
Trust Center
KeldynAI
KeldynAI Trust Center
KeldynAI shares its compliance posture and security control coverage.
Controls
Access Control
Access control
Establish and implement rules to control physical and logical access to information and other associated assets based on business and information security requirements.
Access rights
Provision, review, modify, and remove access rights to information and other associated assets in accordance with the organization's access control policy and rules.
Access to source code
Manage read and write access to source code, development tools, and software libraries appropriately.
Authentication information
Control allocation and management of authentication information through a defined management process, including advising personnel on appropriate handling of authentication information.
Identity management
Manage the full lifecycle of identities — creation, verification, provisioning, suspension, and deactivation — ensuring every identity is accounted for.
Information access restriction
Restrict access to information and other associated assets in accordance with the established topic-specific policy on access control.
Privileged access rights
Restrict and manage the allocation and use of privileged access rights.
Secure authentication
Implement secure authentication mechanisms proportional to the sensitivity of the accessed resource, based on information access restrictions and the access control policy.
Use of privileged utility programs
Restrict and tightly control the use of privileged utility programs capable of overriding system and application controls. Limit access to authorized personnel and log all usage.
Asset Management
Acceptable use of information and other associated assets
Identify, document, and implement rules for acceptable use and handling procedures for information and other associated assets.
Classification of information
Classify information according to confidentiality, integrity, availability needs, and relevant interested party requirements using a defined classification scheme.
Data leakage prevention
Implement data leakage prevention controls across systems, networks, and devices that process, store, or transmit sensitive information to detect and block unauthorized data exfiltration.
Data masking
Apply data masking in accordance with the organization's access control policy and other related topic-specific policies, business requirements, and applicable legislation.
Information transfer
Establish information transfer rules, procedures, or agreements for all types of transfer facilities within the organization and between the organization and other parties.
Inventory of information and other associated assets
Develop and maintain an inventory of information and other associated assets, including designated owners, covering the full asset lifecycle.
Labelling of information
Develop and implement labelling procedures for information assets in accordance with the adopted classification scheme.
Availability
Auto-scaling configuration
Processing capacity is configured to auto-scale to meet processing demand.
Business Continuity
ICT readiness for business continuity
Plan, implement, maintain, and test ICT readiness for business continuity based on business continuity objectives and ICT continuity requirements.
Information backup
Maintain backup copies of information, software, and systems in accordance with the agreed topic-specific policy on backup. Test restoration procedures at planned intervals to verify recoverability.
Information security during disruption
Plan how to maintain information security at an appropriate level during disruption, including alternative procedures and compensating controls.
Redundancy of information processing facilities
Implement information processing facilities with redundancy sufficient to meet availability requirements.
Change Management
Change management
Subject changes to information processing facilities and information systems to change management procedures.
Information security in project management
Integrate information security requirements, risk assessments, and security controls into project management processes for all projects regardless of type.
Children's data
Child Consent Verification
Implement age verification and parental consent mechanisms for information society services offered directly to children, ensuring processing is lawful only where the child meets the applicable age threshold or consent is given or authorised by the holder of parental responsibility
Codes and certification
Compliance Certification Readiness
Assess available approved codes of conduct and data protection certification mechanisms for their applicability to the organization's processing activities, and document the evaluation outcome to support demonstration of GDPR compliance
Competence and awareness
Awareness
Ensure personnel are aware of the information security policy, their contribution to ISMS effectiveness, and the implications of non-conformance with ISMS requirements.
Communication
Determine the need for internal and external communications relevant to the ISMS, including what, when, with whom, and how to communicate.
Competence
Determine required competencies for personnel affecting information security performance, ensure competence through education, training, or experience, take actions to close identified competence gaps and evaluate the effectiveness of those actions, and retain documented evidence of competence.
Resources
Determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS.
Compliance
Compliance with policies, rules and standards for information security
Regularly review compliance with the organization's information security policy, topic-specific policies, rules, and standards, and address identified deviations.
Independent review of information security
Commission independent reviews of the organization's approach to managing information security and its implementation, including people, processes, and technologies, at planned intervals or when significant changes occur.
