Put the executive summary on page 2, before the table of contents.
Some checks are pending
ci / markdown (push) Waiting to run
Some checks are pending
ci / markdown (push) Waiting to run
The cover stays page 1. Numbered chapters now start at What Verae provides. The TOC lists Executive summary at page 2.
This commit is contained in:
parent
5df7ed87d5
commit
8496ef8338
23 changed files with 759 additions and 723 deletions
|
|
@ -5,19 +5,19 @@
|
|||
<meta charset="utf-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||
|
||||
<title>12. Audit-ready checklist — Making yourself audit-ready with Verae DataCubes</title>
|
||||
<title>11. Audit-ready checklist — Making yourself audit-ready with Verae DataCubes</title>
|
||||
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=2d7b7068" />
|
||||
<script src="_static/documentation_options.js?v=250a654d"></script>
|
||||
<script src="_static/doctools.js?v=fd6eb6e6"></script>
|
||||
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
|
||||
<link rel="icon" href="_static/VeraeFullLogo.png"/>
|
||||
<link rel="index" title="Index" href="genindex.html" />
|
||||
<link rel="search" title="Search" href="search.html" />
|
||||
<link rel="next" title="13. How to use this briefing" href="howto.html" />
|
||||
<link rel="prev" title="11. BAAs, DPAs, and ciphertext without host keys" href="baa-dpa.html" />
|
||||
<link rel="next" title="12. How to use this briefing" href="howto.html" />
|
||||
<link rel="prev" title="10. BAAs, DPAs, and ciphertext without host keys" href="baa-dpa.html" />
|
||||
|
||||
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
|
||||
|
||||
|
|
@ -61,41 +61,40 @@
|
|||
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
|
||||
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
|
||||
<ul class="current">
|
||||
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
|
||||
<li class="toctree-l1 current"><a class="current reference internal" href="#">12. Audit-ready checklist</a><ul>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#a-scope-and-honesty">12.1. A. Scope and honesty</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#b-data-in-transit">12.2. B. Data in transit</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#c-data-at-rest">12.3. C. Data at rest</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#d-timestamping">12.4. D. Timestamping</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#e-write-once-archive">12.5. E. Write-once archive</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#f-access-and-change">12.6. F. Access and change</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#g-contracts-counsel">12.7. G. Contracts (counsel)</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#h-independent-examination-of-this-organization">12.8. H. Independent examination of <em>this</em> organization</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">1. What Verae provides — and what it does not</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">2. The Verae DataCube Server Solution</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">3. Secure communications — data in transit</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">4. Encryption at rest — IPFS blocks and Peergos</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">5. Global timestamped receipts</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">6. Peergos security evaluations in Europe</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">7. Verae global timestamping — a cross-blockchain receipt</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">8. Write-once Iceberg archive</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="architecture.html">9. Architecture for an audit interview</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">10. BAAs, DPAs, and ciphertext without host keys</a></li>
|
||||
<li class="toctree-l1 current"><a class="current reference internal" href="#">11. Audit-ready checklist</a><ul>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#a-scope-and-honesty">11.1. A. Scope and honesty</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#b-data-in-transit">11.2. B. Data in transit</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#c-data-at-rest">11.3. C. Data at rest</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#d-timestamping">11.4. D. Timestamping</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#e-write-once-archive">11.5. E. Write-once archive</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#f-access-and-change">11.6. F. Access and change</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#g-contracts-counsel">11.7. G. Contracts (counsel)</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#h-independent-examination-of-this-organization">11.8. H. Independent examination of <em>this</em> organization</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="howto.html">12. How to use this briefing</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">13. James H. Garfinkel</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">14. Stuart Haber</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">15. George Lambert</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="contact.html">16. Verae Inc — contact</a></li>
|
||||
</ul>
|
||||
|
||||
<div class="relations">
|
||||
<h3>Related Topics</h3>
|
||||
<ul>
|
||||
<li><a href="index.html">Documentation overview</a><ul>
|
||||
<li>Previous: <a href="baa-dpa.html" title="previous chapter"><span class="section-number">11. </span>BAAs, DPAs, and ciphertext without host keys</a></li>
|
||||
<li>Next: <a href="howto.html" title="next chapter"><span class="section-number">13. </span>How to use this briefing</a></li>
