Entity has documented Disaster Recovery Policy, that establish guidelines and procedures on continuing business operations in case of a disruption or a security incident

Sep 08, 2023

Entity has a documented Vulnerability Management Policy and makes it available for all staff on the company employee portal

Sep 08, 2023

Entity maintains the inventory of endpoint assets and segregates assets with access to critical data from the others

Sep 08, 2023

Entity requires that all staff members with access to any critical system is protected with a secure login mechanism such as Multifactor-authentication

Sep 08, 2023

Entity maintains and periodically reviews the inventory of systems which are critical to security commitments and requirements

Sep 08, 2023

Entity requires that all staff members complete Information Security Awareness training annually

Sep 08, 2023