8 controls
As of 9 Oct 2026
As of 9 Oct 2026
Filtered byApplication: Meridian Customer Portal ✕
| Control | Name | Domain | Applications | Q3 test | Open findings |
|---|---|---|---|---|---|
| CHG-01 | Production code changes are peer-reviewed and approved | Change Management | GitHub Enterprise Cloud, Meridian Customer Portal | Pass | 0 |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Logging & Monitoring | Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer Portal | Pass | 0 |
| ENC-01 | Customer and payment data encrypted at rest and in transit | Data Protection | Amazon Web Services (ap-south-1), Meridian Customer Portal | Pass | 0 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | Third-Party Risk | PayGate Payment Gateway, Meridian Customer Portal | Fail | 1 |
| KYC-01 | Customer accounts are activated only with complete KYC | Customer Onboarding | Meridian Customer Portal, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | Payments Security | PayGate Payment Gateway, Meridian Customer Portal | Pass | 0 |
| GOV-01 | IT Strategy Committee oversees IT and cyber risk | Governance | Meridian Customer Portal | Pass | 0 |
| GOV-02 | RBI regulatory changes are assessed for impact within 30 days | Governance | Meridian Customer Portal | Not tested | 0 |