Entity has a documented HR Security Policy, and makes it available for all staff on the company employee portal
Entity’s infrastructure is configured to generate audit events for actions of interest related to security for all critical systems
Entity has documented Business Continuity Policy, that establish guidelines and procedures on continuing business operations in case of a disruption or a security incident
Entity has documented Disaster Recovery Policy, that establish guidelines and procedures on continuing business operations in case of a disruption or a security incident
Entity has a documented Vulnerability Management Policy and makes it available for all staff on the company employee portal
Entity maintains the inventory of endpoint assets and segregates assets with access to critical data from the others