Cybersecurity Shared Responsibility Model
Overview
Our Cybersecurity Shared Responsibility Model is designed to provide a comprehensive approach to security and compliance by clearly defining control ownership across the application environment. This model explicitly highlights the shared nature of cybersecurity, encompassing controls supported by Istari Digital and the Customer.
The model divides security controls into three distinct categories, clearly indicating the implementation responsibility:
- Inherited: Security controls managed entirely by Istari Digital, which the customer benefits from without direct action.
- Customer: Security controls that the customer is solely responsible for implementing and maintaining within their environment.
- Hybrid: Controls with shared responsibilities, requiring a combination of efforts from Istari Digital and the Customer to implement specific security aspects.
Figure 3.1: Security Control Allocation by Responsibility
These controls serve as a foundation for shared responsibility discussions and may be adjusted based on specific customer cybersecurity requirements. Istari Digital will consistently review these controls and notify the customer if the status of any Shared Responsibility changes.
The control alignment for the Cybersecurity Shared Responsibility Model is based on the Cybersecurity Maturity Model Certification (CMMC) Level 2 process and governed by the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 3 framework.
Inherited Controls
These are security controls that customers inherit from the Istari Platform. Customers benefit from these controls without direct action, as they are embedded in the service provided by Istari Digital.
| Control | Control Title | Implementation Narrative |
|---|---|---|
| IA.L2-3.5.10 | Cryptographically Protected Passwords | The Istari Digital Platform obscures and encrypts passwords used in conjunction with the Istari Platform. |
| IA.L2-3.5.11 | Obscure Feedback | The Istari Digital Platform obscures feedback for unauthorized login attempts. |
| SC.L2-3.13.2 | Security Engineering | Istari Digital manages our software development lifecycle using a DevSecOps approach, including the following software release activities: Unit/Integration Testing (Requires 80% Code Coverage to meet Government Certification to Field requirement); Dependency Check and Container Scans (Involves scanning against Common Vulnerability Scoring System findings with a manual review for anything higher than 7); Secrets Detection; Static Code and Quality Analysis; Artifact Signing. |
| IA.L2-3.5.4 | Replay-Resistant Authentication | Authentication is handled with a combination of a single use session token and the credentialing hash. Both components are required for an authenticated request. |
| SI-L2-3.14.3 | Security Alerts & Advisories | Istari Digital receives security alerts and advisories relevant to its operations. Should Istari Digital software be affected, appropriate notification pipelines will be activated, and the customer will be informed as necessary, in accordance with established service level agreements (SLAs). |
Hybrid Controls
This category signifies a shared responsibility between the customer and Istari Digital, where Istari Digital typically provides the capability and the customer is responsible for its configuration and use. Istari Digital provides the platform or feature, but the customer must configure it or use it correctly.
| Control | Control Title | Implementation Narrative |
|---|---|---|
| AC.L2-3.1.9 | Privacy & Security Notices | The Istari Digital Platform provides the customer with configurable banners consistent with the requirements of this control which must be set by the system owner upon deployment. |
| CM.L2-3.4.2 | Security Configuration Enforcement | The Istari Digital Platform maintains a system baseline for platform configurations, published at https://docs.istaridigital.com/releases/. Customers are responsible for configuration and maintenance of their respective infrastructure. |
| IA.L2-3.5.5 | Identifier Reuse | Istari supplements the customer's capability by establishing Unique Unit Identifiers (UUIDs) for every piece of data and its subcomponents that are registered with the Istari platform. This ensures a consistent and traceable baseline for all digital assets. Customers are responsible for configuration of system identifiers for their respective infrastructure. |
| AC.L1-3.1.1 | Authorized Access Control | The Istari Digital Platform utilizes Zitadel (Identity) and Spice DB (Authorization) for identity and access management (IAM), implemented locally within the Control Plane. These IAM controls rely on role-based access, allowing for granular adjustments specific to each model within the platform. Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment. |
| AC.L2-3.1.3 | Control CUI Flow | The Istari Digital Platform restricts system services from accessing data in a manner that could potentially expose the protected models. With the use of single use/signed URLs and various encryption methods, protected models can only be accessed by approved tools and services within the Data Plane. This is also limited to authorized end users of the platform as configured by the customer. Customers are responsible for making sure their data is labeled appropriately. |
| AC.L2-3.1.10 | Session Lock | Istari Digital enables automated session locks through the Istari Admin Panel. The customer is responsible for adjusting the control settings to meet their needs. |
