Internal security procedures
How the programme is run, measured and improved.
- Continuous control monitoringMonitored
Controls are monitored continuously, and a failing control opens a tracked issue.
- Incident response planMonitored
A tested plan with defined roles, and notification within 72 hours of a confirmed breach.
- Risk assessmentMonitored
Risks are assessed annually and when the business or the platform changes materially.
- Vendor managementMonitored
Vendors are assessed for security before onboarding and reviewed annually.
- Change managementMonitored
Production changes are reviewed, tested and deployed through an audited pipeline.
- Business continuityMonitored
Recovery objectives are defined and verified by restore drills.