KeldynAI logo

Trust Center

KeldynAI

KeldynAI Trust Center

KeldynAI shares its compliance posture and security control coverage.

Controls

Access Control

  • Access control

    Establish and implement rules to control physical and logical access to information and other associated assets based on business and information security requirements.

  • Access rights

    Provision, review, modify, and remove access rights to information and other associated assets in accordance with the organization's access control policy and rules.

  • Access to source code

    Manage read and write access to source code, development tools, and software libraries appropriately.

  • Authentication information

    Control allocation and management of authentication information through a defined management process, including advising personnel on appropriate handling of authentication information.

  • Identity management

    Manage the full lifecycle of identities — creation, verification, provisioning, suspension, and deactivation — ensuring every identity is accounted for.

  • Information access restriction

    Restrict access to information and other associated assets in accordance with the established topic-specific policy on access control.

  • Privileged access rights

    Restrict and manage the allocation and use of privileged access rights.

  • Secure authentication

    Implement secure authentication mechanisms proportional to the sensitivity of the accessed resource, based on information access restrictions and the access control policy.

  • Use of privileged utility programs

    Restrict and tightly control the use of privileged utility programs capable of overriding system and application controls. Limit access to authorized personnel and log all usage.

Asset Management

  • Acceptable use of information and other associated assets

    Identify, document, and implement rules for acceptable use and handling procedures for information and other associated assets.

  • Classification of information

    Classify information according to confidentiality, integrity, availability needs, and relevant interested party requirements using a defined classification scheme.

  • Data leakage prevention

    Implement data leakage prevention controls across systems, networks, and devices that process, store, or transmit sensitive information to detect and block unauthorized data exfiltration.

  • Data masking

    Apply data masking in accordance with the organization's access control policy and other related topic-specific policies, business requirements, and applicable legislation.

  • Information transfer

    Establish information transfer rules, procedures, or agreements for all types of transfer facilities within the organization and between the organization and other parties.

  • Inventory of information and other associated assets

    Develop and maintain an inventory of information and other associated assets, including designated owners, covering the full asset lifecycle.

  • Labelling of information

    Develop and implement labelling procedures for information assets in accordance with the adopted classification scheme.

Availability

  • Auto-scaling configuration

    Processing capacity is configured to auto-scale to meet processing demand.

Business Continuity

  • ICT readiness for business continuity

    Plan, implement, maintain, and test ICT readiness for business continuity based on business continuity objectives and ICT continuity requirements.

  • Information backup

    Maintain backup copies of information, software, and systems in accordance with the agreed topic-specific policy on backup. Test restoration procedures at planned intervals to verify recoverability.

  • Information security during disruption

    Plan how to maintain information security at an appropriate level during disruption, including alternative procedures and compensating controls.

  • Redundancy of information processing facilities

    Implement information processing facilities with redundancy sufficient to meet availability requirements.

Change Management

  • Change management

    Subject changes to information processing facilities and information systems to change management procedures.

  • Information security in project management

    Integrate information security requirements, risk assessments, and security controls into project management processes for all projects regardless of type.

Children's data

  • Child Consent Verification

    Implement age verification and parental consent mechanisms for information society services offered directly to children, ensuring processing is lawful only where the child meets the applicable age threshold or consent is given or authorised by the holder of parental responsibility

Codes and certification

  • Compliance Certification Readiness

    Assess available approved codes of conduct and data protection certification mechanisms for their applicability to the organization's processing activities, and document the evaluation outcome to support demonstration of GDPR compliance

Competence and awareness

  • Awareness

    Ensure personnel are aware of the information security policy, their contribution to ISMS effectiveness, and the implications of non-conformance with ISMS requirements.

  • Communication

    Determine the need for internal and external communications relevant to the ISMS, including what, when, with whom, and how to communicate.

  • Competence

    Determine required competencies for personnel affecting information security performance, ensure competence through education, training, or experience, take actions to close identified competence gaps and evaluate the effectiveness of those actions, and retain documented evidence of competence.

  • Resources

    Determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS.

Compliance

  • Compliance with policies, rules and standards for information security

    Regularly review compliance with the organization's information security policy, topic-specific policies, rules, and standards, and address identified deviations.

  • Independent review of information security

    Commission independent reviews of the organization's approach to managing information security and its implementation, including people, processes, and technologies, at planned intervals or when significant changes occur.

