Skip to content

Compliance Scorecard

Purpose: Track the current status of HIPAA, HITRUST, and SOC2 controls in one location so the Security Officer can see at a glance what is IMPLEMENTED, IN_PROGRESS, or a GAP before the September 2026 SOC2 audit.

Owner: Rory (Security Officer) Audience: Security Officer, auditors, Business Associates Update cadence: Weekly review of CRITICAL and HIGH gaps; full refresh first week of each month Last refreshed: 2026-06-27 (full refresh)


Status definitions

StatusMeaningSLA
IMPLEMENTEDControl is fully in place, evidence availableVerify annually
IN_PROGRESSControl is partially implemented, work scheduledReach IMPLEMENTED within quarter
GAPControl is missing or not yet designedMust be mitigated, accepted, or closed before September audit

Scorecard

#ControlFrameworkStatusEvidence locationLast verifiedGap owner / target
1Unique user identificationHIPAA §164.312(a)(1) / SOC2 CC6.1IMPLEMENTEDEntra ID user directory2026-04
2Emergency access procedure (break-glass)HIPAA §164.312(a)(2)(i)IMPLEMENTEDSecOps break-glass inventory (18 accounts), API block, hard-unsuppressible rule2026-04
3Automatic logoffHIPAA §164.312(a)(2)(ii)IMPLEMENTEDAVD session policy + Entra CA session controls2026-04
4Encryption at restHIPAA §164.312(a)(2)(iv)IMPLEMENTEDAzure Disk Encryption, SQL TDE, KV CMK, S3 AES-256, EBS encryption2026-03
5Encryption in transit (TLS 1.2+)HIPAA §164.312(e)(2)(ii) / SOC2 CC6.7IMPLEMENTEDPalo Alto decryption policy, cert monitoring2026-04
6Hardware/software activity logsHIPAA §164.312(b) / SOC2 CC7.2IMPLEMENTEDcirius-logging-law-central (ID 5d76d1f2), AWS CloudTrail org trail2026-04
7Log retention 6-year WORMHIPAA §164.316(b)(2)(i) / HITRUST 10.mIMPLEMENTEDAzure blob WORM + S3 Object Lock (2190 days)2026-03
8Regular audit log reviewHIPAA §164.312(b)IMPLEMENTEDWeekly HIPAA audit email + monthly security review runbook2026-04
9Integrity (ePHI protection)HIPAA §164.312(c)(1) / SOC2 PI1.2IMPLEMENTEDVeeam validation (Mar 2026), RSV immutability, FIM2026-03
10AuthenticationHIPAA §164.312(d) / SOC2 CC6.1IMPLEMENTEDEntra ID MFA, Conditional Access, Maester weekly validation2026-04
11FIDO2 hardware keys for privileged accountsInternal hardening / HITRUST 01.qIN_PROGRESSProcurement in flight; target deployment Q3 20262026-04Rory / Q3 2026 — see risk-acceptance-register.md
12Transmission securityHIPAA §164.312(e)(1)IMPLEMENTEDPalo Alto inspection, TLS, firewall segmentation2026-04
13Risk analysisHIPAA §164.308(a)(1)(ii)(A)IMPLEMENTEDMonthly pen test, Cloud Vulnerability Report, annual 3rd-party2026-04
14Risk managementHIPAA §164.308(a)(1)(ii)(B) / SOC2 CC3.2IMPLEMENTEDSecOps findings workflow, Checkov, Azure Policy, Security Hub2026-04
15Information system activity reviewHIPAA §164.308(a)(1)(ii)(D)IMPLEMENTEDWeekly HIPAA audit email, monthly security review2026-04
16Assigned Security ResponsibilityHIPAA §164.308(a)(2)IMPLEMENTEDRory designated as Security Officer (BAA register, HR)2026-04
17Workforce security (authorization)HIPAA §164.308(a)(3)IN_PROGRESSEntra PIM active; Keeper session recording requires PAM tier upgrade (Business tier does not include it — see keeper-license-audit.md)2026-06Rory / Q3 2026
18Workforce terminationHIPAA §164.308(a)(3)(ii)(C)IMPLEMENTEDKobe termination runbook, 4-hr SLA2026-04
19Information access managementHIPAA §164.308(a)(4)IMPLEMENTEDRole-based Entra groups, PIM, quarterly LPRIV audit2026-04
20Security awareness and trainingHIPAA §164.308(a)(5)GAP0/4 staff completed 2026 annual KnowBe4 training (Q1 deadline missed). Phishing simulation data not yet logged. Must complete before September audit.2026-06Rory + Adriana / August 2026
21Security incident proceduresHIPAA §164.308(a)(6) / SOC2 CC7.3IMPLEMENTEDincident-response.md, SecOps workflow2026-04
22Contingency plan — data backupHIPAA §164.308(a)(7)(ii)(A)IMPLEMENTEDVeeam + RSV immutable + AWS S3 offsite2026-04
23Contingency plan — DR planHIPAA §164.308(a)(7)(ii)(B)IMPLEMENTEDaws/dr-failover-procedure.md; Q2 test scheduled2026-04
24Contingency plan — emergency modeHIPAA §164.308(a)(7)(ii)(C)IN_PROGRESSRunbook draft exists (compliance/emergency-mode-operation-plan.md); tabletop exercise to validate it is scheduled Q3 2026 alongside the DR test2026-06Rory / Q3 2026
25Contingency plan — testing and revisionHIPAA §164.308(a)(7)(ii)(D)IN_PROGRESSQ2 DR test not completed (missed June 27 fallback). Plan exists (q2-dr-test-plan-2026.md). Must execute before September audit.2026-06Rory / Q3 2026
26Evaluation (technical and non-technical)HIPAA §164.308(a)(8)IN_PROGRESSAnnual SOC2 audit scheduled September 20262026-04Rory / Sep 2026