Intellectual property rights
Implement appropriate procedures to protect intellectual property rights, including software copyright and licences.
Legal, statutory, regulatory and contractual requirements
Identify, document, and keep up to date all legal, statutory, regulatory, and contractual requirements relevant to information security, along with the organization's approach to meeting them.
Privacy and protection of personal identifiable information (PII)
Identify and meet requirements for the preservation of privacy and protection of personally identifiable information (PII) according to applicable laws, regulations, and contractual requirements.
Protection of records
Protect records from loss, destruction, falsification, unauthorized access, and unauthorized release throughout their retention period.
Confidentiality
Boundaries of confidential data
Confidential data is maintained within the system boundaries at all times where security controls are applied to restrict access to authorised individuals.
Data management policy
The requirements for managing data are established in the data classification, handling, retention and disposal policies.
Register of confidential data
A register of the types and sources of confidential data collected and processed is maintained to track assets and storage locations of confidential data.
Consent
Consent Lifecycle Management
Implement system capabilities to capture, record, manage, and action withdrawal of consent, ensuring withdrawal is as easy as giving consent and that the controller can demonstrate consent was given
Controller-processor responsibilities
Processor Contract
If a Data Processor is involved, execute a contract defining the subject matter, duration, nature, and purpose of processing, and specific obligations (Art. 28(3))
Data breach
Authority Breach Notification
Define procedures to notify breaches to the Supervisory Authority within 72 hours (unless unlikely to result in a risk to rights and freedoms)
Breach Detection Mechanisms
Establish mechanisms to immediately detect any personal data breaches
Breach Documentation Register
Maintain a register documenting all personal data breaches, including the facts relating to each breach, its effects, and the remedial action taken, enabling the supervisory authority to verify compliance with breach notification obligations
Subject Breach Communication
Define procedures to communicate breaches to data subjects if the breach is likely to present a high risk
Data protection officer
DPO Designation Assessment
Assess whether designation of a Data Protection Officer is required and, if so, designate a DPO with expert knowledge of data protection law and practices, publishing their contact details and communicating them to the supervisory authority
DPO DPIA Advisory Role
Ensure the DPO provides advice on the DPIA (Art. 35(2)) and monitors its implementation
DPO Involvement
If a Data Protection Officer (DPO) is designated (Art. 37), involve the DPO in all matters relating to data protection and in compliance monitoring
Data protection principles
Data Accuracy
Implement technical and organizational measures to ensure personal data is accurate and, where necessary, kept up to date, taking every reasonable step to ensure that inaccurate data is erased or rectified without delay
Data Minimisation
Design the system to ensure that only personal data strictly necessary for each specific purpose is collected and processed (data minimization)
Pseudonymisation and Encryption
Implement pseudonymisation and encryption as technical measures for data protection by design and processing security
Storage Limitation
Limit data retention to the period strictly necessary to achieve the purposes, with automatic deletion mechanisms or periodic review
Data subject rights: Access and control
Data Portability
If applicable (automated processing based on consent or contract), enable the system to provide data in a structured, commonly used, machine-readable format, and transmit it directly to another controller (if technically feasible)
Data Rectification
Implement procedures and functionalities to enable timely rectification of inaccurate personal data and completion of incomplete data
Data Subject Processing Restriction
Enable the system to flag personal data as restricted and enforce storage-only processing upon data subject request, ensuring that restricted data is not further processed except with consent, for legal claims, for protection of another person's rights, or for important public interest reasons
Right to Erasure
Implement procedures for erasure (right to be forgotten) of data upon request or when no longer necessary; for publicly disclosed data, ensure the system can take measures to inform other controllers of the erasure request
Right to Object
Enable the system to receive and action data subject objections to processing based on legitimate interest or public task, and to immediately cease processing for direct marketing purposes upon objection, including profiling related to direct marketing
Subject Access Rights
Enable the system to allow data subjects to obtain confirmation that their data is being processed and to access the data and required information (purposes, recipients, retention period)
Third-Party Rectification Notification
Establish procedures to communicate any rectification, erasure, or restriction of processing to each recipient to whom personal data has been disclosed, and to inform the data subject about those recipients upon request
Data subject rights: Automated decisions
Automated Decision Safeguards
If automated decision-making is used (Art. 22), implement measures to ensure human intervention, the right to express opinions, and to contest the decision
Automated Decision Transparency
Design the system to notify the existence of an automated decision-making process (including profiling) that produces legal effects or similarly significantly affects the data subject
Data subject rights: Transparency
Privacy Notice Provision
Plan and implement compliance with information obligations at the time of data collection (Art. 13) or within required timeframes (Art. 14), using concise, transparent, and intelligible language
Document control
Control of documented information
Control documented information to ensure availability, suitability, and adequate protection, addressing distribution, access, retrieval, storage, preservation, version control, retention, disposition, and external-origin documents.
