Appearance
Compliance Scorecard
Purpose: Track the current status of HIPAA, HITRUST, and SOC2 controls in one location so the Security Officer can see at a glance what is IMPLEMENTED, IN_PROGRESS, or a GAP before the September 2026 SOC2 audit.
Owner: Rory (Security Officer) Audience: Security Officer, auditors, Business Associates Update cadence: Weekly review of CRITICAL and HIGH gaps; full refresh first week of each month Last refreshed: 2026-06-27 (full refresh)
Status definitions
| Status | Meaning | SLA |
|---|---|---|
| IMPLEMENTED | Control is fully in place, evidence available | Verify annually |
| IN_PROGRESS | Control is partially implemented, work scheduled | Reach IMPLEMENTED within quarter |
| GAP | Control is missing or not yet designed | Must be mitigated, accepted, or closed before September audit |
Scorecard
| # | Control | Framework | Status | Evidence location | Last verified | Gap owner / target |
|---|---|---|---|---|---|---|
| 1 | Unique user identification | HIPAA §164.312(a)(1) / SOC2 CC6.1 | IMPLEMENTED | Entra ID user directory | 2026-04 | — |
| 2 | Emergency access procedure (break-glass) | HIPAA §164.312(a)(2)(i) | IMPLEMENTED | SecOps break-glass inventory (18 accounts), API block, hard-unsuppressible rule | 2026-04 | — |
| 3 | Automatic logoff | HIPAA §164.312(a)(2)(ii) | IMPLEMENTED | AVD session policy + Entra CA session controls | 2026-04 | — |
| 4 | Encryption at rest | HIPAA §164.312(a)(2)(iv) | IMPLEMENTED | Azure Disk Encryption, SQL TDE, KV CMK, S3 AES-256, EBS encryption | 2026-03 | — |
| 5 | Encryption in transit (TLS 1.2+) | HIPAA §164.312(e)(2)(ii) / SOC2 CC6.7 | IMPLEMENTED | Palo Alto decryption policy, cert monitoring | 2026-04 | — |
| 6 | Hardware/software activity logs | HIPAA §164.312(b) / SOC2 CC7.2 | IMPLEMENTED | cirius-logging-law-central (ID 5d76d1f2), AWS CloudTrail org trail | 2026-04 | — |
| 7 | Log retention 6-year WORM | HIPAA §164.316(b)(2)(i) / HITRUST 10.m | IMPLEMENTED | Azure blob WORM + S3 Object Lock (2190 days) | 2026-03 | — |
| 8 | Regular audit log review | HIPAA §164.312(b) | IMPLEMENTED | Weekly HIPAA audit email + monthly security review runbook | 2026-04 | — |
| 9 | Integrity (ePHI protection) | HIPAA §164.312(c)(1) / SOC2 PI1.2 | IMPLEMENTED | Veeam validation (Mar 2026), RSV immutability, FIM | 2026-03 | — |
| 10 | Authentication | HIPAA §164.312(d) / SOC2 CC6.1 | IMPLEMENTED | Entra ID MFA, Conditional Access, Maester weekly validation | 2026-04 | — |
| 11 | FIDO2 hardware keys for privileged accounts | Internal hardening / HITRUST 01.q | IN_PROGRESS | Procurement in flight; target deployment Q3 2026 | 2026-04 | Rory / Q3 2026 — see risk-acceptance-register.md |
| 12 | Transmission security | HIPAA §164.312(e)(1) | IMPLEMENTED | Palo Alto inspection, TLS, firewall segmentation | 2026-04 | — |
| 13 | Risk analysis | HIPAA §164.308(a)(1)(ii)(A) | IMPLEMENTED | Monthly pen test, Cloud Vulnerability Report, annual 3rd-party | 2026-04 | — |
| 14 | Risk management | HIPAA §164.308(a)(1)(ii)(B) / SOC2 CC3.2 | IMPLEMENTED | SecOps findings workflow, Checkov, Azure Policy, Security Hub | 2026-04 | — |
| 15 | Information system activity review | HIPAA §164.308(a)(1)(ii)(D) | IMPLEMENTED | Weekly HIPAA audit email, monthly security review | 2026-04 | — |
