THE BRONZE SHIELD

Compliance Mapping

Control alignment to NIST/ISO/RMF and data sovereignty requirements.

Control Coverage

RequirementHow We ComplyArtifact
Data ResidencyAll production data in DRC DCs; backups encrypted with state-owned keys.Hosting contract; KMS/HSM policy
NIST CSFIdentify–Protect–Detect–Respond–Recover mapped to services and SLAs.Control matrix; SOC runbooks
ISO 27001ISMS scope; policies; risk & treatment plans; audits.ISMS docs; SoA
RMFBaseline controls; ATO package; continuous monitoring.SSP; POA&M; ATO letter
PrivacyData minimization; DPIAs; access logging; breach notification.DPIA forms; audit trails