Creating and updating
Ensure documented information is appropriately identified, described, formatted, and reviewed and approved for suitability and adequacy when created or updated.
Documented information — General
Maintain documented information required by ISO 27001 and any additional documented information the organization determines necessary for ISMS effectiveness.
EU representative
EU Representative Designation
Designate in writing a representative in the Union where the controller or processor is not established in the Union but processes personal data of data subjects in the Union in connection with offering goods or services or monitoring behaviour
General accountability
Accountability Documentation
Demonstrate compliance (accountability) with appropriate data protection policies, as required by the Controller
Impact assessment
DPIA Periodic Review
Monitor changes in the risk represented by processing activities and conduct DPIA reviews when necessary (Art. 35(11))
Incident Management
Assessment and decision on information security events
Assess information security events and decide whether to categorize them as information security incidents.
Collection of evidence
Establish and implement procedures for the identification, collection, acquisition, and preservation of evidence related to information security events.
Information security event reporting
Provide a mechanism for personnel to report observed or suspected information security events through defined channels in a timely manner.
Information security incident management planning and preparation
Plan and prepare for managing information security incidents by defining, establishing, and communicating incident management processes, roles, and responsibilities.
Learning from information security incidents
Analyze knowledge gained from information security incidents and use findings to strengthen and improve information security controls.
Response to information security incidents
Respond to information security incidents in accordance with documented procedures, including containment, evidence collection, escalation, and recovery actions.
Information Security Governance
Contact with authorities
Establish and maintain contact with relevant authorities for timely reporting and threat coordination.
Contact with special interest groups
Establish and maintain contact with special interest groups, specialist security forums, and professional associations to stay current on threats and best practices.
Documented operating procedures
Document operating procedures for information processing facilities and make them available to personnel who need them.
Information security roles and responsibilities
Define and allocate information security roles and responsibilities according to the organization's needs, ensuring clear ownership for all security functions.
Management responsibilities
Require all personnel to apply information security in accordance with the established information security policy, topic-specific policies, and organizational procedures.
Policies for information security
Define, approve, publish, and communicate an information security policy and topic-specific policies. Review at planned intervals and when significant changes occur, ensuring acknowledgement by relevant personnel and interested parties.
Segregation of duties
Segregate conflicting duties and areas of responsibility to prevent any single individual from having unchecked control over critical security functions.
Threat intelligence
Collect and analyze information relating to information security threats to produce actionable threat intelligence that informs risk decisions and defensive posture.
International transfers
Transfer Identification
Determine whether the project involves the transfer of personal data to a third country or international organization
ISMS scope and context
Determining the scope of the information security management system
Define and document the boundaries and applicability of the ISMS, considering internal/external issues, interested party requirements, and organizational interfaces and dependencies.
Information security management system
Establish, implement, maintain, and continually improve an information security management system, including the processes needed and their interactions.
Understanding the needs and expectations of interested parties
Identify interested parties relevant to the ISMS, determine their requirements, and decide which requirements will be addressed through the management system.
Understanding the organization and its context
Determine external and internal issues relevant to the organization's purpose that affect the ISMS's ability to achieve its intended outcomes, including whether climate change is a relevant issue.
