.14 | GV.SC-07 | - | Sec 16 | Art 44–49 | Dual-jurisdiction transfer control | Confirmed |
| DC-11 | data-classification-handling | Special category data (Aadhaar, PAN, biometrics, GDPR Art 9 data): field-level encryption, audit logging, DPO approval for collection | A.5.12, A.8.24 | PR.DS-01 | - | Sec 8 | Art 9, 35 | KYC/AML fintech relevance | Confirmed |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| IR-01 | incident-response | All personnel must report suspected incidents within 2 hours; no self-remediation without IT Security authorization | A.5.24 | RS.MA-02 | Req 12.10.1 | - | - | - | Confirmed |
| IR-02 | incident-response | Triage and classify SEV level: within 1 hr for SEV-1/2, within 4 hrs for SEV-3/4; CISO escalated on SEV-1/2 | A.5.25 | RS.AN-03 | Req 12.10.1 | - | - | Severity taxonomy in Section 3 | Confirmed |
| IR-03 | incident-response | Containment within 2 hrs of SEV-1 classification; authorized to isolate endpoints, revoke credentials, suspend services | A.5.26 | RS.MA-03 | Req 12.10.1 | - | - | - | Confirmed |
| IR-04 | incident-response | Evidence preservation: do not alter logs/images; take forensic snapshots before eradication | A.5.28 | RS.AN-03 | Req 12.10.1 | - | - | Chain-of-custody requirement implied | Confirmed |
| IR-05 | incident-response | Eradication and recovery: root cause eliminated, CISO approves recovery plan, 14-day enhanced monitoring post-recovery | A.5.27 | RS.MA-04 | Req 12.10.1 | - | - | - | Confirmed |
| IR-06 | incident-response | Regulatory breach notification: DPBI within 72 hrs; GDPR supervisory authority within 72 hrs; IT provides technical details within 24 hrs | A.5.24 | RS.CO-02 | - | Sec 8(6) | Art 33, 34 | - | Corrected |
| IR-07 | incident-response | External communications: only authorized spokespersons; all statements reviewed by Legal; no staff social media disclosure | A.5.24 | RS.CO-02 | - | - | - | - | Confirmed |
| IR-08 | incident-response | Post-Incident Review within 5 business days of SEV-1/2 closure; root cause, timeline, lessons learned, distributed to CISO/Engineering/Legal | A.5.27 | RS.IM-01 | Req 12.10.6 | - | - | - | Confirmed |
| IR-09 | incident-response | Annual tabletop exercise; involves IT Security, Engineering, Legal, HR; lessons incorporated within 30 days | A.5.25 | RS.CO-01 | Req 12.10.2 | - | - | - | Confirmed |
| IR-10 | incident-response | Third-party incident coordination: vendor DPAs must mandate 24-hr notification to FinNexus of breach affecting FinNexus data | A.5.24, A.5.26 | GV.SC-08 | - | - | Art 33 | Cross-ref: VR-07 (vendor incident notification) | Confirmed |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| VR-01 | vendor-third-party-risk | Centralized vendor inventory in VMS; records risk tier, business owner, data types, compliance status | A.5.19 | GV.SC-04 | Req 12.8.1 | - | - | - | Confirmed |
| VR-02 | vendor-third-party-risk | Pre-procurement risk assessment required for Tier 1/2 vendors; no contract until CISO-approved | A.5.21 | GV.SC-06 | Req 12.8.3 | - | - | - | Confirmed |
| VR-03 | vendor-third-party-risk | Tier 1 vendors must supply SOC 2 Type II / ISO 27001 cert / PCI AOC or complete SIG questionnaire | A.5.21 | GV.SC-06 | Req 12.8.4 | - | - | - | Confirmed |
| VR-04 | vendor-third-party-risk | DPA required for vendors processing personal data; cardholder data vendors acknowledge PCI DSS Req 12.8.2 responsibility | A.5.20 | GV.SC-07 | Req 12.8.2 | Sec 8(2) | Art 28 | Cross-ref: AM-09 (vendor access) | Confirmed |
