SPMS
Security Posture
Posture
Overview
Applications
Findings
Work
Tasks
Incidents
Governance
Risk Register
Decisions
Compliance
Insight
KPIs
Audit Trail
Role Matrix
Acting as
Priya Shah
Chief Information Security Officer
Toggle Sidebar
7
PS
Priya Shah
Chief Information Security Officer
Security tasks
All security work items across the organization.
Board
List
New task
Total
60
In progress
15
Blocked
12
SLA breached
14
Backlog
8
SPMS-2024-00130
medium
Enable S3 default encryption org-wide
Marcus Lin
On track
SPMS-2024-00131
low
Q3 secure coding training — Payments team
Noor Idris
At risk
SPMS-2024-00143
low
Review and approve Encryption-at-Rest policy v3
Riley Chen
At risk
SPMS-2024-00147
medium
Implement WAF rule for credential stuffing
Sara Okafor
On track
SPMS-2024-00155
low
Fix IDOR in user export endpoint (pentest 2024Q2)
Riley Chen
At risk
SPMS-2024-00167
low
Implement WAF rule for credential stuffing
Tomas Hill
On track
SPMS-2024-00172
medium
Threat model: new checkout fraud service
Sara Okafor
At risk
SPMS-2024-00177
medium
Apply critical kernel patches across fleet
Aisha Banda
On track
In Progress
15
SPMS-2024-00120
critical
Patch openssl in container base image
Riley Chen
Breached
SPMS-2024-00124
medium
Publish updated Acceptable Use Policy
Sara Okafor
At risk
SPMS-2024-00126
critical
ISO 27001 A.12.4 — logging review
Aisha Banda
Breached
SPMS-2024-00129
medium
Disable root SSH on jumphost cluster
Riley Chen
On track
SPMS-2024-00135
medium
Fix IDOR in user export endpoint (pentest 2024Q2)
Sara Okafor
On track
SPMS-2024-00140
high
Patch openssl in container base image
Sara Okafor
Breached
SPMS-2024-00141
medium
Remediate SQLi in /api/orders/lookup
Sara Okafor
On track
SPMS-2024-00144
critical
Publish updated Acceptable Use Policy
Ben Carter
Breached
SPMS-2024-00145
high
Evidence collection — SOC2 CC6.1 access reviews Q3
Aisha Banda
On track
SPMS-2024-00148
medium
Add anomaly detection on payments-api auth (INC-204 P1)
Noor Idris
On track
SPMS-2024-00152
high
Threat model: new checkout fraud service
Riley Chen
At risk
SPMS-2024-00168
critical
Add anomaly detection on payments-api auth (INC-204 P1)
Marcus Lin
Breached
SPMS-2024-00169
high
Disable root SSH on jumphost cluster
Riley Chen
On track
SPMS-2024-00174
critical
Address external auditor finding A-12 (vendor MFA)
Tomas Hill
Breached
SPMS-2024-00176
high
Quarterly access review — production IAM
Ben Carter
Breached
In Review
9
SPMS-2024-00125
low
Evidence collection — SOC2 CC6.1 access reviews Q3
Noor Idris
On track
SPMS-2024-00127
high
Implement WAF rule for credential stuffing
Ben Carter
Breached
SPMS-2024-00128
high
Add anomaly detection on payments-api auth (INC-204 P1)
Sara Okafor
At risk
SPMS-2024-00137
low
Apply critical kernel patches across fleet
Ben Carter
On track
SPMS-2024-00154
medium
Address external auditor finding A-12 (vendor MFA)
Sara Okafor
At risk
SPMS-2024-00156
critical
Quarterly access review — production IAM
Riley Chen
Breached
SPMS-2024-00159
medium
Document incident response runbook for ransomware
Mei Wong
At risk
SPMS-2024-00161
low
Remediate SQLi in /api/orders/lookup
Sara Okafor
On track
SPMS-2024-00178
medium
Enable GuardDuty in 4 newly created accounts
Mei Wong
On track
Blocked
12
SPMS-2024-00121
high
Remediate SQLi in /api/orders/lookup
Sara Okafor
At risk
SPMS-2024-00122
high
Rotate leaked AWS access key
Sara Okafor
On track
SPMS-2024-00132
critical
Threat model: new checkout fraud service
Mei Wong
Breached
SPMS-2024-00134
high
Address external auditor finding A-12 (vendor MFA)
Mei Wong
Breached
SPMS-2024-00149
low
Disable root SSH on jumphost cluster
Aisha Banda
On track
SPMS-2024-00150
critical
Enable S3 default encryption org-wide
Aisha Banda
Breached
SPMS-2024-00153
medium
Decide on workload identity for k8s pods
Noor Idris
On track
SPMS-2024-00158
high
Enable GuardDuty in 4 newly created accounts
Marcus Lin
Breached
SPMS-2024-00163
high
Review and approve Encryption-at-Rest policy v3
Riley Chen
On track
SPMS-2024-00164
high
Publish updated Acceptable Use Policy
Ben Carter
Breached
SPMS-2024-00166
medium
ISO 27001 A.12.4 — logging review
Ben Carter
On track
SPMS-2024-00179
low
Document incident response runbook for ransomware
Noor Idris
On track
Done
16
SPMS-2024-00123
medium
Review and approve Encryption-at-Rest policy v3
Marcus Lin
Met
SPMS-2024-00133
high
Decide on workload identity for k8s pods
Tomas Hill
Met
SPMS-2024-00136
medium
Quarterly access review — production IAM
Mei Wong
Met
SPMS-2024-00138
critical
Enable GuardDuty in 4 newly created accounts
Riley Chen
Met
SPMS-2024-00139
high
Document incident response runbook for ransomware
Aisha Banda
Met
SPMS-2024-00142
medium
Rotate leaked AWS access key
Ben Carter
Met
SPMS-2024-00146
high
ISO 27001 A.12.4 — logging review
Marcus Lin
Met
SPMS-2024-00151
high
Q3 secure coding training — Payments team
Riley Chen
Met
SPMS-2024-00157
high
Apply critical kernel patches across fleet
Noor Idris
Met
SPMS-2024-00160
medium
Patch openssl in container base image
Tomas Hill
Met
SPMS-2024-00162
critical
Rotate leaked AWS access key
Marcus Lin
Met
SPMS-2024-00165
medium
Evidence collection — SOC2 CC6.1 access reviews Q3
Ben Carter
Met
SPMS-2024-00170
high
Enable S3 default encryption org-wide
Ben Carter
Met
SPMS-2024-00171
medium
Q3 secure coding training — Payments team
Marcus Lin
Met
SPMS-2024-00173
low
Decide on workload identity for k8s pods
Mei Wong
Met
SPMS-2024-00175
high
Fix IDOR in user export endpoint (pentest 2024Q2)
Aisha Banda
Met