Leadership and governance
Leadership and commitment
Demonstrate top management leadership and commitment by establishing an information security policy and objectives, ensuring resource availability, integrating ISMS requirements into organizational processes, and promoting continual improvement.
Organizational roles, responsibilities and authorities
Assign and communicate responsibilities and authorities for information security roles, including responsibility for ISMS conformance and performance reporting to top management.
Policy
Establish and document an information security policy appropriate to the organization's purpose, including security objectives, commitment to applicable requirements, and commitment to continual improvement. Communicate the policy within the organization and make it available to interested parties.
Logging & Monitoring
Clock synchronization
Synchronize clocks of all information processing systems to approved and traceable time sources to ensure log correlation accuracy and forensic timeline integrity.
Logging
Produce, store, protect, and analyze logs that record activities, exceptions, faults, and other relevant events.
Monitoring activities
Monitor networks, systems, and applications for anomalous behavior and take appropriate actions to evaluate potential information security incidents.
Network Security
Capacity management
Monitor resource utilization across information processing systems and adjust capacity based on current demand and projected growth to prevent service degradation and denial-of-service conditions.
Networks security
Secure, manage, and control networks and network devices to protect information in systems and applications.
Security of network services
Identify, implement, and monitor security mechanisms and service level requirements for all network services, whether provided internally or outsourced.
Segregation of networks
Segregate groups of information services, users, and information systems in the organization's networks.
Web filtering
Manage access to external websites to reduce exposure to malicious content.
Operational execution
Information security risk assessment (operational)
Perform information security risk assessments at planned intervals or when significant changes are proposed or occur, applying the criteria established in the risk assessment process, and retain documented results.
Information security risk treatment (operational)
Implement the information security risk treatment plan and retain documented results of risk treatment activities.
Operational planning and control
Plan, implement, and control ISMS processes by establishing criteria, controlling planned changes, reviewing consequences of unintended changes, and ensuring externally provided processes and services are controlled. Retain documented evidence of process execution.
Operations Security
Configuration management
Establish, document, implement, monitor, and review configurations, including security configurations, of hardware, software, services, and networks.
Information deletion
Implement systematic deletion of information from systems, devices, and storage media when no longer required, in accordance with retention policies and applicable legal obligations.
Installation of software on operational systems
Implement procedures and technical controls to securely manage software installation on operational systems, ensuring only authorized and verified software is deployed to production environments.
Management of technical vulnerabilities
Obtain information about technical vulnerabilities of information systems in use, evaluate the organization's exposure to such vulnerabilities, and take appropriate measures.
Protection against malware
Implement protection against malware, supported by appropriate user awareness.
Use of cryptography
Define and implement rules for the effective use of cryptography, including cryptographic key management.
User end point devices
Protect information stored on, processed by, or accessible via user endpoint devices.
People Security
Confidentiality or non-disclosure agreements
Identify, maintain, and document confidentiality and non-disclosure agreements that reflect the organization's information protection needs, review them at defined intervals, and obtain signatures from all relevant personnel and interested parties.
Disciplinary process
Formalize and communicate a disciplinary process for taking action against personnel and other relevant interested parties who commit information security policy violations.
Information security awareness, education and training
Deliver information security awareness, education, and training to all personnel and relevant interested parties, with regular updates on the security policy, topic-specific policies, and procedures relevant to their job function.
Remote working
Implement security measures to protect information accessed, processed, or stored by personnel working remotely outside the organization's premises.
Responsibilities after termination or change of employment
Define, enforce, and communicate to relevant personnel and other interested parties information security responsibilities and duties that remain valid after termination or change of employment.
Screening
Conduct background verification checks on all candidates before they join the organization and on an ongoing basis, taking into consideration applicable laws, regulations, and ethics, proportional to business requirements, the classification of information to be accessed, and the perceived risks.
Terms and conditions of employment
State both the personnel's and the organization's responsibilities for information security in employment contractual agreements.
Performance evaluation and improvement
Continual improvement
Continually improve the suitability, adequacy, and effectiveness of the information security management system.
Internal audit — General
Conduct internal audits at planned intervals to determine whether the ISMS conforms to organizational requirements and ISO 27001 requirements and is effectively implemented and maintained.