| VR-05 | vendor-third-party-risk | Right to Audit clause in all Tier 1 contracts; Compliance Lead may invoke proactively on failed certifications | A.5.22 | GV.SC-06 | Req 12.8.2, 12.8.4 | - | Art 28(3)(h) | - | Corrected |
| VR-06 | vendor-third-party-risk | Tier 1 vendors re-assessed annually; Tier 2 biennially; verify security posture and least-privilege access | A.5.22 | GV.SC-06 | Req 12.8.4 | - | - | - | Confirmed |
| VR-07 | vendor-third-party-risk | Vendor breach notification to FinNexus within 24 hrs; IT Security integrates into IR plan; Legal directs regulatory notifications | A.5.22 | GV.SC-06 | - | Sec 8(6) | Art 33(2) | Cross-ref: IR-10 | Confirmed |
| VR-08 | vendor-third-party-risk | Vendor offboarding: access revoked within 4 hrs; Certificate of Destruction for Restricted/Confidential data within 30 days | A.5.22, A.8.10 | ID.AM-08 | Req 12.8.5 | Sec 8(7) | Art 28(3)(g) | - | Corrected |
| VR-09 | vendor-third-party-risk | Sub-processors require FinNexus written approval; Tier 1 vendors maintain sub-processor list; primary vendor liable for sub-processor failures | A.5.20 | GV.SC-07 | - | - | Art 28(2), 28(4) | - | Confirmed |
| VR-10 | vendor-third-party-risk | Software supply chain: CI/CD blocks CVSS 7.0+ components; API connections require TLS 1.2+ and OAuth 2.0/mTLS | A.8.30, A.8.32, A.5.21 | GV.SC-06 | Req 6.3.2 | - | - | - | Corrected |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| PA-01 | password-authentication | MFA mandatory for all interactive access; FIDO2/WebAuthn or TOTP required; SMS/voice OTP deprecated | A.8.5 | PR.AA-01 | Req 8.4.2 | - | - | Cross-ref: AM-04 | Confirmed |
| PA-02 | password-authentication | Password length: 14-char standard, 20-char privileged; length prioritized over arbitrary composition rules | A.8.5 | PR.AA-01 | Req 8.3.6 | - | - | - | Confirmed |
| PA-03 | password-authentication | 12-password history enforced in AD/IdP; no reuse across systems or for personal external accounts | A.8.5 | PR.AA-01 | Req 8.3.7 | - | - | - | Confirmed |
| PA-04 | password-authentication | No arbitrary time-based password expiration; force-reset on confirmed compromise; service account/API keys rotate every 90 days | A.8.5 | PR.AA-01 | Req 8.3.9 | - | - | Aligns with NIST SP 800-63B guidance | Confirmed |
| PA-05 | password-authentication | Account lockout after 10 consecutive failures; 30-min lockout duration; customer platforms must rate-limit + CAPTCHA | A.8.5 | PR.AA-01 | Req 8.3.4 | - | - | Cross-ref: AM-05 (lockout requirement) | Confirmed |
| PA-06 | password-authentication | No default or hardcoded passwords; defaults changed pre-deployment; CI/CD secret scanning active | A.8.5 | PR.AA-01 | Req 8.2.2 | - | - | Cross-ref: AM-05 (no default credentials) | Confirmed |
| PA-07 | password-authentication | Privileged accounts require hardware-bound FIDO2 key; no shared privileged logins; CDE requires PAM step-up auth | A.8.2 | PR.AA-01 | Req 8.2.1 | - | - | Cross-ref: AM-07 (PAM) | Confirmed |
| PA-08 | password-authentication | Service accounts: mTLS/OAuth 2.0/restricted tokens; no interactive login; credentials dynamically injected via Vault/Secrets Manager | A.8.5 | PR.AA-01 | Req 8.2.7 | - | - | Cross-ref: AM-10 | Confirmed |
| PA-09 | password-authentication | Password storage: Argon2id/bcrypt/PBKDF2 (≥600K iterations) with unique salt; no MD5/SHA-1; TLS 1.2+ for transmission | A.8.24 | PR.DS-01 | Req 8.3.2 | - | - | - | Confirmed |
