> For the complete documentation index, see [llms.txt](https://incident-tracker.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://incident-tracker.gitbook.io/docs/support/security/nist-csf-alignment.md).

# NIST CSF Alignment

## NIST Cybersecurity Framework Alignment

Incident Tracker’s approach to cybersecurity aligns with the [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework), which provides a structured and flexible methodology to identify, manage, and reduce security risks.

This page summarizes how our internal policies, procedures, and technical safeguards map to the five core functions of NIST CSF.

***

### Identify

We maintain visibility into assets, risks, and roles related to our information systems.

* **Asset Management**: All cloud infrastructure is hosted in Microsoft Azure and inventoried.
* **Governance**: Information Security Program
* **Risk Management**: Internal penetration testing, UpGuard scanning, and internal reviews
* **Business Context**: Incident Tracker serves clients across healthcare, education, and government sectors with varying regulatory requirements.
* **Third-Party Risk**: No third-party processors have access to customer data without a signed agreement.

***

### Protect

We implement strong safeguards to protect systems, data, and identities.

* **Access Control**: Role-based access control, granular user rights, and group sync via Microsoft Entra (Azure AD).
* **Data Security**:
  * All data in transit is encrypted using TLS 1.2+
  * All data at rest is encrypted using AES-256 via Microsoft Azure
* **Awareness & Training**: Annual security training for all personnel
* **Data Backup**: Azure-based backups with granular retention from daily to 7 years (see Azure Backup Summary)
* **Protective Technology**: Application-level firewall, Microsoft Defender for Cloud, session fixation protection

***

### Detect

We have robust capabilities to detect anomalies and potential security events.

* **Monitoring**: UptimeRobot, Azure Defender for Cloud, UpGuard
* **Detection Processes**: Logs, audit trails, and security event reviews are performed daily
* **Logging**: All user actions, including IP address and timestamp, are stored for at least one year

***

### Respond

We have documented plans and processes to contain and mitigate incidents.

* **Incident Response Plan**
* **Breach Notification**: Customers are notified within 72 hours of confirmed incidents.
* **Root Cause Analysis**: Performed in collaboration with internal and insurance-provided forensic experts.
* **Response Coordination**: Cross-functional security response team is led by executive management.

***

### Recover

We ensure resilience and restoration of operations through structured recovery planning.

* **Business Continuity Plan**: Disaster recovery RTO = 8 hours, RPO = 6 hours
* **Backups**: Server and SQL data is backed up multiple times daily with long-term retention (up to 7 years)
* **Testing**: Annual testing of DR procedures; employees trained on remote work and recovery protocols
* **Customer Assurance**: Full data export available upon request in Excel, PDF, and ZIP formats.