Internal audit programme
Plan, establish, implement, and maintain an internal audit programme defining frequency, methods, responsibilities, and reporting. Define audit criteria and scope, ensure auditor objectivity, report results to relevant management, and retain documented evidence of the programme and audit results.
Management review — General
Conduct management reviews of the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.
Management review inputs
Include in the management review: status of previous actions, changes in external/internal issues and interested party needs, information security performance trends (nonconformities, monitoring results, audit results, objective fulfilment), feedback from interested parties, results of risk assessment and status of risk treatment plan, and improvement opportunities.
Management review results
Document management review outputs including continual improvement decisions and any needs for changes to the ISMS, and retain documented evidence of management review results.
Monitoring, measurement, analysis and evaluation
Determine what to monitor and measure, establish valid and reproducible methods, define schedules and responsibilities for monitoring, measurement, analysis, and evaluation, and retain documented evidence of results.
Nonconformity and corrective action
React to nonconformities by controlling, correcting, and managing consequences. Evaluate root causes, determine whether similar nonconformities exist or could occur, implement corrective actions, review their effectiveness, and update the ISMS. Retain documented evidence of nonconformities, actions taken, and corrective action results.
Physical & Environmental Security
Clear desk and clear screen
Define and enforce clear desk rules for papers and removable storage media and clear screen rules for information processing facilities to prevent exposure of sensitive information in unattended workspaces.
Secure disposal or re-use of equipment
Verify that all sensitive data and licensed software have been removed or securely overwritten on equipment containing storage media prior to disposal or re-use.
Security of assets off-premises
Implement security measures to protect organizational assets used outside the premises, accounting for the different risks of working in uncontrolled environments.
Storage media
Manage storage media through their full lifecycle — acquisition, use, transportation, and disposal — in accordance with the organization's classification scheme and handling requirements.
Privacy
Communication of changes to the privacy policy
Changes to the privacy policy are communicated to data subjects and relevant parties on a timely basis.
Communication of consequences for refusing consent
The consequences of refusing or withholding consent are communicated to data subjects.
Consent from data subjects
Consent is obtained from data subjects prior to the collection and processing of their personal information where required.
Consideration of privacy requirements and use of personal data.
Privacy requirements and the intended use of personal data are considered when designing systems and processes.
Data breach reporting procedures
Data breach reporting procedures define how privacy breaches are identified, assessed and reported to data subjects and authorities.
Data breach response plans
A data breach response plan is defined to guide the response to privacy incidents affecting personal information.
Data erasure procedure
A data erasure procedure is followed to securely delete personal information when it is no longer required or upon valid request.
Data subject access to modify data
Data subjects are provided the ability to access and modify their personal information held by the organisation.
Data subject contacts
A contact channel is provided for data subjects to raise privacy enquiries, complaints and requests.
Denied privacy requests handling
Denied privacy requests are handled and the reasons for denial are documented and communicated to the data subject.
Log of unauthorized disclosure.
A log of unauthorized disclosures of personal information is maintained and reviewed.
Monitoring of the processing scope and location of personal data.
The scope and location of personal data processing is monitored to ensure processing remains within authorised boundaries.
Opportunity to withdraw consent
Data subjects are provided the opportunity to withdraw consent for the processing of their personal information.
Personal data request authentication
The identity of data subjects making personal data requests is authenticated prior to fulfilment.
Personal information retention protection.
Personal information is protected for the duration of its defined retention period.
Personal information use and consent compliance.
Personal information is used in accordance with the consent obtained and the stated purposes of collection.
Privacy notice noncompliance reporting.
Noncompliance with privacy notices is identified and reported for remediation.
Privacy notices
Privacy notices are provided to data subjects describing how their personal information is collected, used, retained, disclosed and protected.
Privacy policy consent and choices
The privacy policy describes the consent and choices available to data subjects regarding the collection and use of their personal information.
Privacy policy data collection
The privacy policy defines the personal information collected and the purposes for which it is collected, used, retained and disclosed.
Retention period for personal information.