  • Intellectual property rights

    Implement appropriate procedures to protect intellectual property rights, including software copyright and licences.

  • Legal, statutory, regulatory and contractual requirements

    Identify, document, and keep up to date all legal, statutory, regulatory, and contractual requirements relevant to information security, along with the organization's approach to meeting them.

  • Privacy and protection of personal identifiable information (PII)

    Identify and meet requirements for the preservation of privacy and protection of personally identifiable information (PII) according to applicable laws, regulations, and contractual requirements.

  • Protection of records

    Protect records from loss, destruction, falsification, unauthorized access, and unauthorized release throughout their retention period.

Confidentiality

  • Boundaries of confidential data

    Confidential data is maintained within the system boundaries at all times where security controls are applied to restrict access to authorised individuals.

  • Data management policy

    The requirements for managing data are established in the data classification, handling, retention and disposal policies.

  • Register of confidential data

    A register of the types and sources of confidential data collected and processed is maintained to track assets and storage locations of confidential data.

Controller-processor responsibilities

  • Processor Contract

    If a Data Processor is involved, execute a contract defining the subject matter, duration, nature, and purpose of processing, and specific obligations (Art. 28(3))

Data breach

  • Authority Breach Notification

    Define procedures to notify breaches to the Supervisory Authority within 72 hours (unless unlikely to result in a risk to rights and freedoms)

  • Breach Detection Mechanisms

    Establish mechanisms to immediately detect any personal data breaches

  • Breach Documentation Register

    Maintain a register documenting all personal data breaches, including the facts relating to each breach, its effects, and the remedial action taken, enabling the supervisory authority to verify compliance with breach notification obligations

  • Subject Breach Communication

    Define procedures to communicate breaches to data subjects if the breach is likely to present a high risk

Data protection officer

  • DPO Designation Assessment

    Assess whether designation of a Data Protection Officer is required and, if so, designate a DPO with expert knowledge of data protection law and practices, publishing their contact details and communicating them to the supervisory authority

  • DPO DPIA Advisory Role

    Ensure the DPO provides advice on the DPIA (Art. 35(2)) and monitors its implementation

  • DPO Involvement

    If a Data Protection Officer (DPO) is designated (Art. 37), involve the DPO in all matters relating to data protection and in compliance monitoring

Data protection principles

  • Data Accuracy

    Implement technical and organizational measures to ensure personal data is accurate and, where necessary, kept up to date, taking every reasonable step to ensure that inaccurate data is erased or rectified without delay

  • Data Minimisation

    Design the system to ensure that only personal data strictly necessary for each specific purpose is collected and processed (data minimization)

  • Pseudonymisation and Encryption

    Implement pseudonymisation and encryption as technical measures for data protection by design and processing security

  • Storage Limitation

    Limit data retention to the period strictly necessary to achieve the purposes, with automatic deletion mechanisms or periodic review

Data subject rights: Access and control

  • Data Portability

    If applicable (automated processing based on consent or contract), enable the system to provide data in a structured, commonly used, machine-readable format, and transmit it directly to another controller (if technically feasible)

  • Data Rectification

    Implement procedures and functionalities to enable timely rectification of inaccurate personal data and completion of incomplete data

  • Data Subject Processing Restriction

    Enable the system to flag personal data as restricted and enforce storage-only processing upon data subject request, ensuring that restricted data is not further processed except with consent, for legal claims, for protection of another person's rights, or for important public interest reasons

  • Right to Erasure

    Implement procedures for erasure (right to be forgotten) of data upon request or when no longer necessary; for publicly disclosed data, ensure the system can take measures to inform other controllers of the erasure request

  • Right to Object

    Enable the system to receive and action data subject objections to processing based on legitimate interest or public task, and to immediately cease processing for direct marketing purposes upon objection, including profiling related to direct marketing

  • Subject Access Rights

    Enable the system to allow data subjects to obtain confirmation that their data is being processed and to access the data and required information (purposes, recipients, retention period)

  • Third-Party Rectification Notification

    Establish procedures to communicate any rectification, erasure, or restriction of processing to each recipient to whom personal data has been disclosed, and to inform the data subject about those recipients upon request

Data subject rights: Automated decisions

  • Automated Decision Safeguards

    If automated decision-making is used (Art. 22), implement measures to ensure human intervention, the right to express opinions, and to contest the decision

  • Automated Decision Transparency

    Design the system to notify the existence of an automated decision-making process (including profiling) that produces legal effects or similarly significantly affects the data subject

Data subject rights: Transparency

  • Privacy Notice Provision

    Plan and implement compliance with information obligations at the time of data collection (Art. 13) or within required timeframes (Art. 14), using concise, transparent, and intelligible language

Document control

  • Control of documented information

    Control documented information to ensure availability, suitability, and adequate protection, addressing distribution, access, retrieval, storage, preservation, version control, retention, disposition, and external-origin documents.

