Expand | ||
---|---|---|
| ||
Does your organisation keep an up-to-date inventory of all IT assets with assigned owners? Yes, we hold a device register for all assets. More information: https://commonplace.atlassian.net/l/cp/T932Q17u |
Expand | |||
---|---|---|---|
| |||
Yes. More information: https://commonplace.atlassian.net/l/cp/mREyzmQk |
Expand | |||
---|---|---|---|
| |||
Yes. We have an offboarding process for all leavers which includes the return of all IT assets. More information: https://commonplace.atlassian.net/l/cp/TkH6cH18 |
Expand | |||||
---|---|---|---|---|---|
| Yes. We have an offboarding process for all leavers which includes removing access to systems and information when they leave. When an employee changes role, we also review their access rights.|||||
More information: https://commonplace.atlassian.net/l/cp/h1Jccs9A |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/epDzN51a |
Expand | |||||
---|---|---|---|---|---|
| |||||
More information: https://commonplace.atlassian.net/l/cp/DvBykkLj |
Expand | |||||
---|---|---|---|---|---|
| |||||
More information: https://commonplace.atlassian.net/l/cp/1JgqZr1m |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/6MA9BJ9F |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/18dzFfeE |
Expand | ||
---|---|---|
| ||
Do all of your organisations systems automatically lock after a short period of inactivity (requiring re-authentication)? Not all systems do this. However critical systems such as AWS and Google Workspace do. The Commonplace platform does not currently do this for users, but it is on our short term roadmap. More information: https://commonplace.atlassian.net/l/cp/urN201PV |
Expand | |||||
---|---|---|---|---|---|
| 1password is used by all employees and contractors. It provides a place for users to store various passwords, software licenses, and other sensitive information in a virtual vault that is locked with a PBKDF2-guarded master password.|||||
Browser based (Chrome, Safari etc) password saving is disabled for employees. More information: https://commonplace.atlassian.net/l/cp/aUR8cA2h |
Expand | |||
---|---|---|---|
| |||
We do not use Windows devices, we only use Apple Macs / iPads. More information: https://commonplace.atlassian.net/l/cp/oCCUquHU |
Expand | |||
---|---|---|---|
| |||
Yes. This is managed and enforced via Mobile Device Management, JamfPro. More information: https://commonplace.atlassian.net/l/cp/p1JHM9Wu |
Expand | |||||
---|---|---|---|---|---|
| Yes, XXXXX|||||
More information: https://commonplace.atlassian.net/l/cp/3AxhbHXt |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/M59XmU0d |
Expand | ||||
---|---|---|---|---|
| ||||
The Development of the Commonplace platform is managed through the development lifecycle. When the need for a change is identified that may impact on information security or data protection, we engage our Information Security Officer who reviews the scope and objectives of the change and completes our Change Management review, including a DPIA triage to identify if this is required. Where this process identifies items that impact information security or data protection, implementation planning and testing steps are put into place and worked through by a team consisting of internal stakeholders relevant to the change. Any new risks are added to the risk register with appropriate controls implemented where required. As part of our Change Management procedure, where new processing activity requiring an appropriate lawful basis is identified and Legitimate Interests is the selected basis, a Legitimate Interests Assessment is incorporated as part of the procedure to ensure it is completed and recorded along with the DPIA and other change records. A copy of our Change Management Policy is available upon request from customers@commonplace.is More information: https://commonplace.atlassian.net/l/cp/biUCVqVS |
Expand | |||
---|---|---|---|
| |||
Due to the nature of the service architecture (use of AWS, etc) we operate a hybrid of service administration via bastion hosts and direct service administration. The service is only accessible by authorised staff using secured VPN and SSH and utilising AWS IAM provisioning. This is done on devices also used for other general working purposes. These devices are all monitored via JamfPro and have up to date anti-malware software in place along with other controls such as FileVault, GateKeeper and XProtect. Device users have standard profiles by default with permissions elevated for fixed time periods upon request and authorisation. More information: https://commonplace.atlassian.net/l/cp/0mAsv0gH |
Expand | ||
---|---|---|
| ||
Does your organisation have procedures in place to control the installation of software on IT production systems (such as servers)? Due to the nature of the service architecture (use of AWS, etc), this is handled by third parties. XXXXX More information: https://commonplace.atlassian.net/l/cp/0CARWvTN |
Expand | |||
---|---|---|---|