Retention periods for personal information are defined and applied based on purpose and legal requirements.
Tracking of privacy requests and disclosures
Privacy requests and disclosures of personal information are tracked and recorded through to completion.
Vendor risk assessment
A vendor risk assessment is completed to identify and treat privacy risks associated with vendors processing personal information.
Processing Integrity
Critical data output quality assurance
Quality assurance is performed over critical data outputs to confirm processing results are complete and accurate.
Critical data processing error detection and correction.
Processing errors affecting critical data are detected and corrected in a timely manner.
Data validation checks of data inputs.
Data validation checks are applied to data inputs to ensure completeness and accuracy prior to processing.
Management review of the inventory of data.
Management reviews the inventory of data to confirm completeness and accuracy of data used in processing.
Risk assessment of processing objectives
A risk assessment of processing objectives is performed to identify risks to the completeness, accuracy and validity of data processing.
Processing records
Processing Activity Records
Create and maintain up-to-date records of processing activities containing the required information (purposes, data categories, recipients, etc.)
Record-Keeping Exemption Assessment
Determine whether full record-keeping under Art. 30 is required. Organisations with fewer than 250 employees are exempt only if processing is occasional, unlikely to risk data subject rights, and excludes special categories and criminal data
Risk management
Actions to address risks and opportunities — General
Determine risks and opportunities that could affect ISMS outcomes, and plan actions to address them, integrating those actions into ISMS processes with effectiveness evaluation.
Information security objectives and planning to achieve them
Establish information security objectives at relevant functions and levels that are consistent with policy, measurable where practicable, informed by applicable requirements and risk assessment results, monitored, communicated, and updated when requirements or risks change. Document and retain as documented information. Plan what will be done, resources required, responsibilities, timelines, and evaluation methods.
Information security risk assessment (process)
Define and apply a repeatable information security risk assessment process that establishes risk acceptance criteria, identifies risks to confidentiality, integrity, and availability, assigns risk owners, analyzes consequences and likelihood, and prioritizes risks for treatment.
Information security risk treatment (process)
Define and apply an information security risk treatment process that selects treatment options, determines necessary controls, verifies completeness against Annex A, produces a Statement of Applicability documenting necessary controls with justification for inclusion, implementation status, and justification for any Annex A exclusions, formulates a risk treatment plan, and obtains risk owner approval of the plan and acceptance of residual information security risks.
Planning of changes
Carry out changes to the ISMS in a planned manner.
Secure Development
Application security requirements
Identify, specify, and approve information security requirements when developing or acquiring applications.
Secure coding
Apply secure coding principles throughout software development.
Secure development life cycle
Establish and apply secure development lifecycle rules covering requirements analysis, design, coding, testing, and deployment. Integrate security activities into each phase of the development process.
Secure system architecture and engineering principles
Establish, document, maintain, and apply principles for engineering secure systems to any information system development activities.
Security testing in development and acceptance
Define and implement security testing processes in the development lifecycle.
Separation of development, test and production environments
Separate and secure development, testing, and production environments.
Security
Acceptable use policy
The acceptable use policy sets out the roles, responsibilities and requirements to maintain the security of systems, data and endpoint devices.
Access control policy
The access control policy sets out the required system access controls for secure authentication and account use.
Access to critical systems
New user access privileges to critical systems are approved by management prior to provisioning.
Annual privacy training.
Privacy training is provided to personnel at least annually covering the handling of personal information.
Annual review of policies and processes
Key policies and processes are reviewed and updated at least annually to confirm their effectiveness, accuracy and compliance.
Annual review of the incident response plans
The incident response plans are reviewed and updated at least annually to ensure they remain current and effective.
Annual risk assessment
Risk assessments are completed at least annually to identify and analyze the risks and identify any required mitigation actions.
Annual security awareness training.
Security awareness training is provided to employees at least annually.
Annual vendor risk assessment
An annual vendor risk assessment is completed to ensure the identification and treatment of risks remains accurate and appropriate.
Asset management policy
The asset management policy establishes the roles, responsibilities and requirements for managing critical information assets to protect their security, availability, and integrity.
