Trust & firm
Platform security
The target service rests on least privilege, MFA, encryption, separation of environments, logging and recovery.
Protect the workspace
Security measures follow the actual operations: opening access, depositing a document, viewing it, exporting it and resuming after an incident.
Useful security cannot be reduced to a checklist: it must protect the opening of access, document exchanges, user operations and service recovery.
Successful authentication grants access only to the space, functions and duration required for the assigned role.
Layered defence
Identity, workspace, logging and recovery protect against different risks.
Encrypted transfer and storage
Restricted and logged processing
Backup and recovery
Putting into practice
Make access and changes reconstructible.
Authenticate
Verify identity and apply multi-factor authentication to the accesses concerned.
Isolate
Separate spaces, organisations and privileges according to the mandate.
Protect
Encrypt transfers and storage, then govern exports and processing.
Resume
Log relevant events and maintain backup, restoration and access revocation.
Checkpoints
Identity
Named account, role and strong authentication.
Scope
Space, functions and data actually accessible.
Log
Events required to reconstruct operations.
Recovery
Backup, restoration and handling of compromised access.
Operations within the client area
Reconstruct the access and changes that affect the file.
Identities, roles, relevant events and administrative decisions form a usable trail for examining an access, a change or a recovery.
See a trace of exploitation →Preliminary exchange
Present the information and uses that will need to be protected.
Describe the spaces, data, users and operations that will need to be protected so that the necessary measures can be scoped.

