Document summary
This page explains security ownership, access, secure development, vulnerabilities, monitoring, incidents, backups, and providers according to service risk.
Security program
The program defines assets, owners, classification, risks, controls, indicators, and improvement plan. Applicability of national controls is reviewed based on the organization and clients, and no certification is claimed without audit.
Identity and access
Least privilege, MFA for sensitive accounts, periodic review, separation of staff and service accounts, and prompt removal on role change are applied. Highly sensitive access requires reason and re-authentication.
Secure development
Changes follow review, testing, documented dependencies, secret scanning, and reversible migration. Development, test, and production are separated and unredacted production data is not used in development.
Vulnerability management
A vulnerability records asset, severity, exposure, owner, due date, exception, and remediation verification. It is not closed when a patch is created before retest and deployment to all affected assets.
Monitoring and response
Necessary logs are collected with minimization and retention. Alerts link to an incident with lead, impact, timeline, communications, workaround, root cause, and prevention plan.
Backup and recovery
Backups are encrypted, separately stored, and monitored. Backup success alone is insufficient evidence. Restore, data integrity, and recovery timing are tested periodically.
Reporting
A responsible disclosure route and internal staff route are provided. Reports are restricted, triaged, and escalated, and privacy, client, and authority notifications are coordinated as applicable.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.