  • Creating and updating

    Ensure documented information is appropriately identified, described, formatted, and reviewed and approved for suitability and adequacy when created or updated.

  • Documented information — General

    Maintain documented information required by ISO 27001 and any additional documented information the organization determines necessary for ISMS effectiveness.

EU representative

  • EU Representative Designation

    Designate in writing a representative in the Union where the controller or processor is not established in the Union but processes personal data of data subjects in the Union in connection with offering goods or services or monitoring behaviour

General accountability

  • Accountability Documentation

    Demonstrate compliance (accountability) with appropriate data protection policies, as required by the Controller

Impact assessment

  • DPIA Periodic Review

    Monitor changes in the risk represented by processing activities and conduct DPIA reviews when necessary (Art. 35(11))

Incident Management

  • Assessment and decision on information security events

    Assess information security events and decide whether to categorize them as information security incidents.

  • Collection of evidence

    Establish and implement procedures for the identification, collection, acquisition, and preservation of evidence related to information security events.

  • Information security event reporting

    Provide a mechanism for personnel to report observed or suspected information security events through defined channels in a timely manner.

  • Information security incident management planning and preparation

    Plan and prepare for managing information security incidents by defining, establishing, and communicating incident management processes, roles, and responsibilities.

  • Learning from information security incidents

    Analyze knowledge gained from information security incidents and use findings to strengthen and improve information security controls.

  • Response to information security incidents

    Respond to information security incidents in accordance with documented procedures, including containment, evidence collection, escalation, and recovery actions.

Information Security Governance

  • Contact with authorities

    Establish and maintain contact with relevant authorities for timely reporting and threat coordination.

  • Contact with special interest groups

    Establish and maintain contact with special interest groups, specialist security forums, and professional associations to stay current on threats and best practices.

  • Documented operating procedures

    Document operating procedures for information processing facilities and make them available to personnel who need them.

  • Information security roles and responsibilities

    Define and allocate information security roles and responsibilities according to the organization's needs, ensuring clear ownership for all security functions.

  • Management responsibilities

    Require all personnel to apply information security in accordance with the established information security policy, topic-specific policies, and organizational procedures.

  • Policies for information security

    Define, approve, publish, and communicate an information security policy and topic-specific policies. Review at planned intervals and when significant changes occur, ensuring acknowledgement by relevant personnel and interested parties.

  • Segregation of duties

    Segregate conflicting duties and areas of responsibility to prevent any single individual from having unchecked control over critical security functions.

  • Threat intelligence

    Collect and analyze information relating to information security threats to produce actionable threat intelligence that informs risk decisions and defensive posture.

International transfers

  • Transfer Identification

    Determine whether the project involves the transfer of personal data to a third country or international organization

ISMS scope and context

  • Determining the scope of the information security management system

    Define and document the boundaries and applicability of the ISMS, considering internal/external issues, interested party requirements, and organizational interfaces and dependencies.

  • Information security management system

    Establish, implement, maintain, and continually improve an information security management system, including the processes needed and their interactions.

  • Understanding the needs and expectations of interested parties

    Identify interested parties relevant to the ISMS, determine their requirements, and decide which requirements will be addressed through the management system.

  • Understanding the organization and its context

    Determine external and internal issues relevant to the organization's purpose that affect the ISMS's ability to achieve its intended outcomes, including whether climate change is a relevant issue.

Leadership and governance

  • Leadership and commitment

    Demonstrate top management leadership and commitment by establishing an information security policy and objectives, ensuring resource availability, integrating ISMS requirements into organizational processes, and promoting continual improvement.

  • Organizational roles, responsibilities and authorities

    Assign and communicate responsibilities and authorities for information security roles, including responsibility for ISMS conformance and performance reporting to top management.