| 16 | Assigned Security Responsibility | HIPAA §164.308(a)(2) | IMPLEMENTED | Rory designated as Security Officer (BAA register, HR) | 2026-04 | — |
| 17 | Workforce security (authorization) | HIPAA §164.308(a)(3) | IN_PROGRESS | Entra PIM active; Keeper session recording requires PAM tier upgrade (Business tier does not include it — see keeper-license-audit.md) | 2026-06 | Rory / Q3 2026 |
| 18 | Workforce termination | HIPAA §164.308(a)(3)(ii)(C) | IMPLEMENTED | Kobe termination runbook, 4-hr SLA | 2026-04 | — |
| 19 | Information access management | HIPAA §164.308(a)(4) | IMPLEMENTED | Role-based Entra groups, PIM, quarterly LPRIV audit | 2026-04 | — |
| 20 | Security awareness and training | HIPAA §164.308(a)(5) | GAP | 0/4 staff completed 2026 annual KnowBe4 training (Q1 deadline missed). Phishing simulation data not yet logged. Must complete before September audit. | 2026-06 | Rory + Adriana / August 2026 |
| 21 | Security incident procedures | HIPAA §164.308(a)(6) / SOC2 CC7.3 | IMPLEMENTED | incident-response.md, SecOps workflow | 2026-04 | — |
| 22 | Contingency plan — data backup | HIPAA §164.308(a)(7)(ii)(A) | IMPLEMENTED | Veeam + RSV immutable + AWS S3 offsite | 2026-04 | — |
| 23 | Contingency plan — DR plan | HIPAA §164.308(a)(7)(ii)(B) | IMPLEMENTED | aws/dr-failover-procedure.md; Q2 test scheduled | 2026-04 | — |
| 24 | Contingency plan — emergency mode | HIPAA §164.308(a)(7)(ii)(C) | IN_PROGRESS | Runbook draft exists (compliance/emergency-mode-operation-plan.md); tabletop exercise to validate it is scheduled Q3 2026 alongside the DR test | 2026-06 | Rory / Q3 2026 |
| 25 | Contingency plan — testing and revision | HIPAA §164.308(a)(7)(ii)(D) | IN_PROGRESS | Q2 DR test not completed (missed June 27 fallback). Plan exists (q2-dr-test-plan-2026.md). Must execute before September audit. | 2026-06 | Rory / Q3 2026 |
| 26 | Evaluation (technical and non-technical) | HIPAA §164.308(a)(8) | IN_PROGRESS | Annual SOC2 audit scheduled September 2026 | 2026-04 | Rory / Sep 2026 |
| 27 | Business Associate Agreements | HIPAA §164.308(b)(1) / §164.314 | IN_PROGRESS | BAAs confirmed for Azure, AWS; Arctic Wolf, Keeper, Twingate, Cortex status TBD — see vendor-risk-inventory.md | 2026-06 | Adriana / Q3 2026 |
| 28 | Audit controls — AWS Audit Manager | HIPAA / SOC2 | IMPLEMENTED | AWS Audit Manager HIPAA-Omnibus-Jan-2013 framework, continuous assessment | 2026-04 | — |
| 29 | Azure Policy HIPAA/HITRUST initiative | HIPAA / HITRUST | IMPLEMENTED | Both PROD and DDE subscriptions, ISO 27001 also assigned | 2026-04 | — |
| 30 | AWS Security Hub NIST 800-53 R5 | SOC2 / NIST | IMPLEMENTED | Org-wide across 7 accounts | 2026-04 | — |
| 31 | Penetration testing | HITRUST 10.m / SOC2 CC7.1 | IMPLEMENTED | Three-layer programme: (1) Vonahi vPenTest — monthly automated internal scan appliance in Azure hub VNet, reports in app.vpentest.io; (2) attack-teams — weekly autonomous purple-team campaign (REDTEAM_BLACK external recon + REDTEAM_GREY Azure config audit + BLUETEAM detection validation), reports in SecOps and attack.bedrockcybersecurity.org, authorized 2026-04-20; (3) bedrock-soc external surface scan — Nmap + Nuclei against public domains + AWS ELBs, monthly cron. See compliance/pentest-results-log.md. | 2026-06 | — |
