Policy · pol-payments
Payments Security Policy
Controls (6)
| Control | Name | Domain |
|---|---|---|
| SOD-01 | Segregation of incompatible duties in SAP | Segregation of Duties |
| P2P-01 | Purchase orders follow approval thresholds; no self-approval | Procure-to-Pay |
| P2P-02 | Vendor master changes require dual control | Procure-to-Pay |
| ENC-01 | Customer and payment data encrypted at rest and in transit | Data Protection |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | Payments Security |
| PAY-02 | Payment release requires maker-checker | Payments Security |