  • Policy

    Establish and document an information security policy appropriate to the organization's purpose, including security objectives, commitment to applicable requirements, and commitment to continual improvement. Communicate the policy within the organization and make it available to interested parties.

Logging & Monitoring

  • Clock synchronization

    Synchronize clocks of all information processing systems to approved and traceable time sources to ensure log correlation accuracy and forensic timeline integrity.

  • Logging

    Produce, store, protect, and analyze logs that record activities, exceptions, faults, and other relevant events.

  • Monitoring activities

    Monitor networks, systems, and applications for anomalous behavior and take appropriate actions to evaluate potential information security incidents.

Network Security

  • Capacity management

    Monitor resource utilization across information processing systems and adjust capacity based on current demand and projected growth to prevent service degradation and denial-of-service conditions.

  • Networks security

    Secure, manage, and control networks and network devices to protect information in systems and applications.

  • Security of network services

    Identify, implement, and monitor security mechanisms and service level requirements for all network services, whether provided internally or outsourced.

  • Segregation of networks

    Segregate groups of information services, users, and information systems in the organization's networks.

  • Web filtering

    Manage access to external websites to reduce exposure to malicious content.

Operational execution

  • Information security risk assessment (operational)

    Perform information security risk assessments at planned intervals or when significant changes are proposed or occur, applying the criteria established in the risk assessment process, and retain documented results.

  • Information security risk treatment (operational)

    Implement the information security risk treatment plan and retain documented results of risk treatment activities.

  • Operational planning and control

    Plan, implement, and control ISMS processes by establishing criteria, controlling planned changes, reviewing consequences of unintended changes, and ensuring externally provided processes and services are controlled. Retain documented evidence of process execution.

Operations Security

  • Configuration management

    Establish, document, implement, monitor, and review configurations, including security configurations, of hardware, software, services, and networks.

  • Information deletion

    Implement systematic deletion of information from systems, devices, and storage media when no longer required, in accordance with retention policies and applicable legal obligations.

  • Installation of software on operational systems

    Implement procedures and technical controls to securely manage software installation on operational systems, ensuring only authorized and verified software is deployed to production environments.

  • Management of technical vulnerabilities

    Obtain information about technical vulnerabilities of information systems in use, evaluate the organization's exposure to such vulnerabilities, and take appropriate measures.

  • Protection against malware

    Implement protection against malware, supported by appropriate user awareness.

  • Use of cryptography

    Define and implement rules for the effective use of cryptography, including cryptographic key management.

  • User end point devices

    Protect information stored on, processed by, or accessible via user endpoint devices.

People Security

  • Confidentiality or non-disclosure agreements

    Identify, maintain, and document confidentiality and non-disclosure agreements that reflect the organization's information protection needs, review them at defined intervals, and obtain signatures from all relevant personnel and interested parties.

  • Disciplinary process

    Formalize and communicate a disciplinary process for taking action against personnel and other relevant interested parties who commit information security policy violations.

  • Information security awareness, education and training

    Deliver information security awareness, education, and training to all personnel and relevant interested parties, with regular updates on the security policy, topic-specific policies, and procedures relevant to their job function.

  • Remote working

    Implement security measures to protect information accessed, processed, or stored by personnel working remotely outside the organization's premises.

  • Responsibilities after termination or change of employment

    Define, enforce, and communicate to relevant personnel and other interested parties information security responsibilities and duties that remain valid after termination or change of employment.

  • Screening

    Conduct background verification checks on all candidates before they join the organization and on an ongoing basis, taking into consideration applicable laws, regulations, and ethics, proportional to business requirements, the classification of information to be accessed, and the perceived risks.

  • Terms and conditions of employment

    State both the personnel's and the organization's responsibilities for information security in employment contractual agreements.

Performance evaluation and improvement

  • Continual improvement

    Continually improve the suitability, adequacy, and effectiveness of the information security management system.

  • Internal audit — General

    Conduct internal audits at planned intervals to determine whether the ISMS conforms to organizational requirements and ISO 27001 requirements and is effectively implemented and maintained.

  • Internal audit programme

    Plan, establish, implement, and maintain an internal audit programme defining frequency, methods, responsibilities, and reporting. Define audit criteria and scope, ensure auditor objectivity, report results to relevant management, and retain documented evidence of the programme and audit results.