| |||
Yes, via our Mobile Device Management solution JamfPro. More information: https://commonplace.atlassian.net/l/cp/orSKMh3F |
Expand | |||||
---|---|---|---|---|---|
| Yes, each employee is given a company owned Mac Book, provisioned via Apple Business Manager and monitored via JamfPro.|||||
More information: https://commonplace.atlassian.net/l/cp/iMn3S555 |
Expand | ||
---|---|---|
| ||
Are all company owned laptop hard drives encrypted? Yes. More information: https://commonplace.atlassian.net/l/cp/tJ6Pqgms |
Expand | |||||
---|---|---|---|---|---|
| Yes.|||||
More information: https://commonplace.atlassian.net/l/cp/B4d4Sj8v |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/jLc1uDWh |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/PAUimccf |
Expand | ||
---|---|---|
| ||
Does your organisation encrypt customer data on its IT systems? Yes. The Commonplace platform is hosted in AWS. The database is MongoDB Atlas, also hosted in AWS. In both cases, this is within the AWS London, UK region. AWS facilities comply with ISO 9001, ISO27001, ISO 27017 and ISO 28018 among others. Within our MongoDB Atlas database, all data is encrypted at rest using MongoDB’s inbuilt services through encrypted storage volumes. Within the Commonplace infrastructure, the following measures are in place: More information: https://commonplace.atlassian.net/l/cp/Kg3bXMZm |
Expand | ||
---|---|---|
| ||
Does your organisation ensure that all IT systems are regularly patched with security patches in line with vendor recommendations, including end point devices, servers, network devices, and applications? Yes. We use a number of automated security testing and patching tools to ensure we stay up to date with latest security updates to mitigate vulnerabilities and to validate any new code against a set of security standards. Additionally, our use of AWS ensures that the infrastructure underpinning the platform benefits from the world leading expertise and innovation delivered by AWS and significantly simplifies the process of maintaining a secure environment. Our CPTO, Head of Technology and Information Security Officer monitor new technologies and our Information Security Working Group meet monthly to discuss any emerging threats and technologies to understand where there may be risk or benefit to us and our customers. More information: https://commonplace.atlassian.net/l/cp/gSdyGXKg |
Expand | ||
---|---|---|
| ||
Does your organisation run any applications or systems that are no longer supported and no longer receive security updates? No. More information: https://commonplace.atlassian.net/l/cp/T0a1NJT5 |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/GfC6f8mE |
Expand | ||||
---|---|---|---|---|
| ||||
Every week, retained for a month, Every month, retained for a year |
Expand | |||||
---|---|---|---|---|---|
| We utilise Google Workspace for email which will always attempt to use a secure TLS connection when sending email. However, a secure TLS connection requires that both the sender and recipient use TLS. If the receiving server doesn't use TLS, Gmail still delivers messages, but the connection isn't secure.|||||
More information: https://commonplace.atlassian.net/l/cp/vBk5czvP |
Expand | ||
---|---|---|
| ||
Has your organisation implemented SPF, DMARC, and DKIM for all of its email services? |
Expand | ||||
---|---|---|---|---|
| ||||
More information: https://commonplace.atlassian.net/l/cp/WMZhveSN |
Expand | ||
---|---|---|
| ||
Are any components of the system (hardware, applications, software) outsourced or subcontracted to a third party? Yes. Sites are cloud hosted by Commonplace.
More information: https://commonplace.atlassian.net/l/cp/zNF6JF9X |
Expand | ||||
---|---|---|---|---|
| ||||
Our list of sub-processors used within our platform is on our website. The way we deal with sub-processors is covered in our standard license agreement. More information: https://commonplace.atlassian.net/l/cp/NBMjBmiC |
Expand | ||
---|---|---|
| ||
What are your ‘patch deployment cycles’ and maintenance windows? We deploy code multiple times per day using Continuous Integration and Continuous Deployment. We have never required any planned downtime and do not expect to do so. Should this change, we will inform our customers with a 14 day advanced notification of the change and keep any interruptions to off peak hours.https://commonplace.atlassian.net/l/cp/Q1omZezA |
Expand | ||
---|---|---|
| ||
Does your organisation have an enforceable password policy? Yes. In accordance with Cyber Essentials we have a password policy for our internal team users when using our various cloud services. This includes definitions around the generation and storing of passwords, which we enforce via the 1Password application and the use of MFA wherever it is available. Commonplace application users are subject to minimum password length and a strength indicator when creating or changing a password.https://commonplace.atlassian.net/l/cp/CaCP1ZEU |