ASUME

Trust Center

Access Control

How access to ASUME systems is granted, authenticated, reviewed, and removed. Device, VPN, and BYOD controls that are not yet documented are listed separately.

Least privilege

ASUME applies least privilege so that access rights stay limited to what is needed for a role. Individually attributable accounts, authentication appropriate to system sensitivity, and access lifecycle controls — provisioning, review, and removal when roles change or engagement ends — are described in Security Measures.

A documented quarterly access-review calendar is still being formalized. Until it is published, access is reviewed when roles change and when engagement ends.

Logging

ASUME enables logging on production systems and applications as part of how the Service is operated. These logs provide an audit trail used to monitor for suspicious behaviour and to investigate security incidents, as described in Security Measures.

A company-wide logging baseline covering every internal system is still being formalized and is not independently verified.

Log management and monitoring standard

ASUME is building a log-management and monitoring standard so that security-event logs from critical systems can be collected, reviewed, and used to identify potential threats. Current production logging is described in Security Measures.

Centralized, real-time monitoring and automated alerting across every critical system are not yet in place and are not independently verified.

Password security

ASUME is formalizing password and access-control expectations, including complexity, length, and secure storage. Authentication appropriate to system sensitivity is described in Security Measures.

A mandatory company password vault, a required password generator, and uniform MFA across every system are still being built out. Until those are published, treat the current authentication controls as the baseline.

Internal single sign-on

ASUME is extending single sign-on (SSO) for internal systems so that employee access can be granted and revoked in one place.

SSO is not yet enforced across every internal system. Until it is, access follows the identity and access controls in Security Measures.

Separation of duties

ASUME is embedding separation of duties in how access is granted and how production changes are made, to reduce the risk of a single person both requesting and approving a sensitive action.

This control is not yet a documented company-wide standard and is not independently verified.

Device lock

ASUME is defining a workstation policy so that screens lock after a short period of inactivity and users re-authenticate to resume a session, with biometric unlock where the device supports it.

A published global lock-after-five-minutes standard is still being formalized and is not independently verified.

Virtual private network (VPN)

ASUME is defining how remote connections to internal systems are protected so that traffic to company information assets stays encrypted.

A mandatory enterprise VPN for every remote connection is still being formalized and is not independently verified.

Bring your own device (BYOD)

A published Bring Your Own Device (BYOD) standard — including whether personal devices may access source-code repositories and other critical information assets — is a roadmap item.

Until that standard is published, access to production systems and source follows the identity and access controls in Security Measures.