Access reviews: Quarterly access reviews on in-scope systems ensure only authorized personnel have access. These reviews complement our automated controls, with governance led by our Chief Information Officer.
Change management: Our Systems Change Management Policy standardizes how changes to production environments are handled, minimizing the risk of unauthorized modifications.
Employee responsibilities: All employees must review the Acceptable Use Policy (AUP) and sign a confidentiality and non-disclosure agreement (NDA) to protect proprietary and customer information.
Training and awareness: New hires complete general security training in their first week, and all employees participate in monthly micro-trainings and periodic phishing simulations to maintain high security awareness. All developers are required to undergo ad-hoc application security training using vendor-supplied resources.
Security incident management: Guardsquare has a detailed incident management process for detecting and responding to, mitigating, and recovering from security incidents. Incidents can be reported to security@guardsquare.com. Our plan includes defining roles, communication channels, and incident response playbooks.