The Board of Directors meets at least annually, dependent on organisational needs, and exercises oversight of the development and implementation of internal controls.
Company management meets monthly against a recommended agenda to oversee the company's objectives.
The company has defined structures and reporting lines with assigned authority and responsibilities in order to appropriately meet security requirements.
Formal policies and procedures are documented, reviewed, and approved annually by management, and are available to employees.
Employees and contractors are required to read and accept the Code of Conduct and Acceptable Use Policy. Signed employment agreements contain a confidentiality clause, and management monitors compliance.
The company conducts pre-employment screening checks commensurate with the role, in accordance with local laws and the HR policy. The same process is followed for contractors.
New employees and contractors complete an onboarding process covering role responsibilities, organisational policies, and provisioning of relevant access.
The company provides education and training to ensure the skill sets and technical competency of relevant employees are developed and maintained.
The company performs an annual performance review of all employees with 12 or more months of tenure, evaluated in alignment with the company's objectives.
A disciplinary process is established and communicated to take action against personnel and other relevant parties who violate information security policy.
A detailed description of the product architecture and system boundaries is documented and available internally to the company's employees.
The company maintains a Security and Privacy Awareness Training program that all employees are required to complete every year.
The company maintains an internal knowledge base describing its environment, boundaries, user responsibilities, and services.
Detected security incidents are communicated to and reviewed by the individual responsible for security management in the company.
The company maintains external documentation describing product features, system boundaries, and user guides.
New features are communicated to customers in the documentation portal to keep them updated on major product releases.
Service interruptions are communicated to customers via the status page.
Client issues are reported via a dedicated support tool and handled using a ticketing system.
Customer support issues are handled through the relevant communication channels.
The company maintains a formal risk management program to assess information security risks affecting its business objectives, regulatory requirements, and customers. Treatment options include acceptance, avoidance, mitigation, and transfer.
The annual risk assessment summary is presented to senior management for review, comment, and approval. Minutes and action items are documented.
The company identifies, classifies, and manages an inventory of information assets, which is reviewed by management on an annual basis.
An external web application penetration test is conducted annually to identify gaps and vulnerabilities.
All access requests to organisational systems, including administrator accounts, are approved prior to access provisioning.
The company manages access governance through a group-based access control matrix that reflects the minimum access required to perform each business function.
A formal password standard governs authentication: a minimum of 8 characters, mixed character types, reuse prevention where possible, expiry of at most 365 days where technically possible, and mandatory two-factor authentication.
Access to the identity management tool uses two-factor authentication and is restricted to authorised personnel.
Access to the production environment console is restricted to authorised personnel and uses a two-factor authentication method.
Access to the source control tool uses two-factor authentication and is restricted to authorised personnel.
Access to the production server is performed using an SSH key and is restricted to authorised personnel.
The ability to alter and delete backups is restricted to authorised users and uses two-factor authentication.
An established key management process supports the use of cryptographic techniques. Generating, storing, using, rotating, and destroying encryption keys is defined in the Encryption policy.
Provisioning of new user access is performed as part of the onboarding process, documented and collaborated on in a GitHub Issue ticket.
User accounts for terminated users are disabled or deleted in a timely manner upon notification of termination. Organisational assets are returned and wiped clean.
User access and permissions in restricted environments are reviewed and approved by management on a quarterly basis.
Inbound and outbound traffic rules are configured via network security groups in the production environment.
Customer passwords are protected through hashing and salting.
Communication between customers and company assets is encrypted using a valid HTTPS TLS 1.2 (or above) authenticated certificate.
Restricted information assets containing sensitive customer data on databases, storage, and backups are at least disk-level encrypted.
Employee devices are secured with OS-appropriate settings: Windows via Intune (disk encryption, auto-patching, auto screen-lock); macOS (disk encryption, automatic updates, lock screen); Linux (disk encryption, lock screen).
Windows endpoints are centrally configured with Microsoft Defender; macOS endpoints use XProtect and Gatekeeper to protect against malware.
A procedure ensures data and software stored on organisational devices is identified and disposed of in an appropriate manner.
An audit trail of security logs runs continuously in the production environment, capturing actions made to cloud resources and object-level storage actions.
Audit trail security logs are configured to be retained for a minimum of 7 days.
A detection service continuously monitors the production environment for malicious and unexpected activity. Alerts are sent to relevant stakeholders, and incidents are reviewed and resolved per the vulnerability and threat management policy.
A Security Incident Response Policy governs response to security incidents and personal data breaches in accordance with applicable laws and regulations. Data restoration checks are performed annually.
Contingency planning and incident response playbooks are maintained and updated to reflect emerging continuity risks and lessons learned from past incidents.
A root cause analysis is prepared and reviewed by management for high-severity incidents, with change requests raised for remediation and resolution.
Change requests are documented as tickets in the change management system, with pull requests and change tickets linked so each code change can be tracked.
Code changes must be reviewed and approved in order to progress through the SDLC and deploy a version to production.
Source code dependencies and packages are scanned on an ongoing basis for vulnerabilities. Detected issues trigger an update pull request and are logged and resolved per policy.
A successful test result is mandatory to continue the SDLC and deploy to production. On test failure, the build is stopped and does not deploy.
Production and non-production environments are segregated to enforce the confidentiality and privacy of customer data.
The company assesses, on an annual basis, the risks that vendors and business partners represent to the achievement of its objectives.
The company reviews critical vendors' SOC 2 reports annually, documenting the controls in place to address CUECs, any noted deviations, and the auditor's opinion.
IT vendors that engage with the company are subject to information security, confidentiality, and privacy commitments as part of their agreements.
Critical system components are deployed within a single availability zone, with backups stored in a different availability zone to address the risk of zone loss.
A Disaster Recovery Plan is maintained to continue providing critical services in the event of a disaster, and is reviewed on an annual basis.
Disaster recovery testing is conducted annually. Participating teams develop test plans and post-mortems documenting the results and lessons learned.
Data assets containing customer and confidential information are identified and protected, with retention based on asset type and management commitments.
The company can track and identify customer data across its assets, including databases, storage, and backups.
Procedures are in place to dispose of confidential information in accordance with the company's data retention and disposal policy.