ASPIS Cyber Security
SECURITY & COMPLIANCE

Security technology should be able to explain how it protects you.

ASPIS provides transparent information about the principles underlying its platform without exposing sensitive implementation detail.

Zero TrustTrust is continuously evaluated using identity, device posture, security state, and organizational policy.
Least privilegeAccess and administrative capability are limited by organizational role and operational requirement.
Defense in depthCommunications, endpoint, identity, policy, infrastructure, and monitoring provide layered protection.
EncryptionSupported communications are protected using modern cryptographic mechanisms appropriate to the channel and deployment.
Tenant isolationDeployment architecture can provide customer-specific isolation depending on product and infrastructure.
Customer controlApplicable deployments increase customer control over infrastructure, identity, policy, encryption architecture, and retention.
AuditabilityAdministrative, security, and compliance activity can be captured to support investigation and governance.

Compliance

Depending on product, configuration, and deployment, ASPIS capabilities may support customer programs associated with:

  • ISO 27001
  • SOC 2
  • HIPAA / HITECH
  • GDPR
  • PCI DSS
  • FINRA
  • SEC Rule 17a-4
  • GLBA
  • SOX
  • NIST
  • CMMC
  • FISMA
  • CJIS

Compliance depends on an organization’s complete technology environment, policies, processes, configuration, implementation, and operational practices. ASPIS solutions can support applicable security and compliance requirements but do not, by themselves, establish organizational compliance.