27Business Associate AgreementsHIPAA §164.308(b)(1) / §164.314IN_PROGRESSBAAs confirmed for Azure, AWS; Arctic Wolf, Keeper, Twingate, Cortex status TBD — see vendor-risk-inventory.md2026-06Adriana / Q3 2026
28Audit controls — AWS Audit ManagerHIPAA / SOC2IMPLEMENTEDAWS Audit Manager HIPAA-Omnibus-Jan-2013 framework, continuous assessment2026-04
29Azure Policy HIPAA/HITRUST initiativeHIPAA / HITRUSTIMPLEMENTEDBoth PROD and DDE subscriptions, ISO 27001 also assigned2026-04
30AWS Security Hub NIST 800-53 R5SOC2 / NISTIMPLEMENTEDOrg-wide across 7 accounts2026-04
31Penetration testingHITRUST 10.m / SOC2 CC7.1IMPLEMENTEDThree-layer programme: (1) Vonahi vPenTest — monthly automated internal scan appliance in Azure hub VNet, reports in app.vpentest.io; (2) attack-teams — weekly autonomous purple-team campaign (REDTEAM_BLACK external recon + REDTEAM_GREY Azure config audit + BLUETEAM detection validation), reports in SecOps and attack.bedrockcybersecurity.org, authorized 2026-04-20; (3) bedrock-soc external surface scan — Nmap + Nuclei against public domains + AWS ELBs, monthly cron. See compliance/pentest-results-log.md.2026-06
32Vulnerability managementHITRUST 10.b / SOC2 CC7.1IMPLEMENTEDWeekly dashboard, Cloud Vulnerability Report2026-04
33Change managementSOC2 CC8.1IMPLEMENTEDPR → CI → merge → auto CM ticket via SecOps2026-04
34Least privilege baselineSOC2 CC6.3IMPLEMENTEDlpriv-baseline.md, quarterly LPRIV audit2026-04
35Privileged session recordingSOC2 CC6.1 / HITRUST 01.wGAPKeeper Business tier does not include session recording (see keeper-license-audit.md). KeeperPAM add-on or tier upgrade required. Compensating control: Entra PIM activation logs + Azure activity log.2026-06Rory / Q3 2026 — see risk-acceptance-register.md
36EDR coverage on all endpointsSOC2 CC6.8 / HITRUST 09.jIMPLEMENTEDCortex XDR on Windows + Arctic Wolf agents2026-04
37MDR 24×7 oversightSOC2 CC7.3IMPLEMENTEDArctic Wolf active across all managed VLCs2026-04
38Network segmentationHITRUST 09.m / SOC2 CC6.6IMPLEMENTED4 Palo Alto VM-Series + Panorama, no prod/dev peering2026-04
39DNS SecurityHITRUST 09.m / SOC2 CC6.6IMPLEMENTEDPalo Alto DNS Security live and blocking2026-04
40Cloud workload postureSOC2 CC7.1 / HITRUST 09.sIMPLEMENTEDMicrosoft Defender for Cloud both tenants2026-04
41Tenant isolation (PROD vs DDE)HIPAA §164.308(a)(4)(ii)(A)IMPLEMENTEDSeparate tenants, separate subs, no VNet peering2026-04
42Threat model (documented)SOC2 CC3.2IMPLEMENTEDsecurity/threat-model.md — canonical 2026 edition, 8 crown jewels, 4 actor profiles, STRIDE analysis, controls mapping. Companion docs aligned June 2026. Ready for auditor review.2026-06
43Incident response retainerSOC2 CC7.3 / HITRUST 11.aGAPVendor evaluation in progress — deferred past Q22026-04Rory / Q3 2026 — see risk-acceptance-register.md
44Continuous vulnerability scanning (internal)HITRUST 10.mIMPLEMENTEDops-automation weekly scan2026-04
45SSL/TLS certificate monitoringHIPAA §164.312(e)(2)(ii)IMPLEMENTED30/60/90 day expiration alerts2026-04
46CMDB maintainedSOC2 CC6.1IMPLEMENTEDsecurity/cmdb-guide.md, quarterly audit2026-04
47Canary tokensSOC2 CC7.1IMPLEMENTEDsecurity/canary-token-inventory.md — CT-001/CT-002/CT-003/CT-004 all ACTIVE as of 2026-06-272026-06
48Deception layerSOC2 CC7.1IMPLEMENTEDsecurity/deception-layer.md — webhook receiver live at soc.bedrockcybersecurity.org/webhooks/canary2026-06
49FIM coverage verificationHITRUST 10.gIMPLEMENTEDfim_agent + fim_dde_agent live in orchestrator; monitoring MDCFileIntegrityMonitoringEvents, 7-day staleness threshold. Azure-infra PRs #395 #431.2026-06
50Kill-chain detection coverageSOC2 CC7.2IMPLEMENTEDPhase 1 ✅: EventID 4688 (645K/day), 4104 (92K/day), 4624/4648/4698/1102/7045/5140 all flowing to ops LAW. Phase 2 ✅: all 6 kill-chain agents live in orchestrator — execution, persistence, credential_dumping, lateral_movement, exfiltration, defense_evasion (+ DDE variants).2026-06
51pgaudit on psql-secops-prodSOC2 CC7.2IMPLEMENTEDshared_preload_libraries = 'pgaudit' set in azure-infra/prod/secops.tf; Alembic migration a1b3c5d7e9f0 applied. Audit logs streaming to cirius-logging-law-central.2026-06
52Device complianceSOC2 CC6.1IN_PROGRESSCA-RemoteAccess-CompliantDeviceFIDO2 policy deployed in azure-infra/prod/conditional-access.tf (Intune compliance + FIDO2). Currently in report-only mode pending FIDO2 hardware rollout (row 11). Switches to enforced automatically when FIDO2 keys distributed.2026-06Rory / Q3 2026 (when FIDO2 deployed)

