Contrôles
Les 90 contrôles de sécurité et de protection des données ci-dessous sont en place et démontrés par des preuves tenues à jour : tests automatiques quotidiens, revues d'accès trimestrielles, politiques signées, documents revus à échéance. Nous ne listons ici que ce que nous pouvons prouver.
Asset management2
- Secure media disposal
- Technology asset inventory
Business continuity and disaster recovery1
- Database backups
Change management1
- Customer notification for major changes
Compliance2
- Compliance requirements documentation
- Sector regulation applicability review
Configuration management1
- Baseline configuration management
Cryptographic protections2
- Encryption at rest
- Encryption in transit
Cybersecurity and data privacy governance13
- Annual strategic planning
- Board security briefings
- Governance committee charters
- Information security officer designation
- Information security policies
- Intellectual property protection
- Interested party requirements
- ISMS context analysis
- ISMS scope
- ISMS stakeholder management
- Organization chart
- Security roles and responsibilities
- Whistleblower mechanism
Data classification and handling3
- Customer data deletion
- Data classification and access control
- Data retention and deletion policy
Data privacy27
- Anonymisation and pseudonymisation
- Automated decision-making policy
- Breach communication templates
- Consent management
- Criminal data processing policy
- Data governance framework
- Data protection impact assessment
- Data protection officer
- Data sharing frameworks
- Data subject request intake
- Data subject request response timeline
- Documented position on children's data
- Erasure request management
- EU representative
- International transfer safeguards
- Joint controller agreements
- Lawful basis assessment
- Objection management
- Portability request management
- Privacy by design and by default
- Privacy policy
- Privacy requirements register
- Processing without identification
- Records of processing activities
- Rectification and erasure notifications
- Rectification request management
- Transfer derogations
Endpoint security3
- Anti-malware protection
- Remote work policy
- Removable media controls
Human resources security8
- Contractor background checks
- Contractor code of conduct acknowledgment
- Disciplinary process
- Employee background checks
- Employee code of conduct acknowledgment
- Employee confidentiality agreements
- Performance evaluations
- Termination access revocation
Identification and authentication2
- Production access management
- Session timeout enforcement
Incident response4
- Incident response procedures
- Regulatory authority communication
- Security concern resolution
- Security incident logging
Information assurance2
- Internal audit program
- Security documentation availability
Mobile device management1
- Mobile device management
Network security2
- Network architecture documentation
- Secure connection requirements
Physical and environmental security3
- Cabling and utility security
- Clear desk and screen policy
- Visitor management policy
Project and resource management1
- Security in project management
Risk management1
- Security and privacy risk management
Secure engineering and architecture6
- Code review and testing
- Environment and tenant segmentation
- Environment separation
- Secure development procedures
- Source code access controls
- Static application security testing
Security awareness and training1
- Security awareness training
Security operations1
- Time synchronization
Third-party management2
- Contractor confidentiality agreements
- Contractual security commitments
Threat management1
- Security community participation