Org Logo

Controls

Here are the controls implemented at Facctum to ensure compliance, as a part of our security program.

Product security (3)

Production System User Review

Situational Awareness For Incidents

Log Priviledged Operations

Data security (11)

Identify Validation

Termination of Employment

Production Databases Access Restriction

User Privileges Reviews

User Access Reviews

Encrypting Data At Rest

Inventory of Infrastructure Assets

Data Backups

Choice & Consent

Data Subject Access

Physical Security

Network security (9)

Impact analysis

Limit Network Connections

External System Connections

Transmission Confidentiality

Anomalous Behavior

Capacity & Performance Management

Data used in Testing

Cloud Provider Requirements

Centralized Collection of Security Event Logs

App security (6)

Conspicuous Link To Privacy Notice

Secure system modification

Approval of Changes

Testing of changes

Unauthorized Activities

Regression Testing

Endpoint security (5)

Malicious Code Protection (Anti-Malware)

Full Device or Container-based Encryption

Endpoint Security Validation

Session Lock

Endpoints Encryption

Corporate security (31)

Code of Business Conduct

Organizational Structure

Roles & Responsibilities

Competency Screening

Personnel Screening

New Hire Policy Acknowledgement

Security & Privacy Awareness

Performance Review

Periodic Policy Acknowledgement

Risk Assessment

Third-Party Criticality Assessments

Internal Audit using Sprinto

Management Review of Org Chart

Management Review of Risks

Management Review of Third-Party Risks

Segregates Roles and Responsibilities

Subprocessor Requirements

Data Protection Impact Assessment (DPIA)

EU Representative

Testing

Customer Obligations

Retention of Policies

UK Representative

Asset Ownership Assignment

Incident Management by Service Providers

Validate Security Controls

Review of Third-Party Services

Infosec training ack

New Hire Security & Privacy Training Records

Periodic Security & Privacy Training Records

Inventory of Endpoint Assets