Serensia - Technical and Organisational Measures

Technical and Organisational Measures, Including Measures to Ensure the Security of the Data

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risk — the probability and severity of which vary — to the rights and freedoms of natural persons, the data importer has implemented appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk.

Domain

Practices

Organisation of information security

Security responsibility. Each Party shall appoint one or more security officers responsible for coordinating and overseeing security policies and procedures.

Security roles and responsibilities. All personnel of each Party with access to data are subject to confidentiality obligations.

Risk management programme. Each Party shall carry out a risk assessment before processing the data or launching the relevant service.

Each Party shall retain its security documentation in accordance with its retention requirements after such documentation ceases to be in force

Asset management

Asset inventory. Each Party shall maintain an inventory of all assets on which the data is stored. Access to such asset inventories must be limited to personnel who have been authorised in writing to access them.

Asset management. Each Party shall classify data in order to identify it and appropriately restrict access to it.

Human Resources Security

Security training. Each Party shall inform its personnel of the applicable security procedures and their respective roles. Each Party shall also inform its personnel of the possible consequences of breaching security rules and procedures.

Physical and environmental security

Physical access to premises. Each Party restricts access to premises housing information systems processing data to identified and authorised persons.

Protection against disruptions. Each Party uses different systems in line with industry standards to protect against data loss due to power outages or line disruptions.

Component disposal. The controller uses standard procedures to delete data when it is no longer required.

Communications and operations management

Data restoration procedures. Each Party stores data backups and data restoration procedures in a location separate from the main IT equipment used to process the data. Malware. Each Party shall implement anti-malware controls to prevent malicious software from obtaining unauthorised access to the data, including malware originating from public networks.

Cross-border data:

- Each Party shall encrypt data transmitted over public networks;

- Each Party restricts access to data stored on media leaving its premises. Event logging. Each Party logs access to and use of information systems containing data, recording the access identifier, time, authorisation granted or denied, and corresponding activity.

Access Control

Access policy. Each Party shall maintain a record of the security privileges of persons having access to the data.

Access authorisation:

- Each Party shall disable authentication credentials that have not been used for a period not exceeding six months;

- Each Party shall identify personnel who may grant, modify or revoke authorised access to data and resources;

- Each Party shall ensure that persons have unique identifiers/logins.

Need-to-know

- Technical support personnel are authorised to access data only on a need-to-know basis. Each Party shall limit access to data to those persons who need such access to perform their duties.

Integrity and confidentiality:

- Each Party shall require its personnel to close administration sessions when leaving premises under its control or when computers are left unattended;

- Each Party shall store passwords in a manner that renders them unintelligible when used.

Authentication:

- Each Party shall use industry-standard practices to identify and authenticate users attempting to access information systems; where authentication mechanisms rely on passwords,

- Each Party shall require passwords to be changed regularly;

- Each Party shall ensure that disabled or expired identifiers are not assigned to other persons;

- Each Party shall maintain standard procedures for disabling passwords that have been compromised or inadvertently disclosed;

- Each Party uses industry-standard password protection practices, including practices designed to preserve the confidentiality and integrity of passwords when assigned and distributed, and when stored.

Network design. Each component includes controls designed to prevent persons from obtaining access rights that have not been granted to them in order to access data they are not authorised to view.

Information Security Incident Management

Incident response process:

- Each Party maintains a record of security breaches, including a description of the breach, the period concerned, the consequences of the breach, the source of the report, and the main mitigation and recovery measures.

- For each breach constituting a security incident, the processor shall notify the controller without undue delay.

Service monitoring. Operational personnel of each Party regularly review logs in order to propose corrective actions where necessary.

Business continuity management

The controller maintains contingency and disaster recovery plans for premises housing its information systems that process data.