Internal security procedures
| Control | Status |
|---|---|
|
Continuity and Disaster Recovery plans established The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel. |
|
|
Continuity and Disaster Recovery plans tested The company has a documented Business Continuity/Disaster Recovery (BC/DR) plan and tests it at least annually. |
|
|
Organization structure documented The company maintains an organizational chart that describes the organizational structure and reporting lines. |
|
|
System changes communicated The company communicates system changes to authorized internal users. |
|
|
Company commitments externally communicated The company's security commitments are communicated to customers in Master Service Agreements (MSA) or Terms of Service (TOS). |
|
|
Service description communicated The company provides a description of its products and services to internal and external users. |
|
|
Risks assessments performed The company's risk assessments are performed at least annually. As part of this process, threats and changes (environmental, regulatory, and technological) to service commitments are identified and the risks are formally assessed. The risk assessment includes a consideration of the potential for fraud and how fraud may impact the achievement of objectives. |
|
|
Third-party agreements established The company has written agreements in place with vendors and related third-parties. These agreements include confidentiality and privacy commitments applicable to that entity. |