Compliance Score
98.4%
▲ 1.2% vs Q3
Open Findings
12
▼ 3% vs last audit
Avg. Retention Cycle
3.2 yrs
Within SLA
Last Penetration Test
2026-04-12
Next: 2026-10-15

Information Security Framework

Zero Trust Architecture

All network traffic, internal and external, is treated as untrusted by default. Continuous verification of identity, device health, and context is enforced across all 400 subsidiaries.

STD-INFOSEC-001 | ENFORCED

Encryption Standards

AES-256-GCM for data at rest, TLS 1.3+ for data in transit. FIPS 140-3 Level 2 validated modules required for all financial and healthcare subsystems.

STD-INFOSEC-004 | ENFORCED

Network Segmentation

Micro-segmentation isolates critical assets. East-west traffic is filtered via software-defined perimeters. IoT/OT networks are strictly air-gapped or proxied.

STD-INFOSEC-007 | ENFORCED

Endpoint Detection & Response

Centralized EDR deployment across all corporate and remote devices. Automated containment protocols trigger on anomalous behavior or known IOCs.

STD-INFOSEC-012 | ENFORCED

Data Retention Matrix

Data Category Retention Period Disposal Method Regulatory Scope Status
Financial Records (GAAP/IFRS) 7 Years Certified Shredding / Crypto-erase SOC 2, SOX, PCI-DSS Regulated
Employee HR Files 5 Years Post-Termination Secure Deletion / Archival Vault GDPR, CCPA, Local Labor Laws Standard
Healthcare/Patient Data 10 Years HIPAA-Compliant Purge HIPAA, HITECH, ISO 27799 Regulated
Source Code & IP Indefinite Air-gapped Backup / DRM Internal Trade Sec Policy Archival
Network Logs & SIEM Data 1 Year (Hot) / 3 Years (Cold) Overwrite / Immutable WORM ISO 27001, NIST 800-53 Standard
Marketing & Analytics 2 Years Anonymization / Aggregate Retention GDPR, CCPA, ePrivacy Standard

Access Control & IAM Protocols

Multi-Factor Authentication (MFA) Requirements

All Aevum Zenth assets require phishing-resistant MFA (FIDO2/WebAuthn or hardware tokens). SMS/TOTP is deprecated for privileged accounts. Conditional access policies evaluate device compliance, geolocation, and risk score before granting session tokens.

Role-Based Access Control (RBAC) & Least Privilege

Permissions are assigned via centralized IdP synchronized with HRIS. Access follows strict least-privilege models. Quarterly access reviews are mandatory. Privileged access workstations (PAW) are required for administrative functions. Just-in-Time (JIT) elevation is enforced for Tier 1+ systems.

Offboarding & Credential Revocation

Upon termination or role change, access is revoked within 15 minutes via automated HR-IT integration. Service accounts undergo mandatory rotation. Data ownership is transferred to designated delegates. Former credentials are quarantined for 90 days for forensic audit purposes.

Incident Response & Reporting

  1. Detection & Triage: Automated alerts routed to SOC Tier 1. Initial severity classification (SEV 1-4) within 15 minutes.
  2. Containment: Isolate affected endpoints/segments. Preserve forensic artifacts. Activate incident command structure.
  3. Eradication & Recovery: Remove threat vectors. Patch vulnerabilities. Restore from verified clean backups. Validate system integrity.
  4. Post-Incident Review: Root cause analysis. Update playbooks. Report to executive steering committee within 72 hours.
📞 24/7 Security Hotline: ext. 9111 | 📧 report@security.aevumzenth.internal | 🔗 Incident Portal: #/portal/incidents

Quick Actions & Resources