  • Management review — General

    Conduct management reviews of the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.

  • Management review inputs

    Include in the management review: status of previous actions, changes in external/internal issues and interested party needs, information security performance trends (nonconformities, monitoring results, audit results, objective fulfilment), feedback from interested parties, results of risk assessment and status of risk treatment plan, and improvement opportunities.

  • Management review results

    Document management review outputs including continual improvement decisions and any needs for changes to the ISMS, and retain documented evidence of management review results.

  • Monitoring, measurement, analysis and evaluation

    Determine what to monitor and measure, establish valid and reproducible methods, define schedules and responsibilities for monitoring, measurement, analysis, and evaluation, and retain documented evidence of results.

  • Nonconformity and corrective action

    React to nonconformities by controlling, correcting, and managing consequences. Evaluate root causes, determine whether similar nonconformities exist or could occur, implement corrective actions, review their effectiveness, and update the ISMS. Retain documented evidence of nonconformities, actions taken, and corrective action results.

Physical & Environmental Security

  • Clear desk and clear screen

    Define and enforce clear desk rules for papers and removable storage media and clear screen rules for information processing facilities to prevent exposure of sensitive information in unattended workspaces.

  • Secure disposal or re-use of equipment

    Verify that all sensitive data and licensed software have been removed or securely overwritten on equipment containing storage media prior to disposal or re-use.

  • Security of assets off-premises

    Implement security measures to protect organizational assets used outside the premises, accounting for the different risks of working in uncontrolled environments.

  • Storage media

    Manage storage media through their full lifecycle — acquisition, use, transportation, and disposal — in accordance with the organization's classification scheme and handling requirements.

Privacy

  • Communication of changes to the privacy policy

    Changes to the privacy policy are communicated to data subjects and relevant parties on a timely basis.

  • Communication of consequences for refusing consent

    The consequences of refusing or withholding consent are communicated to data subjects.

  • Consent from data subjects

    Consent is obtained from data subjects prior to the collection and processing of their personal information where required.

  • Consideration of privacy requirements and use of personal data.

    Privacy requirements and the intended use of personal data are considered when designing systems and processes.

  • Data breach reporting procedures

    Data breach reporting procedures define how privacy breaches are identified, assessed and reported to data subjects and authorities.

  • Data breach response plans

    A data breach response plan is defined to guide the response to privacy incidents affecting personal information.

  • Data erasure procedure

    A data erasure procedure is followed to securely delete personal information when it is no longer required or upon valid request.

  • Data subject access to modify data

    Data subjects are provided the ability to access and modify their personal information held by the organisation.

  • Data subject contacts

    A contact channel is provided for data subjects to raise privacy enquiries, complaints and requests.

  • Denied privacy requests handling

    Denied privacy requests are handled and the reasons for denial are documented and communicated to the data subject.

  • Log of unauthorized disclosure.

    A log of unauthorized disclosures of personal information is maintained and reviewed.

  • Monitoring of the processing scope and location of personal data.

    The scope and location of personal data processing is monitored to ensure processing remains within authorised boundaries.

  • Opportunity to withdraw consent

    Data subjects are provided the opportunity to withdraw consent for the processing of their personal information.

  • Personal data request authentication

    The identity of data subjects making personal data requests is authenticated prior to fulfilment.

  • Personal information retention protection.

    Personal information is protected for the duration of its defined retention period.

  • Personal information use and consent compliance.

    Personal information is used in accordance with the consent obtained and the stated purposes of collection.

  • Privacy notice noncompliance reporting.

    Noncompliance with privacy notices is identified and reported for remediation.

  • Privacy notices

    Privacy notices are provided to data subjects describing how their personal information is collected, used, retained, disclosed and protected.

  • Privacy policy consent and choices

    The privacy policy describes the consent and choices available to data subjects regarding the collection and use of their personal information.

  • Privacy policy data collection

    The privacy policy defines the personal information collected and the purposes for which it is collected, used, retained and disclosed.

  • Retention period for personal information.

    Retention periods for personal information are defined and applied based on purpose and legal requirements.

  • Tracking of privacy requests and disclosures

    Privacy requests and disclosures of personal information are tracked and recorded through to completion.

  • Vendor risk assessment

    A vendor risk assessment is completed to identify and treat privacy risks associated with vendors processing personal information.

