Security controls
Access control
- Automatically terminating user sessions after a defined period of inactivity.
- There is a documented approval process whereby authorized parties create user accounts and specify required privileges for user access to systems and data. Users require approval for requests to create information system accounts. Each request for information system access is tracked using a ticketing system.
- Using mechanisms (e.g. RBAC, LBAC, ABAC ) to enforce defined access restrictions.
Identification & authentication
- Requiring strong password complexity, length, and Multi-Factor Authentication (MFA).
- Ensuring each user and system component has a unique, non-shared identifier.
- Protecting the security and integrity of authentication data (e.g., securely hashing passwords).
Audit and accountability
- Identifying, generating, and logging critical events (e.g., login attempts, configuration changes).
- Encrypting and restricting access to log data at rest and in transit.
- Ensuring logs contain necessary details: event type, time, location, source, outcome, and user/object identity.
- Alerting personnel immediately if the logging system fails or log files are full.
System and info integrity
- Timely identification, reporting, and remediation (patching) of known software and firmware vulnerabilities following NIST standards.
- Employing and regularly updating anti-malware and intrusion detection software on systems at respective patching cycles.
- Continuous monitoring of system components for unauthorized activity, attacks, or security breaches (using IDS/IPS/SIEM/EDR).
System and communications protection
- Network segmentation, firewalls, load balancers, and gateways have been implemented and are actively managed to maintain and enforce secure system boundaries.
- Encryption in transit is enforced for all external and sensitive internal communications, utilizing secure protocols such as TLS 1.2.
- Encryption at rest is enforced for all stored data, including databases, file systems, and backups, using industry-standard encryption algorithms and methods.
Configuration management
- A formal, documented, and secure minimum configuration (security baseline) has been established and is enforced across all systems.
- All changes to hardware, software, and firmware are required to follow a formal, documented approval process.
- We use automated monitoring to quickly detect any unauthorized hardware, software, or firmware in our systems. If detected, we immediately block the component and notify our security team to ensure your data remains protected.
Incident response
- Conducting periodic simulated exercises (e.g., tabletop exercises) to test the effectiveness of the plan and procedures.
- We maintain a documented process for analyzing, containing, eradicating, and recovering from security incidents to ensure rapid and effective response.
- We continuously monitor for threats using advanced security tools (e.g., SIEM/IDS/EDR) and act immediately to block and resolve any detected risks.
- We maintain clear communication channels and defined timelines to report security incidents to the appropriate internal and external parties
Contingency planning
- Developed a formal plan outlining roles, responsibilities, and procedures for maintaining essential operations during and after a disruption.
- Perform regular scheduled backups of all system data, software, and configurations, and verify backup integrity to ensure recoverability.
- We have defined procedures to quickly restore systems and data from secure backups, ensuring minimal disruption and fast recovery.
Physical and environmental protection
- We control physical access to our facilities and data centers using badges, biometrics, and strict visitor procedures.
- 24/7 video surveillance and on-site security personnel monitor access points and sensitive areas.
- Automated fire detection and suppression systems are in place to protect our data centers.
Media protection
- We ensure all media is securely sanitized before disposal or reuse, using approved methods such as such as cryptographic erase, secure wiping, or physical destruction are used to ensure data cannot be recovered.
Awareness and training
- All users receive annual security awareness training covering phishing identification, incident response procedures, and password protection, in alignment with organizational security policies and regulatory requirements.
Personnel security
- Background checks are conducted on all personnel prior to granting access to organizational systems, in accordance with security and regulatory requirements.
- Formal procedures are implemented to promptly revoke access rights and recover organizational assets upon employee separation or role change.
Get in touch
Connect with us to scale up the potential of your programs