| AT.L2-3.2.1 | Role-based Risk Awareness | Recommendations for this control include all Defense and Industrial Base and Government users completing the following training or equivalent prior to receiving access to the Istari Digital Platform Environment: 1) Security Awareness: https://securityawareness.usalearning.gov/cybersecurity/index.htm 2) CUI: https://securityawareness.usalearning.gov/cui/index.html 3) Insider Threat: https://securityawareness.usalearning.gov/itawareness/index.htm. While Istari Digital maintains its own acceptable use and training policy consistent with the above recommendations, the customer is responsible for controlling access and maintaining training requirements on their systems. |
| AT.L2-3.2.2 | Role-based Training | Recommendations for this control include all Defense and Industrial Base and Government users completing the following training or equivalent prior to receiving access to the Istari Digital Platform Environment: 1) Security Awareness: https://securityawareness.usalearning.gov/cybersecurity/index.htm 2) CUI: https://securityawareness.usalearning.gov/cui/index.html 3) Insider Threat: https://securityawareness.usalearning.gov/itawareness/index.htm. While Istari Digital maintains its own acceptable use and training policy consistent with the above recommendations, the customer is responsible for controlling access and maintaining training requirements on their systems. |
| AT.L2-3.2.3 | Insider Threat Awareness | Recommendations for this control include all Defense and Industrial Base and Government users completing the following training or equivalent prior to receiving access to the Istari Digital Platform Environment: 1) Security Awareness: https://securityawareness.usalearning.gov/cybersecurity/index.htm 2) CUI: https://securityawareness.usalearning.gov/cui/index.html 3) Insider Threat: https://securityawareness.usalearning.gov/itawareness/index.htm. While Istari Digital maintains its own acceptable use and training policy consistent with the above recommendations, the customer is responsible for controlling access and maintaining training requirements on their systems. |
| CM.L2-3.4.1 | System Baselining | The Istari Digital Platform maintains a system baseline for platform configurations, published at https://docs.istaridigital.com/releases/. Customers are responsible for configuration and maintenance of their respective infrastructure. |
| CM.L2-3.4.6 | Least Functionality | Istari Digital continually ensures that native systems and services operate with only the minimum functionality required to effectively complete authorized and necessary actions. Additional configurations may be required based on requirements of the customer environment to limit nonessential actions and enforce the principle of least privilege. |
| CM.L2-3.4.7 | Nonessential Functionality | Istari Digital continually ensures that native systems and services operate with only the minimum functionality required to effectively complete authorized and necessary actions. Additional configurations may be required based on requirements of the customer environment to limit nonessential actions and enforce the principle of least privilege. |
| CM.L2-3.4.8 | Application Execution Policy | Istari Digital continually ensures that native systems and services operate with only the minimum functionality required to effectively complete authorized and necessary actions. Additional configurations may be required based on requirements of the customer environment to limit nonessential actions and enforce the principle of least privilege. |
| IA.L1-3.5.1 | Identification | The Istari Platform implements identity and access management controls using Zitadel. Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment. |
| IA.L1-3.5.2 | Authentication | The Istari Digital Platform supports the use of Multi-Factor Authentication (MFA). Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment. |
| IA.L2-3.5.3 | Multifactor Authentication | The Istari Digital Platform supports the use of Multi-Factor Authentication (MFA). Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment. |
| IR-L2-3.6.1 | Incident Handling | Istari Digital maintains an operational incident-handling capability for its systems, encompassing preparation, analysis, containment, and recovery. We also identify vulnerabilities within the software development pipeline and communicate necessary patches. Customers are notified of any vulnerabilities affecting their systems in accordance with established service level agreements. The customer is responsible for responding to their environment, including tracking, documenting, and internally reporting incidents, as well as communicating them between organizations when necessary. |
| IR-L2-3.6.2 | Incident Reporting | Istari Digital maintains an operational incident-handling capability for its systems, encompassing preparation, analysis, containment, and recovery. We also identify vulnerabilities within the software development pipeline and communicate necessary patches. Customers are notified of any vulnerabilities affecting their systems in accordance with established service level agreements. The customer is responsible for responding to their environment, including tracking, documenting, and internally reporting incidents, as well as communicating them between organizations when necessary. |
| IR-L2-3.6.3 | Incident Response Testing | Istari Digital maintains an operational incident-handling capability for its systems, encompassing preparation, analysis, containment, and recovery. We also identify vulnerabilities within the software development pipeline and communicate necessary patches. Customers are notified of any vulnerabilities affecting their systems in accordance with established service level agreements. The customer is responsible for responding to their environment, including tracking, documenting, and internally reporting incidents, as well as communicating them between organizations when necessary. |