| PA-10 | password-authentication | Continuous monitoring against known-compromised password databases (e.g., HIBP); force reset on match | A.8.5 | PR.AA-01 | Req 8.3.6 | - | - | DPDP Act 2023/GDPR may apply if monitoring involves employee personal data | Review Required |
| PA-11 | password-authentication | Session timeout: corporate IdP 12-hr idle; customer financial apps 15-min idle; sessions invalidated on password change/logout/suspension | A.8.5 | PR.AA-01 | Req 8.2.8 | - | - | - | Confirmed |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| AS-01 | asset-management | Centralized ITSM + CSPM inventory; cloud assets auto-discovered every 24 hrs; records ID, status, classification, owner, location | A.5.9 | ID.AM-01, ID.AM-02 | Req 2.4 | - | - | Policy cites Req 2.4 (not 12.5.1 as in earlier CTM draft) | Confirmed |
| AS-02 | asset-management | Named owner for every asset; orphaned assets quarantined/decommissioned within 72 hrs | A.5.9 | ID.AM-03 | Req 2.4 | - | - | - | Confirmed |
| AS-03 | asset-management | Assets used for authorized business purposes only; no unauthorized software/EDR bypass; BYOD requires MDM enrolment for Restricted/Confidential access | A.5.10 | PR.AT-01 | - | Sec 8 | - | Cross-ref: AU-02(c) (unauthorized software) | Confirmed |
| AS-04 | asset-management | Endpoints: MDM pre-deployment; BitLocker/FileVault; host firewall; EDR; 15-min auto-lock | A.8.1, A.8.9 | PR.AA-03 | Req 8.2 | - | - | Cross-ref: AU-06 (5-min lock in AU policy) - reconcile timeout | Confirmed |
| AS-05 | asset-management | Cloud assets provisioned via approved IaC only; no manual prod deployments; IaC static security analysis in CI/CD | A.8.8 | PR.IP-01 | Req 2.2 | - | - | - | Confirmed |
| AS-06 | asset-management | Software from approved portal or documented IT ticket; semi-annual review of endpoint fleet for shadow IT | A.8.19 | ID.AM-02 | Req 2.4 | - | - | - | Confirmed |
| AS-07 | asset-management | Physical security: devices secured when unattended; MDM tracks location; 30-day no-check-in triggers auto-wipe | A.7.10 | PR.DS-01 | Req 9.3 | - | - | - | Confirmed |
| AS-08 | asset-management | Asset return by end of final day; for-cause: 1-hr retrieval; ITSM logged within 24 hrs of return | A.5.11 | PR.IP-03 | - | - | Art 32 | Cross-ref: AM-08 (access revocation) | Confirmed |
| AS-09 | asset-management | Secure decommissioning per DC-08: crypto wipe or physical destruction; cloud teardown via IaC with storage deletion and IAM revocation; CoD retained | A.8.10 | PR.DS-03 | Req 9.4.6 | Sec 8(7) | - | - | Confirmed |
| AS-10 | asset-management | Lost/stolen: report within 12 hrs; MDM remote wipe + VPN certificate revocation; Legal notified if Restricted data involved | A.5.24 | RS.CO-02 | - | Sec 8(6) | Art 33 | Cross-ref: IR-01 (incident reporting) | Confirmed |
| Control ID | Policy / Control | Objective | ISO/IEC 27001:2022 | NIST CSF 2.0 | PCI DSS v4.0.1 | DPDP Act / Rules | GDPR | Evidence / Rationale | Status |
|---|---|---|---|---|---|---|---|---|---|
| BC-01 | business-continuity-backup | Annual BIA or upon major architectural change; classifies systems into criticality tiers; CISO approves | A.5.29 | ID.RA-04 | - | - | - | NIST ref is ID.RA-04 per policy; RC.RP-01 also applicable | Confirmed |
| BC-02 | business-continuity-backup | Backup schedules: Tier 1 every 15 min, 30-day hot/1-year cold; Tier 2 daily incremental, 60-day; Tier 3 weekly, 30-day | A.8.13 | PR.DS-11 | Req 10.7.2 | - | - | - | Confirmed |