Processing Integrity

  • Critical data output quality assurance

    Quality assurance is performed over critical data outputs to confirm processing results are complete and accurate.

  • Critical data processing error detection and correction.

    Processing errors affecting critical data are detected and corrected in a timely manner.

  • Data validation checks of data inputs.

    Data validation checks are applied to data inputs to ensure completeness and accuracy prior to processing.

  • Management review of the inventory of data.

    Management reviews the inventory of data to confirm completeness and accuracy of data used in processing.

  • Risk assessment of processing objectives

    A risk assessment of processing objectives is performed to identify risks to the completeness, accuracy and validity of data processing.

Processing records

  • Processing Activity Records

    Create and maintain up-to-date records of processing activities containing the required information (purposes, data categories, recipients, etc.)

  • Record-Keeping Exemption Assessment

    Determine whether full record-keeping under Art. 30 is required. Organisations with fewer than 250 employees are exempt only if processing is occasional, unlikely to risk data subject rights, and excludes special categories and criminal data

Risk management

  • Actions to address risks and opportunities — General

    Determine risks and opportunities that could affect ISMS outcomes, and plan actions to address them, integrating those actions into ISMS processes with effectiveness evaluation.

  • Information security objectives and planning to achieve them

    Establish information security objectives at relevant functions and levels that are consistent with policy, measurable where practicable, informed by applicable requirements and risk assessment results, monitored, communicated, and updated when requirements or risks change. Document and retain as documented information. Plan what will be done, resources required, responsibilities, timelines, and evaluation methods.

  • Information security risk assessment (process)

    Define and apply a repeatable information security risk assessment process that establishes risk acceptance criteria, identifies risks to confidentiality, integrity, and availability, assigns risk owners, analyzes consequences and likelihood, and prioritizes risks for treatment.

  • Information security risk treatment (process)

    Define and apply an information security risk treatment process that selects treatment options, determines necessary controls, verifies completeness against Annex A, produces a Statement of Applicability documenting necessary controls with justification for inclusion, implementation status, and justification for any Annex A exclusions, formulates a risk treatment plan, and obtains risk owner approval of the plan and acceptance of residual information security risks.

  • Planning of changes

    Carry out changes to the ISMS in a planned manner.

Secure Development

  • Application security requirements

    Identify, specify, and approve information security requirements when developing or acquiring applications.

  • Secure coding

    Apply secure coding principles throughout software development.

  • Secure development life cycle

    Establish and apply secure development lifecycle rules covering requirements analysis, design, coding, testing, and deployment. Integrate security activities into each phase of the development process.

  • Secure system architecture and engineering principles

    Establish, document, maintain, and apply principles for engineering secure systems to any information system development activities.

  • Security testing in development and acceptance

    Define and implement security testing processes in the development lifecycle.

  • Separation of development, test and production environments

    Separate and secure development, testing, and production environments.

Security

  • Acceptable use policy

    The acceptable use policy sets out the roles, responsibilities and requirements to maintain the security of systems, data and endpoint devices.

  • Access control policy

    The access control policy sets out the required system access controls for secure authentication and account use.

  • Access to critical systems

    New user access privileges to critical systems are approved by management prior to provisioning.

  • Annual privacy training.

    Privacy training is provided to personnel at least annually covering the handling of personal information.

  • Annual review of policies and processes

    Key policies and processes are reviewed and updated at least annually to confirm their effectiveness, accuracy and compliance.

  • Annual review of the incident response plans

    The incident response plans are reviewed and updated at least annually to ensure they remain current and effective.

  • Annual risk assessment

    Risk assessments are completed at least annually to identify and analyze the risks and identify any required mitigation actions.

  • Annual security awareness training.

    Security awareness training is provided to employees at least annually.

  • Annual vendor risk assessment

    An annual vendor risk assessment is completed to ensure the identification and treatment of risks remains accurate and appropriate.

  • Asset management policy

    The asset management policy establishes the roles, responsibilities and requirements for managing critical information assets to protect their security, availability, and integrity.

  • Backup configuration and schedule

    Backups of the application and database are performed daily.

  • Backup policy

    The backup policy establishes the requirements for backups and recoverability.

  • Backup restoration tests

    Backup and restoration tests are performed on at least an annual basis to ensure the recovery controls are effective.

