| Restricting who reaches what | Application control, Device oversight | Application control decides what may execute, and device oversight decides where a machine may go. Permission decisions inside your own identity provider remain yours. Split · 16 CFR 314.4 at (c)(1) |
| Knowing where the records sit | Data safeguards | Regulated records get located across workstations and shares, then reported by category, by volume, and by how exposed each machine happens to be. We run it · 16 CFR 314.4 at (c)(2) |
| Customer information kept unreadable | Data safeguards | Whatever the scanning found gets encrypted, and the channels it can leave along get narrowed. Settings inside a cloud platform you own stay under your hand. Split · 16 CFR 314.4 at (c)(3) |
| A second factor at sign in | Nothing to buy. Help configuring it | This belongs to your identity provider. We will set it up beside you and confirm later that it stayed on, and there is no line item attached to doing so. Your practice · 16 CFR 314.4 at (c)(5) |
| Changes recorded, software updated | Device oversight | Build and third party update status is tracked, approved updates are delivered, and whatever declined to install comes back to you as a list. We run it · 16 CFR 314.4 at (c)(7) |
| Activity logged and actually read | Monitoring and response | Machine, directory, mail, and network events are collected, retained, and put in front of an analyst who reacts to what they show. We run it · 16 CFR 314.4 at (c)(8) |
| Watching continuously, or testing instead | Monitoring and response | The staffed watching entries are the continuous route. Penetration testing and vulnerability sweeps get engaged separately, and neither is billed from this page. Split · 16 CFR 314.4 at (d) |
| Instruction for the people who read mail | Email protection | Simulation and short lessons, reported individually, so instruction reaches whoever the outcomes indicate rather than the whole practice at once. We run it · 16 CFR 314.4 at (e) |
| Keeping an eye on your suppliers | Nothing to buy. We answer yours | We happen to be one of those suppliers, and a written diligence questionnaire gets answered. Assessing your other vendors is programme work rather than a subscription. Your practice · 16 CFR 314.4 at (f) |
| A response plan, in writing | Monitoring and response, Recovery and continuity | Watching supplies the plan with detection and containment. Recovery supplies it with restoration. Drafting the document and naming who decides belongs to your practice. Split · 16 CFR 314.4 at (h) |
| A risk assessment, written and revisited | Nothing to buy. Evidence supplied | No entry in this catalog performs one. What we hand over is the asset record, the exposure figures, and update status, so whoever writes it starts from facts. Your practice · 16 CFR 314.4 at (b) |
| A qualified individual, and reporting upward | Nothing to buy | A named person inside your practice owns the programme and reports on it. That role cannot be handed to a catalog, and pretending otherwise would not help you. Your practice · 16 CFR 314.4 at (a) and at (i) |