| PS.L2-3.9.1 | Screen Individuals | Istari Digital currently implements an onboarding/offboarding system that includes personnel screening, background checks and certification of appropriate citizenship status. This is maintained for as long as access is required. Customers are responsible for implementing their own process to screen individuals that have access to the Istari Platform. |
| PS.L2-3.9.2 | Personnel Actions | Istari Digital currently implements an onboarding/offboarding system that includes personnel screening, background checks and certification of appropriate citizenship status. This is maintained for as long as access is required. Customers are responsible for implementing their own process to screen individuals that have access to the Istari Platform. |
| SC.L2-3.13.3 | Role Separation | Istari Digital has configured the platform for user functionality and system management to be identified through two different authentication pipelines. Customers are responsible for implementing their user base to utilize those mechanisms. |
| SC.L2-3.13.4 | Shared Resource Control | Istari Digital's Platform integrates microsegmentation of data with controlled access permissioned to respect individual user access, data sensitivity, and overarching handling caveats. In addition, the Platform's multitenancy capability enables data segregation. Customers are responsible for ensuring resources are appropriately configured. |
| SC.L2-3.13.8 | Data in Transit | The Istari Platform is built to run off FIPS validated encryption algorithms such as TLS. Communication from the agent to the platform is configured to work over Port 443. Customers are responsible for ensuring encryption configurations are appropriately set. |
| SC.L2-3.13.11 | CUI Encryption | The Istari Platform is built to run off FIPS validated encryption algorithms such as TLS. Communication from the agent to the platform is configured to work over Port 443. Customers are responsible for ensuring encryption configurations are appropriately set. |
| SC.L2-3.13.15 | Communications Authenticity | Istari protects the authenticity of communication sessions by implementing the following: Transport Layer Security (TLS) protocol; Multifactor Authentication required for system login. Customers are responsible for ensuring communication authenticity is appropriately configured for their systems. |
| SC.L2-3.13.16 | Data at Rest | The Istari Digital Platform supports Data at Rest Encryption. Customers are responsible for ensuring organizational key management is in place to leverage this capability. |
| SI-L1-3.14.1 | Flaw Remediation | Istari Digital conducts monthly risk and vulnerability assessments as part of its software development lifecycle. If a vulnerability is identified, an appropriate notification will be provided to all relevant stakeholders in accordance with service level agreements (SLAs) to support informed risk management. Customers are responsible for implementing timely system patches to maintain a compliant risk posture. |
| SI-L1-3.14.2 | Malicious Code Protection | Istari Digital maintains malicious code protection within the backend of the platform. Customers are responsible for ensuring their systems have the same protection and that the data they process through the Istari Platform is safe. |
| SI-L1-3.14.4 | Update Malicious Code Protection | Istari Digital maintains malicious code protection within the platform's backend. Customers are responsible for ensuring their own systems have equivalent protection and that the data they process through the Istari Platform is secure. |
| AC.L2-3.1.12 | Control Remote Access | Customers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data. |
| AC.L2-3.1.13 | Remote Access Confidentiality | Customers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data. |
| AC.L2-3.1.15 | Privileged Remote Access | Customers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data. |
| AC.L1-3.1.2 | Transaction & Function Control | The customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| AC.L2-3.1.4 | Separation of Duties | The customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| AC.L2-3.1.5 | Least Privilege | The customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| AC.L2-3.1.6 | Non-Privilege Account Use | The customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| AC.L2-3.1.7 | Privileged Functions | The customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| AC.L2-3.1.20 | External Connections | Customers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data. |
| IA.L2-3.5.7 | Password Complexity | The customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| IA.L2-3.5.8 | Password Reuse | The customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| IA.L2-3.5.9 | Temporary Passwords | The customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| RA.L2-3.11.1 | Risk Assessments | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| RA.L2-3.11.2 | Vulnerability Scan | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| RA.L2-3.11.3 | Vulnerability Remediation | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
Customer Controls
The remaining controls are the customer's responsibility. They include securing customer data, customer tenant environments, client-side data encryption and integrity, and the security of customer-created or managed applications. The customer must implement these controls to ensure their data is appropriately protected.