|
||||
<li>Previous: <a href="baa-dpa.html" title="previous chapter"><span class="section-number">10. </span>BAAs, DPAs, and ciphertext without host keys</a></li>
|
||||
<li>Next: <a href="howto.html" title="next chapter"><span class="section-number">12. </span>How to use this briefing</a></li>
|
||||
</ul></li>
|
||||
</ul>
|
||||
</div>
|
||||
|
|
@ -116,13 +115,13 @@
|
|||
<div class="body" role="main">
|
||||
|
||||
<section id="audit-ready-checklist">
|
||||
<h1><span class="section-number">12. </span>Audit-ready checklist<a class="headerlink" href="#audit-ready-checklist" title="Link to this heading">¶</a></h1>
|
||||
<h1><span class="section-number">11. </span>Audit-ready checklist<a class="headerlink" href="#audit-ready-checklist" title="Link to this heading">¶</a></h1>
|
||||
<p>Use this as a working list. Check an item only when
|
||||
<strong>evidence exists</strong> (screenshot, log export, signed policy,
|
||||
ticket, receipt). This list is not a certificate. Software
|
||||
having been installed does not tick these boxes.</p>
|
||||
<section id="a-scope-and-honesty">
|
||||
<h2><span class="section-number">12.1. </span>A. Scope and honesty<a class="headerlink" href="#a-scope-and-honesty" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.1. </span>A. Scope and honesty<a class="headerlink" href="#a-scope-and-honesty" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>Named legal entity and systems in scope (console, Drive,
|
||||
message fabric, IPFS, timestamping link, Iceberg archive)</p></li>
|
||||
|
|
@ -137,7 +136,7 @@ security evaluation</strong></p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="b-data-in-transit">
|
||||
<h2><span class="section-number">12.2. </span>B. Data in transit<a class="headerlink" href="#b-data-in-transit" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.2. </span>B. Data in transit<a class="headerlink" href="#b-data-in-transit" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>Production algorithm is HPKE (or documented successor),
|
||||
not a lab construction</p></li>
|
||||
|
|
@ -150,7 +149,7 @@ mode 0600 or HSM</p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="c-data-at-rest">
|
||||
<h2><span class="section-number">12.3. </span>C. Data at rest<a class="headerlink" href="#c-data-at-rest" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.3. </span>C. Data at rest<a class="headerlink" href="#c-data-at-rest" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>Customer holds Peergos / Drive keys; not on storage host</p></li>
|
||||
<li><p>Peergos hash verification on write and on read, evidenced</p></li>
|
||||
|
|
@ -160,7 +159,7 @@ ciphertext <strong>without</strong> a plaintext tape</p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="d-timestamping">
|
||||
<h2><span class="section-number">12.4. </span>D. Timestamping<a class="headerlink" href="#d-timestamping" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.4. </span>D. Timestamping<a class="headerlink" href="#d-timestamping" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>First-registration rule documented and tested (second
|
||||
submit returns original receipt)</p></li>
|
||||
|
|
@ -173,7 +172,7 @@ the data map</p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="e-write-once-archive">
|
||||
<h2><span class="section-number">12.5. </span>E. Write-once archive<a class="headerlink" href="#e-write-once-archive" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.5. </span>E. Write-once archive<a class="headerlink" href="#e-write-once-archive" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>Iceberg (or equivalent) export job exists and has a dated
|
||||
last-run</p></li>
|
||||
|
|
@ -185,7 +184,7 @@ engineering folklore</p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="f-access-and-change">
|
||||
<h2><span class="section-number">12.6. </span>F. Access and change<a class="headerlink" href="#f-access-and-change" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.6. </span>F. Access and change<a class="headerlink" href="#f-access-and-change" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>Console requires authentication (TOTP or equivalent);
|
||||
Drive login is a separate plane</p></li>
|
||||
|
|
@ -197,7 +196,7 @@ prev + new + diff</p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="g-contracts-counsel">
|
||||
<h2><span class="section-number">12.7. </span>G. Contracts (counsel)<a class="headerlink" href="#g-contracts-counsel" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.7. </span>G. Contracts (counsel)<a class="headerlink" href="#g-contracts-counsel" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>Written BA / not-a-BA determination for disk, VM, backup,
|
||||
IPFS, Iceberg</p></li>
|
||||
|
|
@ -208,7 +207,7 @@ IPFS, Iceberg</p></li>
|
|||
</ul>
|
||||
</section>
|
||||
<section id="h-independent-examination-of-this-organization">
|
||||
<h2><span class="section-number">12.8. </span>H. Independent examination of <em>this</em> organization<a class="headerlink" href="#h-independent-examination-of-this-organization" title="Link to this heading">¶</a></h2>
|
||||
<h2><span class="section-number">11.8. </span>H. Independent examination of <em>this</em> organization<a class="headerlink" href="#h-independent-examination-of-this-organization" title="Link to this heading">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><p>SOC 2 Type I/II engagement, <strong>or</strong> ISO 27001 registrar,
|
||||
<strong>or</strong> HIPAA risk analysis plus policies — <strong>the program
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue