Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Trust & firm

Trust & firm

Platform security

The target service rests on least privilege, MFA, encryption, separation of environments, logging and recovery.

Protect the workspace

Security measures follow the actual operations: opening access, depositing a document, viewing it, exporting it and resuming after an incident.

Useful security cannot be reduced to a checklist: it must protect the opening of access, document exchanges, user operations and service recovery.

Named and limited access

Successful authentication grants access only to the space, functions and duration required for the assigned role.

Layered defence

Identity, workspace, logging and recovery protect against different risks.

01

Access by role and scope

02

Encrypted transfer and storage

03

Restricted and logged processing

04

Backup and recovery

Putting into practice

Make access and changes reconstructible.

Authenticate

Verify identity and apply multi-factor authentication to the accesses concerned.

Isolate

Separate spaces, organisations and privileges according to the mandate.

Protect

Encrypt transfers and storage, then govern exports and processing.

Resume

Log relevant events and maintain backup, restoration and access revocation.

Checkpoints

01

Identity

Named account, role and strong authentication.

02

Scope

Space, functions and data actually accessible.

03

Log

Events required to reconstruct operations.

04

Recovery

Backup, restoration and handling of compromised access.

Operations within the client area

Reconstruct the access and changes that affect the file.

Identities, roles, relevant events and administrative decisions form a usable trail for examining an access, a change or a recovery.

See a trace of exploitation →
European client → Contract → Requirement
Promise → Policy → Practice → Platform
Evidence → Verification → Exception
Technical drift → Affected commitment
Remediation → Residual risk → Deadline

Preliminary exchange

Present the information and uses that will need to be protected.

Describe the spaces, data, users and operations that will need to be protected so that the necessary measures can be scoped.

Ask a question