Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually.
Disciplinary Action
Personnel who violate information security policies are subject to disciplinary action and such disciplinary action is clearly documented in one or more policies.
Code of Conduct
A Code of Conduct outlines ethical expectations, behavior standards, and ramifications of noncompliance.
Risk Assessment
Vendor Due Diligence Review
Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis.
Access Security
Unique Access IDs
Personnel are assigned unique IDs to access sensitive systems, networks, and information
Communications
Privacy Policy
A Privacy Policy to both external users and internal personnel. This policy details the company's privacy commitments.