JJaydaiTrustDemander l'accès

Contrôles

Les 90 contrôles de sécurité et de protection des données ci-dessous sont en place et démontrés par des preuves tenues à jour : tests automatiques quotidiens, revues d'accès trimestrielles, politiques signées, documents revus à échéance. Nous ne listons ici que ce que nous pouvons prouver.

Asset management2

  • Secure media disposal
  • Technology asset inventory

Business continuity and disaster recovery1

  • Database backups

Change management1

  • Customer notification for major changes

Compliance2

  • Compliance requirements documentation
  • Sector regulation applicability review

Configuration management1

  • Baseline configuration management

Cryptographic protections2

  • Encryption at rest
  • Encryption in transit

Cybersecurity and data privacy governance13

  • Annual strategic planning
  • Board security briefings
  • Governance committee charters
  • Information security officer designation
  • Information security policies
  • Intellectual property protection
  • Interested party requirements
  • ISMS context analysis
  • ISMS scope
  • ISMS stakeholder management
  • Organization chart
  • Security roles and responsibilities
  • Whistleblower mechanism

Data classification and handling3

  • Customer data deletion
  • Data classification and access control
  • Data retention and deletion policy

Data privacy27

  • Anonymisation and pseudonymisation
  • Automated decision-making policy
  • Breach communication templates
  • Consent management
  • Criminal data processing policy
  • Data governance framework
  • Data protection impact assessment
  • Data protection officer
  • Data sharing frameworks
  • Data subject request intake
  • Data subject request response timeline
  • Documented position on children's data
  • Erasure request management
  • EU representative
  • International transfer safeguards
  • Joint controller agreements
  • Lawful basis assessment
  • Objection management
  • Portability request management
  • Privacy by design and by default
  • Privacy policy
  • Privacy requirements register
  • Processing without identification
  • Records of processing activities
  • Rectification and erasure notifications
  • Rectification request management
  • Transfer derogations

Endpoint security3

  • Anti-malware protection
  • Remote work policy
  • Removable media controls

Human resources security8

  • Contractor background checks
  • Contractor code of conduct acknowledgment
  • Disciplinary process
  • Employee background checks
  • Employee code of conduct acknowledgment
  • Employee confidentiality agreements
  • Performance evaluations
  • Termination access revocation

Identification and authentication2

  • Production access management
  • Session timeout enforcement

Incident response4

  • Incident response procedures
  • Regulatory authority communication
  • Security concern resolution
  • Security incident logging

Information assurance2

  • Internal audit program
  • Security documentation availability

Mobile device management1

  • Mobile device management

Network security2

  • Network architecture documentation
  • Secure connection requirements

Physical and environmental security3

  • Cabling and utility security
  • Clear desk and screen policy
  • Visitor management policy

Project and resource management1

  • Security in project management

Risk management1

  • Security and privacy risk management

Secure engineering and architecture6

  • Code review and testing
  • Environment and tenant segmentation
  • Environment separation
  • Secure development procedures
  • Source code access controls
  • Static application security testing

Security awareness and training1

  • Security awareness training

Security operations1

  • Time synchronization

Third-party management2

  • Contractor confidentiality agreements
  • Contractual security commitments

Threat management1

  • Security community participation