How to answer the funds-transfer verification question
The funds-transfer question is tied to the largest share of cyber claims, so a wrong answer is costly. This page lists every funds-transfer, dual-control and payment-change question in the held carrier documents, the ISO 27001:2022, SOC 2 and NIST CSF 2.0 controls each one reaches, and the evidence to have on file. It is drawn only from the held applications and the held control text.
The evidence that answers this question is the bank or treasury platform dual-authorisation setup and the payee-change verification, not an IT segregation-of-duties matrix on its own. An applicant can hold a duties matrix and still let one person release a payment.
What to have on file before you answer Yes
- the bank or treasury platform dual-authorisation setup, showing a payment needs a second approver on a different device
- the payment approval workflow, with the threshold above which the second approver is required
- the callback or out-of-band verification for any change to payee bank details, with a dated example
Where a form offers a partial option (for example Sometimes), it tells the carrier the control is partial; answer it as it is rather than rounding up. Whether an applicant is offered cover stays the carrier's underwriting decision.
The held funds-transfer questions, mapped
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.19 Information security in supplier relationships. Evidence to have on file: The topic-specific supplier relationship policy and its communication record; A supplier inventory categorized by type and by the information, services and infrastructure each can access.
- ISO 27001:2022 A.5.20 Addressing information security within supplier agreements. Evidence to have on file: Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms; A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed.
- ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain. Evidence to have on file: Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers; Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers.
- SOC 2 CC9.2 Assessing and managing vendor and business partner risk. Evidence to have on file: Vendor inventory with risk tiers and the review frequency set for each tier; Due diligence records, for example vendor SOC reports reviewed with complementary controls noted.
- SOC 2 P6.4 Privacy commitments from vendors and third parties. Evidence to have on file: Data processing agreements with privacy clauses; Periodic assessments of vendors' privacy compliance.
- NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders. Evidence to have on file: Third party risk management program charter; Supplier risk policy with tiering criteria.
- NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. Evidence to have on file: Standard supplier security requirements catalog; Contract clause library with cyber obligations.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.19 Information security in supplier relationships. Evidence to have on file: The topic-specific supplier relationship policy and its communication record; A supplier inventory categorized by type and by the information, services and infrastructure each can access.
- ISO 27001:2022 A.5.20 Addressing information security within supplier agreements. Evidence to have on file: Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms; A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed.
- ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain. Evidence to have on file: Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers; Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers.
- SOC 2 CC9.2 Assessing and managing vendor and business partner risk. Evidence to have on file: Vendor inventory with risk tiers and the review frequency set for each tier; Due diligence records, for example vendor SOC reports reviewed with complementary controls noted.
- SOC 2 P6.4 Privacy commitments from vendors and third parties. Evidence to have on file: Data processing agreements with privacy clauses; Periodic assessments of vendors' privacy compliance.
- NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders. Evidence to have on file: Third party risk management program charter; Supplier risk policy with tiering criteria.
- NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. Evidence to have on file: Standard supplier security requirements catalog; Contract clause library with cyber obligations.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced. Evidence to have on file: Cybersecurity risk management policy approved by leadership; Policy linkage matrix to standards and procedures.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.8.23 Web filtering. Evidence to have on file: Current rules on safe, proper use of online resources; Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites.
- ISO 27001:2022 A.8.7 Protection against malware. Evidence to have on file: Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations.
- ISO 27001:2022 A.5.14 Information transfer. Evidence to have on file: The topic-specific information transfer policy and its communication record; Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling.
- SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software. Evidence to have on file: Endpoint protection coverage report across servers and workstations; Local administrator and software installation restrictions.
- SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4). Evidence to have on file: Background check policy and completed checks for a sample of new hires and contractors; Role competency requirements and performance review records.
- NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented. Evidence to have on file: Application allowlist policy and tooling configuration; Endpoint protection deployment reports.
- NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind. Evidence to have on file: Security awareness program curriculum; Completion records by population.
- ISO 27001:2022 A.5.19 Information security in supplier relationships. Evidence to have on file: The topic-specific supplier relationship policy and its communication record; A supplier inventory categorized by type and by the information, services and infrastructure each can access.
- ISO 27001:2022 A.5.20 Addressing information security within supplier agreements. Evidence to have on file: Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms; A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed.
- ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain. Evidence to have on file: Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers; Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers.
- SOC 2 CC9.2 Assessing and managing vendor and business partner risk. Evidence to have on file: Vendor inventory with risk tiers and the review frequency set for each tier; Due diligence records, for example vendor SOC reports reviewed with complementary controls noted.
- SOC 2 P6.4 Privacy commitments from vendors and third parties. Evidence to have on file: Data processing agreements with privacy clauses; Periodic assessments of vendors' privacy compliance.
- NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders. Evidence to have on file: Third party risk management program charter; Supplier risk policy with tiering criteria.
- NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. Evidence to have on file: Standard supplier security requirements catalog; Contract clause library with cyber obligations.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- ISO 27001:2022 A.6.3 Information security awareness, education and training. Evidence to have on file: A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC3.3 Considering fraud risk (COSO principle 8). Evidence to have on file: Fraud risk assessment or fraud section of the enterprise risk assessment; Analysis of privileged access and data misuse scenarios.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
- ISO 27001:2022 A.5.19 Information security in supplier relationships. Evidence to have on file: The topic-specific supplier relationship policy and its communication record; A supplier inventory categorized by type and by the information, services and infrastructure each can access.
- ISO 27001:2022 A.5.20 Addressing information security within supplier agreements. Evidence to have on file: Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms; A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed.
- ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain. Evidence to have on file: Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers; Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers.
- SOC 2 CC9.2 Assessing and managing vendor and business partner risk. Evidence to have on file: Vendor inventory with risk tiers and the review frequency set for each tier; Due diligence records, for example vendor SOC reports reviewed with complementary controls noted.
- SOC 2 P6.4 Privacy commitments from vendors and third parties. Evidence to have on file: Data processing agreements with privacy clauses; Periodic assessments of vendors' privacy compliance.
- NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders. Evidence to have on file: Third party risk management program charter; Supplier risk policy with tiering criteria.
- NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. Evidence to have on file: Standard supplier security requirements catalog; Contract clause library with cyber obligations.
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
Map your own answers in the tool. The other worked answer is what counts as MFA on an application.