| 32 | Vulnerability management | HITRUST 10.b / SOC2 CC7.1 | IMPLEMENTED | Weekly dashboard, Cloud Vulnerability Report | 2026-04 | — |
| 33 | Change management | SOC2 CC8.1 | IMPLEMENTED | PR → CI → merge → auto CM ticket via SecOps | 2026-04 | — |
| 34 | Least privilege baseline | SOC2 CC6.3 | IMPLEMENTED | lpriv-baseline.md, quarterly LPRIV audit | 2026-04 | — |
| 35 | Privileged session recording | SOC2 CC6.1 / HITRUST 01.w | GAP | Keeper Business tier does not include session recording (see keeper-license-audit.md). KeeperPAM add-on or tier upgrade required. Compensating control: Entra PIM activation logs + Azure activity log. | 2026-06 | Rory / Q3 2026 — see risk-acceptance-register.md |
| 36 | EDR coverage on all endpoints | SOC2 CC6.8 / HITRUST 09.j | IMPLEMENTED | Cortex XDR on Windows + Arctic Wolf agents | 2026-04 | — |
| 37 | MDR 24×7 oversight | SOC2 CC7.3 | IMPLEMENTED | Arctic Wolf active across all managed VLCs | 2026-04 | — |
| 38 | Network segmentation | HITRUST 09.m / SOC2 CC6.6 | IMPLEMENTED | 4 Palo Alto VM-Series + Panorama, no prod/dev peering | 2026-04 | — |
| 39 | DNS Security | HITRUST 09.m / SOC2 CC6.6 | IMPLEMENTED | Palo Alto DNS Security live and blocking | 2026-04 | — |
| 40 | Cloud workload posture | SOC2 CC7.1 / HITRUST 09.s | IMPLEMENTED | Microsoft Defender for Cloud both tenants | 2026-04 | — |
| 41 | Tenant isolation (PROD vs DDE) | HIPAA §164.308(a)(4)(ii)(A) | IMPLEMENTED | Separate tenants, separate subs, no VNet peering | 2026-04 | — |
| 42 | Threat model (documented) | SOC2 CC3.2 | IMPLEMENTED | security/threat-model.md — canonical 2026 edition, 8 crown jewels, 4 actor profiles, STRIDE analysis, controls mapping. Companion docs aligned June 2026. Ready for auditor review. | 2026-06 | — |
| 43 | Incident response retainer | SOC2 CC7.3 / HITRUST 11.a | GAP | Vendor evaluation in progress — deferred past Q2 | 2026-04 | Rory / Q3 2026 — see risk-acceptance-register.md |
| 44 | Continuous vulnerability scanning (internal) | HITRUST 10.m | IMPLEMENTED | ops-automation weekly scan | 2026-04 | — |
| 45 | SSL/TLS certificate monitoring | HIPAA §164.312(e)(2)(ii) | IMPLEMENTED | 30/60/90 day expiration alerts | 2026-04 | — |
| 46 | CMDB maintained | SOC2 CC6.1 | IMPLEMENTED | security/cmdb-guide.md, quarterly audit | 2026-04 | — |
| 47 | Canary tokens | SOC2 CC7.1 | IMPLEMENTED | security/canary-token-inventory.md — CT-001/CT-002/CT-003/CT-004 all ACTIVE as of 2026-06-27 | 2026-06 | — |
| 48 | Deception layer | SOC2 CC7.1 | IMPLEMENTED | security/deception-layer.md — webhook receiver live at soc.bedrockcybersecurity.org/webhooks/canary | 2026-06 | — |
| 49 | FIM coverage verification | HITRUST 10.g | IMPLEMENTED | fim_agent + fim_dde_agent live in orchestrator; monitoring MDCFileIntegrityMonitoringEvents, 7-day staleness threshold. Azure-infra PRs #395 #431. | 2026-06 | — |
| 50 | Kill-chain detection coverage | SOC2 CC7.2 | IMPLEMENTED | Phase 1 ✅: EventID 4688 (645K/day), 4104 (92K/day), 4624/4648/4698/1102/7045/5140 all flowing to ops LAW. Phase 2 ✅: all 6 kill-chain agents live in orchestrator — execution, persistence, credential_dumping, lateral_movement, exfiltration, defense_evasion (+ DDE variants). | 2026-06 | — |
