Monitoring

Change Management
Software Change Testing
Software changes are tested prior to being deployed into production.
Segregation of Environments
Development, staging, and production environments are segregated.
Production Data Use is Restricted
Production data is not used in the development and testing environments, unless required for debugging customer issues.
Secure Development Lifecycle
A software development life cycle (SDLC) is utilized to designate milestones that must be achieved throughout the development and testing process. Policies and procedures govern the testing, evaluation, and authorization of system components before implementation.
Change Management Controls
Policies and procedures govern the documenting, tracking, testing, and approving of changes. A ticket or change management form is completed and properly approved before core changes are made to production application code. Change management software is used to manage and log all application changes.
System Configuration Controls
Policies and procedures are in place to ensure that design, acquisition, implementation, configuration, modification, and management of infrastructure and software are consistent with defined system security policies.
Availability
Business Continuity and Disaster Recovery Plan
A current Disaster Recovery Plan and Business Continuity Plan are maintained. These plans are periodically tested and help ensure that disruptive incidents are responded to quickly and effectively.
Backup Policy and Data Protection
A backup policy is in place. Backups of production systems and data are completed in a timely manner, and the retention period for backup data has been defined by management.
Business Continuity and Disaster Recovery Testing
The Business Continuity and Disaster Recovery Plans are periodically tested. Management uses test results to evaluate and update the plans as necessary.
Uptime and Availability Monitoring
Third-party enterprise monitoring tools monitor system uptime, downtime, and critical performance metrics. Alerts are triggered when predefined thresholds are exceeded.
Organizational Management
Internal Control Policies
Internal control policies identify how a system of controls should be maintained to safeguard assets, promote operational efficiency, and encourage adherence to prescribed managerial policies.
Information Security Standards and Conduct
The importance of information security is communicated through ongoing training for employees, documented information security policies, and frequent discussion of individual responsibilities for data and systems security. Employees are required to read and sign acknowledgement of security policies and procedures annually.
Background Checks
Comprehensive background checks are performed by an independent third party for both employees and contract workers (1099) as part of the hiring process.
New Hire Screening
Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency to fulfill their responsibilities. New hires sign confidentiality agreements or equivalents upon hire.
Performance Reviews
Internal personnel are evaluated via a formal performance review at least annually. A formal evaluation is prepared and maintained in the employee's HR file.
Information Security Program Review
Security policies are reviewed and updated at least annually by senior management for consistency with the organization’s risk mitigation strategy, and updated as necessary for changes in the strategy.
Internal Control Monitoring
A continuous monitoring solution monitors internal controls used in the achievement of service commitments and system requirements.
Roles and Responsibilities
Information security roles and responsibilities are outlined for personnel responsible for the security, availability, and confidentiality of the system.
Management Oversight of Security
Operational meetings are held on a regular basis to discuss internal control responsibilities and performance measurement. Senior management oversees risk management, accountability, and is involved in the risk identification process. A formal annual risk assessment is performed and documented.
Personnel Accountability
A policy is in place to assign responsibility and accountability for developing and maintaining the entity's security policies, and changes and updates to those policies, to appropriate personnel.
Organizational Chart
Management maintains a formal organizational chart to clearly identify positions of authority and the lines of communication, and publishes the organizational chart to internal personnel.
Information Security Policies
Documented information security policies establish security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data. These policies are reviewed annually and communicated to all relevant personnel.
Confidentiality
Data Classification Policy
A Data Classification Policy details the security and handling protocols for sensitive data.
Disposal of Customer Data
Upon customer request, Company requires that data that is no longer needed from databases and other file stores is removed in accordance with agreed-upon customer requirements.
Data Retention and Disposal Policy
A Data Retention and Disposal Policy specifies how customer data is to be retained and disposed of based on compliance requirements and contractual obligations.
Vulnerability Management
Vulnerability and Patch Management Policy
A Vulnerability Management and Patch Management Policy outlines the processes to efficiently respond to identified vulnerabilities.
Incident Response
Incident Response Plan
An Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning and tracking confirmed incidents through to resolution.
Risk Assessment
Risk Register
A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy.
Vendor Risk Management Policy
A Vendor Risk Management Policy defines a framework for the onboarding and management of the vendor relationship lifecycle.
Risk Assessment
Formal risk assessments are performed, which includes the identification of relevant internal and external threats related to security, availability, confidentiality, and fraud, and an analysis of risks associated with those threats.
Risk Assessment and Treatment Policy
A Risk Assessment and Treatment Policy governs the process for conducting risk assessments to account for threats, vulnerabilities, likelihood, and impact with respect to assets, team members, customers, vendors, suppliers, and partners. Risk tolerance and strategies are also defined in the policy.
Network Security
Network Security Policy
A Network Security Policy identifies the requirements for protecting information and systems within and across networks.
Automated Alerting for Security Events
Alerting software is used to notify impacted teams of potential security events.
Access Security
Asset Inventory
A list of system assets, components, and respective owners are maintained and reviewed at least annually
Access Control and Termination Policy
An Access Control and Termination Policy governs authentication and access to applicable systems, data, and networks.
Access to Product is Restricted
Non-console access to production infrastructure is restricted to users with a unique SSH key or access key
Encryption-in-Transit
Service data transmitted over the internet is encrypted-in-transit.
Encryption and Key Management Policy
An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls.
Removal of Access
Upon termination or when internal personnel no longer require access, system access is removed, as applicable.
Physical Security
Physical Access Restrictions
Processes are in place to create, modify or remove physical access to facilities such as data centers, office spaces, and work areas based on the needs of such individual.
Physical Security Policy
A Physical Security Policy that details physical security requirements for the company facilities is in place.
Communications
Security Issue Reporting
Policies and procedures are in place to guide personnel regarding addressing how complaints and requests relating to security issues are resolved. Management has implemented processes to handle security concerns raised by both internal personnel and external parties.
Communication of Security Commitments
Security commitments and expectations are communicated to both internal personnel and external users via the company's website.
Privacy Policy
A Privacy Policy to both external users and internal personnel. This policy details the company's privacy commitments.
Communication of Critical Information
Critical information is communicated to external parties, as applicable.