Due Diligence Workspace
5 in progress · 1 overdue · 1 pending approval
8
Total Reviews
5
In Progress
1
Overdue
1
Pending Approval
1
Not Started
Cybersecurity Review
In ProgressCriticalNorthStar Utility Billing Inc.
Evaluate vendor cybersecurity controls, incident response capability, and independent assessment status.
Due
2026-04-30
Reviewer
Kevin Tanaka
Control Checklist — Cybersecurity
0 of 12 items confirmedMulti-factor authentication enforced on all admin accounts
Encryption at rest for all city data
Encryption in transit (TLS 1.2+)
Centralized logging and SIEM in place
Vulnerability management program documented
Patch management SLA ≤30 days for critical patches
Endpoint detection and response (EDR) deployed
Identity and access management (IAM) policy
Incident response plan tested within 12 months
Independent security assessment (SOC 2 / pen test) current
Secure software development lifecycle (SDLC) if applicable
Third-party / supply chain risk program
Document observations, context, or exceptions relevant to this domain review.