  • Business continuity and disaster recovery plans

    The business continuity and disaster recovery plans include defined procedures to recover from significant events, and are reviewed and updated at least annually.

  • Business continuity plan test

    The business continuity plan is tested at least annually to ensure the response plans to critical events are effective.

  • Candidate competency evaluation

    Candidate competency is evaluated against documented role requirements prior to hiring to ensure individuals are qualified for their responsibilities.

  • Change management policy

    Documented change control policies and procedures are in place to guide personnel in the change management process.

  • Cloud service provider SOC 2 report review.

    SOC 2 reports of cloud service providers are reviewed at least annually to confirm the adequacy of provider controls.

  • Code of conduct

    The code of conduct is documented to communicate conduct standards and enforcement procedures.

  • Communication of the privacy policy

    The privacy policy is communicated to data subjects and relevant internal and external parties.

  • Conduct control self-assessments

    The control framework is reviewed at least annually by the control owners to ensure the control descriptions and owners are accurate, and that the controls are operating effectively as described.

  • Control framework responsibilities

    Management are assigned ownership of ongoing monitoring of the effectiveness of controls and that key policy and process requirements are being adhered to.

  • Critical data encryption at rest

    Data at rest in the production database(s) is automatically encrypted.

  • Cryptography policy

    The Cryptography Policy defines the required use of encryption and managing encryption keys to secure systems and data.

  • Cyber liability insurance

    The organisation has purchased insurance to offset or compensate for the financial loss of an adverse event with the services.

  • Data disposal guideline

    The defined data disposal guidelines and requirements set out the process for ensuring data is erased prior to disposal of system assets.

  • DC Individual Access

    Physical access to data centers is authorised prior to being granted, reviewed periodically, and revoked upon termination.

  • Disaster recovery plan test

    The disaster recovery plan is tested to confirm the recovery procedures for significant events are effective.

  • Documented policies with responsibilities

    The documented policies and procedures establish roles, responsibilities, and area accountabilities.

  • Employee job descriptions

    Job descriptions are documented for employees and management setting out the responsibilities, role requirements, and any key accountabilities.

  • Employee performance reviews

    Employee performance reviews are conducted at least annually.

  • Encryption in transit

    Data in transit to the infrastructure is automatically encrypted.

  • External communication channels for reporting incidents.

    External communication channels are provided for interested parties to report incidents, failures and concerns.

  • Firewalls at access points

    Firewalls are used at external points of connectivity to the infrastructure and network.

  • Incident response plan

    An incident response plan documents the approach to identifying, reporting, evaluating, classifying and handling incidents.

  • Incident response plans

    Incident response plans are defined to provide guidelines for responding to major incidents including security breaches.

  • Incident tickets or records

    Incident management processes are defined and followed for identification, assessment, classification, response, communications to interested parties, and resolution.

  • Information security policy

    The security policies set out the requirements for managing information security across the organisation's operations.

  • Internal control deficiency evaluation and communication

    Management tracks whether control failures, breaches of policies and procedures, customer complaints and other issues are assessed, tracked and monitored through to resolution.

  • Inventory of system assets

    An inventory of system assets and components is maintained to classify and manage the information assets.

  • Management meeting minutes

    Board of Directors / management meetings are held at least annually for organisational oversight and governance.

  • Management oversight of the information security

    The Board is responsible for oversight of the systems and data security with review at least annually.

  • Multi-factor authentication

    Multi-factor authentication or equivalent is applied across in-scope systems.

  • Network monitoring alerts

    Automated alerts and log reviews are used to identify and respond to suspicious network activity.

  • New hire acknowledgement of the acceptable use policy

    New hires acknowledge the acceptable use policy setting out responsibilities to maintain the security of systems, data and endpoint devices.

  • New hire acknowledgement of the code of conduct

    New hires acknowledge the documented code of conduct communicating conduct standards and enforcement procedures.

  • New hire background checks

    Background checks are completed for candidates prior to employment.

  • Office Individual Access

    Physical access to offices is authorised prior to being granted, reviewed periodically, and revoked upon termination.

  • Operating system updates

    A formal process is defined and followed to ensure operating system versions for devices are updated regularly.

  • Organization chart

    The organisation chart documents the reporting lines, accountable executives, team and individual roles, and is updated whenever there are changes in personnel.

