Comparison Overview

Yocha Dehe Wintun Nation

VS

ISSSTE

Yocha Dehe Wintun Nation

18960 Puhkum Road Brooks, California 95606, US
Last Update: 2025-03-14 (UTC)
Between 900 and 1000

Excellent

Yocha Dehe Wintun Nation is an independent, self-governed tribal nation located in Brooks, California. The Yocha Dehe Tribe is a sovereign Native American nation and is recognized by the United States. Operating under the Tribe’s own constitution and bylaws, the Tribal Council enacts laws that govern its own sovereign lands and enterprises. The Yocha Dehe Wintun Nation Tribal Council is the governing body of the Tribe. The Tribe enjoys a productive government-to-government relationship with the State of California and Yolo County. As the Tribe’s governing body, the Tribal Council negotiates government-to-government agreements with the State, the County and local agencies. The Tribal Council consists of five tribal citizens who are duly elected for three-year terms by the full Tribal Community Council. As a federally-recognized tribe, Yocha Dehe possesses the inherent authority to govern its own lands and people, and manage its own affairs, for the overall health and welfare of the Tribe and its citizens. Through an independent government, Yocha Dehe has established systems and operations designed to achieve the Tribe's various mission and values, which include fostering education and cultural renewal, protecting natural resources and achieving environmental sustainability, engaging in community giving and partnerships, securing economic self-sufficiency through sound business, and more generally, protecting the overall health and wellness of the Tribe's people. The Tribal Council oversees all areas of the tribal government and its business enterprises, evaluating and making final decisions with respect to the recommendations of the Tribe’s various departments and committees. The Tribe also owns and operates a number of business enterprises, including Cache Creek Casino Resort and the Séka Hills Olive Mill & Tasting Room.

NAICS: 922
NAICS Definition:
Employees: 51-200
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

ISSSTE

Last Update: 2025-03-14 (UTC)

Excellent

Between 900 and 1000

INSTITUTO DE SEGURIDAD Y SERVICIOS SOCIALES DE LOS TRABAJADORES DEL ESTADO. ES UN ORGANISMOS PÚBLICO QUE OTORGA SERVICIOS DE SALUD, PENSIONES, VIVIENDA, PRÉSTAMOS, ESTANCIAS INFANTILES, TURISMO, CULTURA, RECREACION, DEPORTE; CUYOS AFILIADOS SON TRABAJADORES DE DEPENDENCIAS GUBERNAMENTALES, CON DERECHO A LA SEGURIDAD SOCIAL. Y CUYOS OBJETIVOS INSTITUCIONALES ADEMÁS DE CONTRIBUIR A LOGRAR LOS OBJETIVOS PROPUESTOS POR EL PLAN NACIONAL DE DESARROLLO 2007 – 2012, COADYUVARÁN A LOGRAR LA VISIÓN DE LA INSTITUCIÓN ESTABLECIDA PARA EL AÑO 2030 Y CONCRETAR LA MISIÓN QUE TIENE ESTABLECIDA. MISIÓN DEL ISSSTE CONTRIBUIR A SATISFACER NIVELES DE BIENESTAR INTEGRAL DE LOS TRABAJADORES AL SERVICIO DEL ESTADO, PENSIONADOS, JUBILADOS Y FAMILIARES DERECHOHABIENTES, CON EL OTORGAMIENTO EFICAZ Y EFICIENTE DE LOS SEGUROS, PRESTACIONES Y SERVICIOS, CON ATENCIÓN ESMERADA, RESPETO, CALIDAD Y CUMPLIENDO SIEMPRE CON LOS VALORES INSTITUCIONALES DE HONESTIDAD, LEGALIDAD Y TRANSPARENCIA. VISIÓN DEL ISSSTE POSICIONAR AL ISSSTE COMO LA INSTITUCIÓN QUE GARANTICE LA PROTECCIÓN INTEGRAL DE LOS TRABAJADORES DE LA ADMINISTRACIÓN PÚBLICA FEDERAL, PENSIONADOS, JUBILADOS Y SUS FAMILIAS DE ACUERDO AL NUEVO PERFIL DEMOGRÁFICO DE LA DERECHOHABIENCIA, CON EL OTORGAMIENTO DE SEGUROS, PRESTACIONES Y SERVICIOS DE CONFORMIDAD CON LA NORMATIVIDAD VIGENTE, BAJO CÓDIGOS NORMADOS DE CALIDAD Y CALIDEZ, CON SOLVENCIA FINANCIERA, QUE PERMITAN GENERAR VALORES Y PRÁCTICAS QUE FOMENTEN LA MEJORA SOSTENIDA DE BIENESTAR, CALIDAD DE VIDA Y EL DESARROLLO DEL CAPITAL HUMANO. PARA CONOCER MAS DE NUESTRO INSTITUTO FAVOR DE CONSULTAR LA PAGINA INSTITUCIONAL WWW2.ISSSTE.GOB.MX EN DONDE SEGURAMENTE ENCONTRARAN MATERIAL DE ORIENTACION AMENO Y EXPLICATIVO ADEMAS DE LA HISTORIA DE INSTITUTO, SUS ALCANCES Y LOGROS ASI COMO LOS PROGRAMAS CON QUE CUENTA ACTUALMENTE EL INSTITUTO.

