Test · TST-Q2-ENC-01
ENC-01 · Customer and payment data encrypted at rest and in transit
PassQ2 2026 Unified Program ReviewTested 12 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.8.24 · RBI-DPSC-2021-4 · SOC2-C1.1 · SOC2-CC6.1 · SOC2-CC6.7
mapped
Policy
Payments Security Policy
pol-payments
Control
ENC-01
Customer and payment data encrypted at rest and in transit
Application
Amazon Web Services (ap-south-1) · Meridian Customer Portal
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-SOC2-ENC-01 · High confidence
Finding
None
Action
None
Validation
Not planned
Procedure and result
- Procedure
- AWS KMS CMKs, ALB TLS policy. Tests: Amazon Web Services (ap-south-1): RDS and S3 encryption enabled; Meridian Customer Portal: TLS configuration on portal endpoints. Frequency continuous.
- Sample
- 25 items sampled (Q2 baseline)
- Expected
- Customer PII, KYC documents and payment data are encrypted at rest with KMS-managed keys and in transit with TLS 1.2+; keys are rotated annually.
- Observed
- No exceptions in the sample; encryption of sensitive data operated as designed.
- Confidence
- High