Governance and operations
Security procedures
Documented processes supporting governance and operational resilience.
Information security policy set
01Security policies have named owners, are version controlled and are reviewed on a defined schedule.
Incident response plan
02A defined response process documents roles, communications and escalation paths for security incidents.
Risk assessment and treatment
03Security risks are identified, assessed, treated and tracked using a repeatable methodology.
Business continuity and disaster recovery
04Recovery objectives and procedures support the restoration of critical services following disruption.
Change management
05Changes are assessed, approved and recorded to support stable and auditable production operations.
Vendor and subprocessor management
06Suppliers are security assessed before onboarding and reviewed periodically thereafter.
Data breach notification procedure
07A defined process supports assessment, containment and required notification following a data breach.