| Control | Control Title | Implementation Narrative |
|---|---|---|
| SI-L1-3.14.5 | System & File Scanning | Istari Digital maintains malicious code protection within the platform's backend. Customers are responsible for ensuring their own systems have equivalent protection and that the data they process through the Istari Platform is secure. |
| SI-L2-3.14.6 | Monitor Communications for Attacks | All Istari Platform-driven interactions are captured via standard OpenTelemetry (OTel) logging. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. Customers are responsible for configuring SIEM solutions to monitor logs. |
| SI-L2-3.14.7 | Identify Unauthorized Use | All Istari Platform-driven interactions are captured via standard OpenTelemetry (OTel) logging. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. Customers are responsible for configuring SIEM solutions to monitor logs. |
| AC.L2-3.1.11 | Session Termination | Istari enables configuration of session termination settings within the Istari Platform Admin console. Customers are responsible for setting session timeouts in accordance with relevant cybersecurity standards. |
| MA.L2-3.7.1 | Perform Maintenance | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MA.L2-3.7.2 | System Maintenance Control | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MA.L2-3.7.3 | Equipment Sanitization | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MA.L2-3.7.4 | Media Inspection | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MA.L2-3.7.5 | Nonlocal Maintenance | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MA.L2-3.7.6 | Maintenance Personnel | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.1 | Media Protection | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.2 | Media Access | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L1-3.8.3 | Media Disposal | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.4 | Media Markings | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.5 | Media Accountability | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.6 | Portable Storage Encryption | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.7 | Removable Media | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.8 | Shared Media | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| MP.L2-3.8.9 | Protect Backups | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| PE.L1-3.10.1 | Limit Physical Access | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| PE.L2-3.10.2 | Monitor Facility | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| PE.L1-3.10.3 | Escort Visitors | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| PE.L1-3.10.4 | Physical Access Logs | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| PE.L1-3.10.5 | Manage Physical Access | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| PE.L2-3.10.6 | Alternative Work Sites | Customers are responsible for configuration and maintenance of their respective infrastructure. |
| SC.L2-3.13.13 | Mobile Code | Customers are responsible for configuration of their infrastructure to limit the use of mobile code. |
| AC.L2-3.1.8 | Unsuccessful Logon Attempts | Zitadel enables setting of system limits on the number of failed logon attempts. Customers are responsible for configuration to meet their system needs. |
| AC.L2-3.1.14 | Remote Access Routing | Customers are responsible for Remote Access Routing. |
| AC.L2-3.1.16 | Wireless Access Authorization | Customers are responsible for configuration of wireless and mobile devices. |
| AC.L2-3.1.17 | Wireless Access Protection | Customers are responsible for configuration of wireless and mobile devices. |
| AC.L2-3.1.18 | Mobile Device Connection | Customers are responsible for configuration of wireless and mobile devices. |
| AC.L2-3.1.19 | Encrypt CUI on mobile | Customers are responsible for configuration of wireless and mobile devices. |
| AC.L2-3.1.21 | Portable Storage Use | Customers are responsible for Portable Storage Use. |
| AC.L2-3.1.22 | Control Public Information | Customers are responsible for Control of their Public Information. |
| AU-L2-3.3.1 | System Auditing | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.2 | User Accountability | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.3 | Event Review | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.4 | Audit Failure Alerting | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.5 | Audit Correlation | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.6 | Reduction & Reporting | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.7 | Authoritative Time Source | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.8 | Audit Protection | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| AU-L2-3.3.9 | Audit Management | Istari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. |
| CA.L2-3.12.1 | Security Control Assessment | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CA.L2-3.12.2 | Plan of Action and Milestones | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CA.L2-3.12.3 | Security Control Monitoring | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CA.L2-3.12.4 | System Security Plan | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CM.L2-3.4.3 | System Change Management | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CM.L2-3.4.4 | Security Impact Analysis | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CM.L2-3.4.5 | Access Restrictions for Change | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| CM.L2-3.4.9 | User-Installed Software | Istari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates. |
| IA.L2-3.5.6 | Identifier Handling | The customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning. |
| SC.L1-3.13.1 | Boundary Protection | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L1-3.13.5 | Public-Access System Separation | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L2-3.13.6 | Network Communication by Exception | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L2-3.13.7 | Split Tunneling | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L2-3.13.9 | Connections Termination | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L2-3.13.10 | Key Management | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L2-3.13.12 | Collaborative Device Control | Boundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture. |
| SC.L2-3.13.14 | Voice over Internet Protocol (VoIP) | Not Applicable. Istari does not integrate with VoIP devices. |