  • Password policy

    The password policy sets out the requirements and guidelines for using secure and strong passwords.

  • Physical access policy

    A physical access policy defines the requirements for authorising, restricting and monitoring physical access to facilities and data centers.

  • Privacy training for new hires

    Privacy training is provided to new hires on the collection, use, retention and disclosure of personal information.

  • Privilege access restriction

    Privileged access to systems is restricted to authorised individuals based on job responsibilities.

  • Production environment restriction.

    Access to the production environment is restricted to authorised personnel to prevent unauthorised changes.

  • Responsibilities of the executive management team

    The Board Charter sets out the responsibilities and scope of the Board of Directors / executive management team.

  • Review of vendor assurance reports and certifications

    Vendor assurance reports and certifications are reviewed to confirm vendors maintain adequate controls over personal information.

  • Revocation of user access

    A defined terminations process is followed including revocation of user access from systems in a timely manner.

  • Risk assessment of fraud

    The risk assessment process considers the potential for fraud including malicious acts of employees or other users of the system.

  • Risk assessment of operating changes

    The risk assessment process identifies and assesses changes that could significantly impact the system of internal control.

  • Risk management policy

    Documented policies and procedures are in place to guide personnel when performing a risk assessment.

  • Root cause analysis for high severity incidents

    Root cause analysis is conducted on high-severity incidents to determine lessons learned and updates required to the incident response plans, and raise change requests for permanent fixes.

  • Security awareness training for new hires

    Security awareness training is provided to new hires.

  • Security Personnel

    Security personnel are used to monitor and control physical access to facilities.

  • Segregated change environments

    Development and test environments are logically separated from the production environment.

  • Segregation of duties

    An assessment of functional roles and system access privileges has been completed to identify the requirements for the segregation of duties.

  • Site Monitoring

    Site monitoring through surveillance is used to detect and record physical access to facilities.

  • System redundancy

    The system is designed with multiple availability zones and redundancy to support continued availability in the event of a failure.

  • Third-party agreements

    The entity's third-party agreements outline and communicate the scope of services, roles and responsibilities, terms, communication protocols, compliance requirements, service levels and just cause for terminating the relationship.

  • Third-party vendor risk management policy

    Management has defined a third-party vendor risk management approach for evaluating third-party risks.

  • User communication of significant system changes.

    Significant system changes are communicated to users in a timely manner.

  • Version control software

    Version control software is used to track changes to the source code and provide rollback capability if required.

  • Vulnerability management program

    A vulnerability management program is defined and documented to assess and manage the technical security of systems including identification, prioritisation and resolution of vulnerabilities.

Security of processing

  • Personnel Processing Instructions

    Implement architectural access controls ensuring that any person acting under the authority of the controller or processor, processes data according to instructions provided by the controller, unless required by Union or Member State law

  • Processing Security Measures

    Implement technical and organizational measures (e.g., encryption, resilience, recovery capability) to ensure a level of security appropriate to the risk

Special category and criminal data

  • Sensitive Data Identification

    Determine whether the project involves processing special categories of personal data (Art. 9, e.g., health, genetic, biometric data) or data relating to criminal convictions (Art. 10)

Supervisory authority cooperation

  • Supervisory Authority Cooperation

    Establish procedures for the controller, processor, and their representatives to cooperate on request with the supervisory authority in the performance of its tasks

Supplier Security

  • Addressing information security within supplier agreements

    Establish and agree relevant information security requirements with each supplier based on the type of supplier relationship, documented in formal agreements.

  • Information security for use of cloud services

    Establish processes for acquisition, use, management, and exit from cloud services in accordance with the organization's information security requirements.

  • Information security in supplier relationships

    Define and implement processes and procedures to assess and manage information security risks associated with the use of supplier products or services.

  • Managing information security in the information and communication technology (ICT) supply chain

    Define and implement processes and procedures to manage information security risks specific to the ICT products and services supply chain.

  • Monitoring, review and change management of supplier services

    Regularly monitor, review, evaluate, and manage changes in supplier information security practices and service delivery to detect degradation or non-compliance.

Test & Audit Security

  • Protection of information systems during audit testing

    Plan and agree audit tests and other assurance activities involving assessment of operational systems between the tester and appropriate management.

  • Test information

    Appropriately select, protect, and manage test information.