You get verifiable security elements, dated, and their limits.
Your IT department and your procurement team do not need a discourse on security, but dated elements, with their limits and a point of contact. You will find here how the security of the service is organised, what can be shown and what remains restricted. No certification, audit or availability rate appears here without evidence.
Organisation
Who answers for the security of the service
Security falls under an identified responsibility within the entity, with periodic reviews and a risk assessment specific to the activity. The corresponding elements are presented in the documentation file, with their limits and their date.
Access management
Access to systems and data is granted according to role, reviewed and logged. The rights table for a programme is settled at the first discussion. Nobody holds access that does not correspond to their role.
Protection of exchanges
Exchanges between your organisation, the service and the parties in the flow are encrypted in transit. Authentication arrangements, authorised channels and exchange formats are settled at the first discussion and described in the integration documentation.
Monitoring
Operations and access are monitored in proportion to the risks identified. The detail of these monitoring measures is not public: publishing it would reduce their effectiveness. We present it, to the extent useful, to organisations conducting a supplier assessment.
Incidents
An incident follows a procedure. We establish its nature and severity, we handle it, we inform the parties concerned, and we draw the lessons learned. The applicable notification time limits are those provided for by the regulations and by the contract, and not a general commercial commitment.
Available audits
The security documents, and their mode of access
A document appears here once it exists and can be provided in the mode indicated. Restricted documents are not hosted on this site.
Limits and point of contact
This page describes an organisation, not a result. A specific question from your IT department, a security questionnaire to complete or a clause to negotiate are dealt with through a point of contact. We do so with the documents to hand, while the programme is being prepared.