NAICS: 922
NAICS Definition:
Employees: 10,001+
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/yocha-dehe-wintun-nation.jpeg
Yocha Dehe Wintun Nation
ISO 27001
Not verified
SOC 2
Not verified
GDPR
No public badge
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/issste.jpeg
ISSSTE
ISO 27001
Not verified
SOC 2
Not verified
GDPR
No public badge
PCI DSS
No public badge
Compliance Summary
Yocha Dehe Wintun Nation
100%
Compliance Rate
0/4 Standards Verified
ISSSTE
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Government Administration Industry Average (This Year)

No incidents recorded for Yocha Dehe Wintun Nation in 2025.

Incidents vs Government Administration Industry Average (This Year)

No incidents recorded for ISSSTE in 2025.

Incident History — Yocha Dehe Wintun Nation (X = Date, Y = Severity)

Yocha Dehe Wintun Nation cyber incidents detection timeline including parent company and subsidiaries

Incident History — ISSSTE (X = Date, Y = Severity)

ISSSTE cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/yocha-dehe-wintun-nation.jpeg
Yocha Dehe Wintun Nation
Incidents

No Incident

https://images.rankiteo.com/companyimages/issste.jpeg
ISSSTE
Incidents

No Incident

FAQ

Both Yocha Dehe Wintun Nation company and ISSSTE company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Historically, ISSSTE company has disclosed a higher number of cyber incidents compared to Yocha Dehe Wintun Nation company.

In the current year, ISSSTE company and Yocha Dehe Wintun Nation company have not reported any cyber incidents.

Neither ISSSTE company nor Yocha Dehe Wintun Nation company has reported experiencing a ransomware attack publicly.

Neither ISSSTE company nor Yocha Dehe Wintun Nation company has reported experiencing a data breach publicly.

Neither ISSSTE company nor Yocha Dehe Wintun Nation company has reported experiencing targeted cyberattacks publicly.

Neither Yocha Dehe Wintun Nation company nor ISSSTE company has reported experiencing or disclosing vulnerabilities publicly.

Neither Yocha Dehe Wintun Nation company nor ISSSTE company has publicly disclosed detailed information about the number of their subsidiaries.

Neither Yocha Dehe Wintun Nation company nor ISSSTE company has publicly disclosed the exact number of their employees.

Latest Global CVEs (Not Company-Specific)

Description

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the token’s signature, expiration, issuer, or audience. If an attacker learns the victim’s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victim’s password. This issue has been patched in version 4.0.1.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Description

Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victim’s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victim’s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Description

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X