How Decisive Analytical Systems secures both On-Demand (SaaS) and On-Premise (PaaS) deployments of Plumb5, and responds to security incidents.
Plumb5 offers both On-Demand (SaaS) and On-Premise (PaaS) deployments. Technical and organizational security and privacy measures are implemented for each type of offering in compliance with Decisive Analytical Systems policy, according to its architecture, intended use, and the type of service provided.
This Data Security and Privacy Principles document describes the Decisive Analytical Systems policies and practices.
Decisive Analytical Systems security policies, which derive their authority from specific corporate instructions, are established and managed by the organization and are an integral part of our business. Compliance with internal IT policies is mandatory and audited.
Decisive Analytical Systems information security policies are reviewed at least annually and refined as necessary to keep current with modern threats and in line with updates to broadly accepted international standards.
Decisive Analytical Systems follows a mandated set of employment verification requirements for all new hires, including supplemental employees — which may include criminal background checks, proof of identity validation, and additional checks where a candidate previously worked for a government entity. Each Decisive Analytical Systems company is responsible for implementing these requirements as applicable and permissible under local law.
Security incidents are handled in accordance with Decisive Analytical Systems incident management and response policies, taking into account data breach notification requirements under applicable law.
The core functions of our cybersecurity incident management practice are conducted by our Infrastructure Team, which coordinates with other functions to investigate suspected incidents and, if warranted, define and execute the appropriate response plan. Upon determining that a security incident has occurred, Decisive Analytical Systems will promptly notify affected cloud services clients as appropriate.
The architecture of Decisive Analytical Systems services maintains logical separation of client data. Internal rules and measures separate data processing — inserting, modifying, deleting, and transferring data — according to the contracted purposes. Access to client data, including any personal data, is allowed only by authorized personnel in accordance with principles of segregation of duties, strictly controlled and monitored under our internal privileged user monitoring and auditing.
Privileged access authorization is individual, role-based, and subject to regular validation. Access to client data is restricted to the level required to deliver services and support to the client (least required privilege).
Transfer of data within the network takes place on wired infrastructure and behind firewalls, without the use of wireless networking. Upon request or service termination, pursuant to the cloud service agreement, client data is rendered unrecoverable in conformity with guidelines for media sanitization.
Modifications to operating system resources and application software are governed by change management policies. Changes to network devices and firewall rules are also governed by change management policies and are separately reviewed by security staff prior to implementation.
Decisive Analytical Systems cloud services undergo penetration testing and vulnerability scanning prior to production release. Additionally, penetration testing, vulnerability scanning, and ethical hacking is performed by Decisive Analytical Systems and authorized independent third parties.
Decisive Analytical Systems policy requires administrative access and activity in its cloud services' computing environments to be logged and monitored, and the logs to be archived and retained in compliance with the management plan.
Changes made to production cloud services are recorded and managed in compliance with our change management policy.
Decisive Analytical Systems maintains physical security standards designed to restrict unauthorized physical access to resources. Entry points into our data centers are limited, controlled by access readers, and monitored. Access is allowed only by authorized personnel.
Delivery areas where unauthorized persons may enter the premises are strictly controlled. Personnel who are not part of the operations, facilities, or security staff are registered upon entering the premises and are escorted by authorized personnel while on the premises. Terminated employees are removed from the access list and required to surrender their access badges. Use of access badges is logged.
Data processing is performed according to the offering agreement in which Decisive Analytical Systems describes the terms, functionality, support, and maintenance of a cloud service offering, and the measures taken to maintain the confidentiality, integrity, and availability of client data.
Decisive Analytical Systems information security standards and management practices for cloud services are aligned to global standards for information security management. Assessments and audits are conducted on a need basis to track compliance with our information security standards.
Decisive Analytical Systems cloud services may require a third party to access client data in the normal performance of their contracted duties. If such a sub-processor is engaged in the delivery of a cloud service, the sub-processor and its role will be provided upon request. We require all such sub-processors to maintain standards, practices, and policies which preserve the overall level of security and privacy we provide.
In accordance with industry best practices and to comply with numerous compliance regulations, Decisive Analytical Systems has implemented procedures, policies and guidelines to protect the confidentiality, integrity and availability of critical client data and computing resources. This plan is reviewed and refined at least annually as new technologies and requirements are introduced.
There are many different security incidents that can occur, with assorted severity levels, and not all incidents require focus on every step — but it's important to understand the phases involved and the goals of each. The phases of our incident response plan are: Prepare, Identify, Contain, Eradicate, Recover, and Review.
Awareness that a security incident has occurred can originate from different sources — technical people, end users, or even clients. Best practice is to declare an incident once security officers sense an adverse risk exists, assemble the team, and implement the plan — involving multiple people early, preserving key system files and logs, and starting detailed documentation as soon as possible. Business owners are involved in deciding the goals of handling a particular incident, such as immediate business recovery or forensic examination.
This phase allows Decisive Analytical Systems to better handle future security incidents. A final report is written describing the incident and how it was handled, using the incident reporting form, with suggestions for handling future incidents and refining this document.
Personnel that might assist in handling an incident:
Business owners to make key business decisions: