Compliance
PCI
Compliance with PCI DSS (Payment Card Industry Data Security Standard) requires organizations that handle payment card data to implement security controls that protect cardholder information. This includes measures for network security, access control, encryption, vulnerability management, and regular monitoring to prevent data breaches and fraud.
NYS 23 NYCRR 500 (NY DFS)
Compliance with NYS 23 NYCRR 500 (NY DFS) involves adhering to New York State's cybersecurity regulation for financial services companies. It requires covered entities to implement a cybersecurity program, maintain written policies, conduct risk assessments, report breaches, and ensure oversight of third-party service providers to protect sensitive customer data and financial systems.
SOC 2 Type 2
IN PROGRESS - Compliance with SOC 2 involves implementing and maintaining controls that ensure the security, availability, processing integrity, confidentiality, and privacy of customer data. It is based on the AICPA’s Trust Services Criteria and is validated through an independent audit to demonstrate an organization’s commitment to protecting data and operating with transparency.
Monitoring
Resources
FIANT Security Scorecard Rating
SecurityScorecard provides an external cybersecurity rating for Fiant based on key risk categories such as network security, patching cadence, IP reputation, and endpoint protection. It offers a snapshot of Fiant’s overall security posture and vendor risk exposure, helping stakeholders assess cyber risk independently of internal disclosures
FIANT Cybersecurity Policies & Procedures
This document outlines Fiant's core cybersecurity policies, including data management, access controls, system monitoring, technical safeguards, and employee training. It supports compliance with SOC 2, NIST CSF, NYDFS, and PCI DSS.
FIANT Information Security Policy
Fiant’s Information Security Policy outlines key security roles, data protection practices, risk management, and compliance measures. It provides external stakeholders with a high-level view of the company's approach to safeguarding information assets.
FIANT Third-Party Vendor Management Policy
Fiant’s Third-Party Vendor Management Policy outlines standardized procedures for evaluating, onboarding, monitoring, and offboarding vendors. It ensures vendors meet security, risk, and compliance requirements.
FIANT Risk Assessment & Treatment Policye
Fiant’s Risk Assessment & Treatment Policy outlines the company's structured approach to identifying, evaluating, and mitigating risks to information systems and data. It supports regulatory compliance and emphasizes governance.
FIANT Business Continuity & Disaster Recover Policy
Fiant’s BC/DR Policy outlines its strategy for maintaining business operations and restoring services during disruptions. It details roles, recovery metrics (RTO/RPO), incident response, vendor coordination, and testing practices.
FIANT Standards for Safeguarding Customer Information
Fiant’s Safeguarding Customer Information Policy outlines standards for protecting customer data, including access controls, encryption, incident response, third-party oversight, and employee training. It supports compliance with GLBA, NYDFS, PCI DSS, and NIST CSF.
