Trust Center - Ethyca
Ethyca
Privacy compliance automated
To grow your business, you need to prove your customers can trust you with their data.
Ethyca simplifies trust - so you can focus on business.
Controls
Updated 33 minutes ago
Infrastructure security
| Control | Status |
|---|---|
| Infrastructure performance monitored An infrastructure monitoring tool is utilized to monitor systems, infrastructure, and performance and generates alerts when specific predefined thresholds are met. |
|
| Network and system hardening standards maintained The company's network and system hardening standards are documented, based on industry best practices, and reviewed at least annually. |
|
| Log management utilized The company utilizes a log management tool to identify events that may have a potential impact on the company's ability to achieve its security objectives. |
|
| Access control procedures established The company's access control policy documents the requirements for the following access control functions: - adding new users; - modifying users; and/or - removing an existing user's access. |
|
| Encryption key access restricted The company restricts privileged access to encryption keys to authorized users with a business need. |
|
| Network segmentation implemented The company's network is segmented to prevent unauthorized access to customer data. |
|
| Access requests required The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned. |
|
| Remote access MFA enforced The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method. |
|
| Data encryption utilized The company's datastores housing sensitive customer data are encrypted at rest. |
|
| Production network access restricted The company restricts privileged access to the production network to authorized users with a business need. |
Organizational security
| Control | Status |
|---|---|
| Employee background checks performed The company performs background checks on new employees, where allowed by law. |
|
| Employee Handbook acknowledged by employees The company’s employees acknowledge the employee handbook at the time of hire. The handbook contains guidance on employee behavior and conduct. |
|
| Data retention procedures established The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data. |
|
| Anti-malware technology utilized The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems. |
|
| Vulnerability and system monitoring procedures established The company's formal policies outline the requirements for the following functions related to IT / Engineering: - vulnerability management; - system monitoring. |
Product security
| Control | Status |
|---|---|
| Control self-assessments conducted The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. |
|
| Penetration testing performed The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs. |
Internal security procedures
| Control | Status |
|---|---|
| SOC 2 - System Description Complete a description of your system for Section III of the audit report |
|
| Organization structure documented The company maintains an organizational chart that describes the organizational structure and reporting lines. |
|
| Roles and responsibilities specified Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in the Roles and Responsibilities policy. |
|
| Cybersecurity insurance maintained The company maintains cybersecurity insurance to mitigate the financial impact of business disruptions. |
|
| Security policies established and reviewed The company's information security policies and procedures are documented and reviewed at least annually. |
|
| System changes communicated The company communicates system changes to authorized internal users. |
|
| Incident response policies established The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users. |
|
| Risk management program established The company has a documented risk management program in place that includes guidance on the identification of potential threats, rating the significance of the risks associated with the identified threats, and mitigation strategies for those risks. |
|
| Risks assessments performed The company's risk assessments are performed at least annually. As part of this process, threats and changes (environmental, regulatory, and technological) to service commitments are identified and the risks are formally assessed. The risk assessment includes a consideration of the potential for fraud and how fraud may impact the achievement of objectives. |
|
| Continuity and Disaster Recovery plans established The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel. |
Data and privacy
| Control | Status |
|---|---|
| Data classification policy established The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel. |
|
| Customer data deleted upon leaving The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service. |
Vanta connects to a company's core systems to continuously monitor these controls.