Backup configuration and schedule
Backups of the application and database are performed daily.
Backup policy
The backup policy establishes the requirements for backups and recoverability.
Backup restoration tests
Backup and restoration tests are performed on at least an annual basis to ensure the recovery controls are effective.
Business continuity and disaster recovery plans
The business continuity and disaster recovery plans include defined procedures to recover from significant events, and are reviewed and updated at least annually.
Business continuity plan test
The business continuity plan is tested at least annually to ensure the response plans to critical events are effective.
Candidate competency evaluation
Candidate competency is evaluated against documented role requirements prior to hiring to ensure individuals are qualified for their responsibilities.
Change management policy
Documented change control policies and procedures are in place to guide personnel in the change management process.
Cloud service provider SOC 2 report review.
SOC 2 reports of cloud service providers are reviewed at least annually to confirm the adequacy of provider controls.
Code of conduct
The code of conduct is documented to communicate conduct standards and enforcement procedures.
Communication of the privacy policy
The privacy policy is communicated to data subjects and relevant internal and external parties.
Conduct control self-assessments
The control framework is reviewed at least annually by the control owners to ensure the control descriptions and owners are accurate, and that the controls are operating effectively as described.
Control framework responsibilities
Management are assigned ownership of ongoing monitoring of the effectiveness of controls and that key policy and process requirements are being adhered to.
Critical data encryption at rest
Data at rest in the production database(s) is automatically encrypted.
Cryptography policy
The Cryptography Policy defines the required use of encryption and managing encryption keys to secure systems and data.
Cyber liability insurance
The organisation has purchased insurance to offset or compensate for the financial loss of an adverse event with the services.
Data disposal guideline
The defined data disposal guidelines and requirements set out the process for ensuring data is erased prior to disposal of system assets.
DC Individual Access
Physical access to data centers is authorised prior to being granted, reviewed periodically, and revoked upon termination.
Disaster recovery plan test
The disaster recovery plan is tested to confirm the recovery procedures for significant events are effective.
Documented policies with responsibilities
The documented policies and procedures establish roles, responsibilities, and area accountabilities.
Employee job descriptions
Job descriptions are documented for employees and management setting out the responsibilities, role requirements, and any key accountabilities.
Employee performance reviews
Employee performance reviews are conducted at least annually.
Encryption in transit
Data in transit to the infrastructure is automatically encrypted.
External communication channels for reporting incidents.
External communication channels are provided for interested parties to report incidents, failures and concerns.
Firewalls at access points
Firewalls are used at external points of connectivity to the infrastructure and network.
Incident response plan
An incident response plan documents the approach to identifying, reporting, evaluating, classifying and handling incidents.
Incident response plans
Incident response plans are defined to provide guidelines for responding to major incidents including security breaches.
Incident tickets or records
Incident management processes are defined and followed for identification, assessment, classification, response, communications to interested parties, and resolution.
Information security policy
The security policies set out the requirements for managing information security across the organisation's operations.
Internal control deficiency evaluation and communication
Management tracks whether control failures, breaches of policies and procedures, customer complaints and other issues are assessed, tracked and monitored through to resolution.
Inventory of system assets
An inventory of system assets and components is maintained to classify and manage the information assets.
Management meeting minutes
Board of Directors / management meetings are held at least annually for organisational oversight and governance.
Management oversight of the information security
The Board is responsible for oversight of the systems and data security with review at least annually.
Multi-factor authentication
Multi-factor authentication or equivalent is applied across in-scope systems.
Network monitoring alerts
Automated alerts and log reviews are used to identify and respond to suspicious network activity.
New hire acknowledgement of the acceptable use policy
New hires acknowledge the acceptable use policy setting out responsibilities to maintain the security of systems, data and endpoint devices.
New hire acknowledgement of the code of conduct
New hires acknowledge the documented code of conduct communicating conduct standards and enforcement procedures.
New hire background checks
Background checks are completed for candidates prior to employment.
Office Individual Access
Physical access to offices is authorised prior to being granted, reviewed periodically, and revoked upon termination.