Gap summary — pre-audit action list

Items that require active work before the September 2026 SOC2 audit. Rows marked IMPLEMENTED above are removed from this list.

GapStatusOwnerAction
Security awareness training (row 20)GAPRory + Adriana / August 2026Assign and complete KnowBe4 annual + HIPAA courses for all 4 staff. Must be done before September fieldwork.
Privileged session recording (row 35)GAPRory / Q3 2026Keeper Business does not include session recording. Upgrade to KeeperPAM add-on or accept risk via risk-acceptance-register.md. Decision required before audit.
FIDO2 hardware keys (row 11)IN_PROGRESSRory / Q3 2026Hardware procured; deploy for all privileged accounts Q3. Accepted risk documented in risk-acceptance-register.md. Completing this also flips row 52 to IMPLEMENTED.
Contingency emergency mode tabletop (row 24)IN_PROGRESSRory / Q3 2026Runbook exists; schedule tabletop validation for Q3 alongside DR test.
DR test Q3 (row 25)IN_PROGRESSRory / Q3 2026Q2 DR test missed. Plan in q2-dr-test-plan-2026.md — execute as Q3 test, log results in dr-test-results-log.md before September audit.
BAA backlog (row 27)IN_PROGRESSAdriana / Q3 20264 outstanding BAAs: Arctic Wolf, Keeper, Twingate, Cortex. Adriana to confirm status and get IN_FORCE before September.
IR retainer (row 43)GAPRory / Q3 2026No IR retainer in place. Vendor evaluation in ir-retainer-evaluation.md. Risk accepted in risk-acceptance-register.md. Execute before September audit.
Device compliance enforcement (row 52)IN_PROGRESSRory / Q3 2026CA policy in report-only pending FIDO2 rollout. Switches to enforced automatically with row 11. No independent action needed.

How to keep this current

  • Each gap row must have a named owner and target date
  • When a row flips to IMPLEMENTED, update "Last verified" and move the action out of the gap list
  • Any new control added to the environment is added as a new row within 7 days
  • Annual recertification: every IMPLEMENTED row re-verified in December

Document history

DateChangeAuthor
April 2026Initial scorecard covering 52 controls across HIPAA, HITRUST, SOC2Kobe
June 2026Full refresh: rows 31/42/49/50/51 → IMPLEMENTED (three-layer pentest programme: vpentest monthly + attack-teams weekly + bedrock-soc external); rows 24/27/52 updated with correct dates and descriptions; gap summary rebuiltKobe

Internal use only — Cirius Group