Meridian Alpha

Records

13 controls
As of 9 Oct 2026
Filtered byAssured: yes ✕
ControlNameDomainApplicationsQ3 testOpen findings
ACC-01MFA and SSO enforced for workforce accessAccess ControlAmazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise CloudPass0
ACC-02User access provisioning is approved before grantAccess ControlMicrosoft Entra ID, SAP S/4HANA, ServiceNow ITSMPass0
JML-01Leavers are de-provisioned within 24 hoursJoiner/Mover/LeaverDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAPass0
P2P-02Vendor master changes require dual controlProcure-to-PaySAP S/4HANAPass0
CHG-01Production code changes are peer-reviewed and approvedChange ManagementGitHub Enterprise Cloud, Meridian Customer PortalPass0
CHG-03Developers have no standing production access; deployments via pipeline onlyChange ManagementAmazon Web Services (ap-south-1), GitHub Enterprise CloudPass0
LOG-01Security events are centrally logged and monitored 24x7Logging & MonitoringAmazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer PortalPass0
OPS-01Backups are performed daily and monitoredOperations & ResilienceAmazon Web Services (ap-south-1), Microsoft Azure (corporate)Pass0
BCP-01Backup restore and DR are testedOperations & ResilienceAmazon Web Services (ap-south-1), Microsoft Azure (corporate)Pass0
ENC-01Customer and payment data encrypted at rest and in transitData ProtectionAmazon Web Services (ap-south-1), Meridian Customer PortalPass0
PAY-01Payment APIs secured with mTLS, signing and customer 2FAPayments SecurityPayGate Payment Gateway, Meridian Customer PortalPass0
PAY-02Payment release requires maker-checkerPayments SecuritySAP S/4HANAPass0
GOV-01IT Strategy Committee oversees IT and cyber riskGovernanceMeridian Customer PortalPass0