Operating system updates
A formal process is defined and followed to ensure operating system versions for devices are updated regularly.
Organization chart
The organisation chart documents the reporting lines, accountable executives, team and individual roles, and is updated whenever there are changes in personnel.
Password policy
The password policy sets out the requirements and guidelines for using secure and strong passwords.
Physical access policy
A physical access policy defines the requirements for authorising, restricting and monitoring physical access to facilities and data centers.
Privacy training for new hires
Privacy training is provided to new hires on the collection, use, retention and disclosure of personal information.
Privilege access restriction
Privileged access to systems is restricted to authorised individuals based on job responsibilities.
Production environment restriction.
Access to the production environment is restricted to authorised personnel to prevent unauthorised changes.
Responsibilities of the executive management team
The Board Charter sets out the responsibilities and scope of the Board of Directors / executive management team.
Review of vendor assurance reports and certifications
Vendor assurance reports and certifications are reviewed to confirm vendors maintain adequate controls over personal information.
Revocation of user access
A defined terminations process is followed including revocation of user access from systems in a timely manner.
Risk assessment of fraud
The risk assessment process considers the potential for fraud including malicious acts of employees or other users of the system.
Risk assessment of operating changes
The risk assessment process identifies and assesses changes that could significantly impact the system of internal control.
Risk management policy
Documented policies and procedures are in place to guide personnel when performing a risk assessment.
Root cause analysis for high severity incidents
Root cause analysis is conducted on high-severity incidents to determine lessons learned and updates required to the incident response plans, and raise change requests for permanent fixes.
Security awareness training for new hires
Security awareness training is provided to new hires.
Security Personnel
Security personnel are used to monitor and control physical access to facilities.
Segregated change environments
Development and test environments are logically separated from the production environment.
Segregation of duties
An assessment of functional roles and system access privileges has been completed to identify the requirements for the segregation of duties.
Site Monitoring
Site monitoring through surveillance is used to detect and record physical access to facilities.
System redundancy
The system is designed with multiple availability zones and redundancy to support continued availability in the event of a failure.
Third-party agreements
The entity's third-party agreements outline and communicate the scope of services, roles and responsibilities, terms, communication protocols, compliance requirements, service levels and just cause for terminating the relationship.
Third-party vendor risk management policy
Management has defined a third-party vendor risk management approach for evaluating third-party risks.
User communication of significant system changes.
Significant system changes are communicated to users in a timely manner.
Version control software
Version control software is used to track changes to the source code and provide rollback capability if required.
Vulnerability management program
A vulnerability management program is defined and documented to assess and manage the technical security of systems including identification, prioritisation and resolution of vulnerabilities.
Security of processing
Personnel Processing Instructions
Implement architectural access controls ensuring that any person acting under the authority of the controller or processor, processes data according to instructions provided by the controller, unless required by Union or Member State law
Processing Security Measures
Implement technical and organizational measures (e.g., encryption, resilience, recovery capability) to ensure a level of security appropriate to the risk
Special category and criminal data
Sensitive Data Identification
Determine whether the project involves processing special categories of personal data (Art. 9, e.g., health, genetic, biometric data) or data relating to criminal convictions (Art. 10)
Supplier Security
Addressing information security within supplier agreements
Establish and agree relevant information security requirements with each supplier based on the type of supplier relationship, documented in formal agreements.
Information security for use of cloud services
Establish processes for acquisition, use, management, and exit from cloud services in accordance with the organization's information security requirements.
Information security in supplier relationships
Define and implement processes and procedures to assess and manage information security risks associated with the use of supplier products or services.
Managing information security in the information and communication technology (ICT) supply chain
Define and implement processes and procedures to manage information security risks specific to the ICT products and services supply chain.
Monitoring, review and change management of supplier services
Regularly monitor, review, evaluate, and manage changes in supplier information security practices and service delivery to detect degradation or non-compliance.
Test & Audit Security
Protection of information systems during audit testing
Plan and agree audit tests and other assurance activities involving assessment of operational systems between the tester and appropriate management.
Test information
Appropriately select, protect, and manage test information.