Skip to content

13.20 Security

  • As an InfoSec officer, I want SIEM to surface anomalies.
  • As an engineer, I want secrets vaulted and rotated.
  • As a borrower, I want my PII encrypted and access-controlled.
  • POST /pii/tokenize, POST /pii/detokenize (audited).
  • GET /security/incidents.
  • pii_token, incident, vuln, pen_test.
  • InfoSec console: incidents, vulns, pen test findings.
  • PII vault.
  • SIEM integration.
  • IR orchestration.
  • KMS / Vault.
  • SIEM vendor.
  • Pen test partner.
  • PII tokenised at write.
  • Detokenize logged per call.
  • Vulnerability ticket auto-created.
  • Pen test finding tracked.
  • PII leak in log → DLP catches.
  • Cred rotation cascading.
  • Insider threat.
  • PII tokenisation 100% on inbound.
  • Pen test annual.
  • Material cyber incident reportable in < 6h.
  • Quarterly access review.