| 51 | pgaudit on psql-secops-prod | SOC2 CC7.2 | IMPLEMENTED | shared_preload_libraries = 'pgaudit' set in azure-infra/prod/secops.tf; Alembic migration a1b3c5d7e9f0 applied. Audit logs streaming to cirius-logging-law-central. | 2026-06 | — |
| 52 | Device compliance | SOC2 CC6.1 | IN_PROGRESS | CA-RemoteAccess-CompliantDeviceFIDO2 policy deployed in azure-infra/prod/conditional-access.tf (Intune compliance + FIDO2). Currently in report-only mode pending FIDO2 hardware rollout (row 11). Switches to enforced automatically when FIDO2 keys distributed. | 2026-06 | Rory / Q3 2026 (when FIDO2 deployed) |
Gap summary — pre-audit action list
Items that require active work before the September 2026 SOC2 audit. Rows marked IMPLEMENTED above are removed from this list.
| Gap | Status | Owner | Action |
|---|---|---|---|
| Security awareness training (row 20) | GAP | Rory + Adriana / August 2026 | Assign and complete KnowBe4 annual + HIPAA courses for all 4 staff. Must be done before September fieldwork. |
| Privileged session recording (row 35) | GAP | Rory / Q3 2026 | Keeper Business does not include session recording. Upgrade to KeeperPAM add-on or accept risk via risk-acceptance-register.md. Decision required before audit. |
| FIDO2 hardware keys (row 11) | IN_PROGRESS | Rory / Q3 2026 | Hardware procured; deploy for all privileged accounts Q3. Accepted risk documented in risk-acceptance-register.md. Completing this also flips row 52 to IMPLEMENTED. |
| Contingency emergency mode tabletop (row 24) | IN_PROGRESS | Rory / Q3 2026 | Runbook exists; schedule tabletop validation for Q3 alongside DR test. |
| DR test Q3 (row 25) | IN_PROGRESS | Rory / Q3 2026 | Q2 DR test missed. Plan in q2-dr-test-plan-2026.md — execute as Q3 test, log results in dr-test-results-log.md before September audit. |
| BAA backlog (row 27) | IN_PROGRESS | Adriana / Q3 2026 | 4 outstanding BAAs: Arctic Wolf, Keeper, Twingate, Cortex. Adriana to confirm status and get IN_FORCE before September. |
| IR retainer (row 43) | GAP | Rory / Q3 2026 | No IR retainer in place. Vendor evaluation in ir-retainer-evaluation.md. Risk accepted in risk-acceptance-register.md. Execute before September audit. |
| Device compliance enforcement (row 52) | IN_PROGRESS | Rory / Q3 2026 | CA policy in report-only pending FIDO2 rollout. Switches to enforced automatically with row 11. No independent action needed. |
How to keep this current
- Each gap row must have a named owner and target date
- When a row flips to IMPLEMENTED, update "Last verified" and move the action out of the gap list
- Any new control added to the environment is added as a new row within 7 days
- Annual recertification: every IMPLEMENTED row re-verified in December
Document history
| Date | Change | Author |
|---|---|---|
| April 2026 | Initial scorecard covering 52 controls across HIPAA, HITRUST, SOC2 | Kobe |
| June 2026 | Full refresh: rows 31/42/49/50/51 → IMPLEMENTED (three-layer pentest programme: vpentest monthly + attack-teams weekly + bedrock-soc external); rows 24/27/52 updated with correct dates and descriptions; gap summary rebuilt | Kobe |