| BC-03 | business-continuity-backup | All backups: AES-256 at rest, TLS 1.2+/1.3 in transit; KMS physically and logically separated from backup storage | A.8.24 | PR.DS-01 | Req 3.5 | - | Art 32 | - | Confirmed |
| BC-04 | business-continuity-backup | Tier 1 and 2 backups in WORM immutable storage for first 30 days; auto-replicated to geographically separate cloud region | A.8.13 | PR.DS-11 | - | - | Art 32(1)(c) | Ransomware resilience control | Confirmed |
| BC-05 | business-continuity-backup | Restoration testing: Tier 1 quarterly, Tier 2 semi-annually; verify recoverability within RTO; results reviewed by IT Security Lead | A.5.30, A.8.13 | RC.RP-03 | Req 10.7.3 | - | - | - | Confirmed |
| BC-06 | business-continuity-backup | Tier 1 platforms: Multi-AZ with active-active or auto active-passive failover; single-zone failure cannot exceed 4-hr RTO | A.8.14 | PR.IR-03 | - | - | - | - | Corrected |
| BC-07 | business-continuity-backup | DRP documented for Tier 1/2; updated annually or within 30 days of major infra change; includes IR contacts and manual fallbacks | A.5.30 | RC.RP-01 | - | - | - | - | Confirmed |
| BC-08 | business-continuity-backup | Alternate workspace: redundant load-balanced VPN gateways; critical personnel issued failover-configured laptops | A.5.30 | PR.IR-03, PR.AA-05 | - | - | - | - | Corrected |
| BC-09 | business-continuity-backup | Bi-annual tabletop exercise; simulates ransomware or cloud region failure; lessons in risk register, remediated within 90 days | A.5.30 | RC.RP-03 | - | Sec 8 | - | - | Confirmed |
| BC-10 | business-continuity-backup | Tier 1 vendors contractually required: 99.9% uptime SLA, compliant DRP; reviewed in annual vendor risk cycle | A.5.21, A.5.22 | GV.SC-06 | - | - | - | Cross-ref: VR-06 (vendor re-assessment) | Confirmed |
| BC-11 | business-continuity-backup | Declared disaster: CISO notifies internal stakeholders and Board within 1 hr; Legal engaged immediately if Restricted data/funds affected | A.5.24 | RC.CO-03 | - | Sec 8(6) | Art 33 | Cross-ref: IR-06 (regulatory notification) | Confirmed |
| Policy | Controls Mapped | With PCI DSS Ref | With DPDP Act / Rules Ref | With GDPR Ref | "Review" Flags |
|---|---|---|---|---|---|
| AM - Access Management | 10 | 10 | 4 | 5 | 0 |
| AU - Acceptable Use | 10 | 7 | 5 | 5 | 0 |
| DC - Data Classification | 11 | 8 | 7 | 9 | 0 |
| IR - Incident Response | 10 | 6 | 2 | 4 | 0 |
| VR - Vendor/Third-Party Risk | 10 | 6 | 2 | 5 | 0 |
| PA - Password & Authentication | 11 | 11 | 0 | 0 | 1 |
| AS - Asset Management | 10 | 5 | 3 | 2 | 0 |
| BC - Business Continuity | 11 | 4 | 3 | 3 | 0 |
| TOTAL | 83 | 57 | 26 | 33 | 1 |
The following cells were flagged Review and require manual verification by the Compliance team before the mapping is relied on for an audit evidence package:
| Flag | Location | Issue |
|---|---|---|
| PA-10 DPDP Act 2023/GDPR | PA - Password & Authentication | Pending DPO/Legal review - do not close without formal sign-off. |
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 1.0 | DD.MM.YY | Compliance Lead / IT Security Lead | Initial skeleton matrix. |
| 2.0 | DD.MM.YY | IT Security Lead | Full rebuild - all 83 safeguard IDs extracted and mapped from final policy files; Review flags added; cross-references linked. |
| 2.1 | DD.MM.YY | Compliance Lead | Applied audit corrections (BC-08, IR-06, VR-05, VR-08, BC-06, VR-10); removed resolved review flags. |