Information classification and handling
Information must be classified according to its sensitivity and criticality and handled in line with its required level of protection. Rules for access, use, storage, transmission and disposal will be defined in accordance with that classification.
Access and identity control
Access to information and systems will be granted in accordance with the principles of least privilege, need to know and individual identity. The organisation will manage, in a controlled manner, the life cycle of users, privileged accounts, authentication and remote access.
Secure development
The development and maintenance of CustomsGo will follow secure development practices, code review, change control, protection of test data and priority response to vulnerabilities in production.
Network, encryption and endpoint security
The organisation will apply appropriate measures for network protection, segmentation, encryption, hardening, system patching, screen locking, anti-malware protection and control over the use of devices and removable media.
Management of operations, changes and logs
Changes to systems and environments, backups, resource capacity, maintenance, the generation and retention of logs, and the traceability of security-relevant activity will all be controlled.
Incidents, vulnerabilities and continuity
The organisation will define and maintain procedures for the reporting, classification, response, analysis of and learning from security incidents, as well as for vulnerability management, business continuity and disaster recovery.
Third parties and the supply chain
Suppliers and third parties with access to VM2 information or assets must meet security requirements proportionate to their criticality. The organisation will control third-party relationships, confidentiality agreements, subcontracting and supply chain risks.
Training and awareness
All staff must receive initial and periodic information security training and awareness, according to their role.