ASUME

Trust Center

Endpoint Security

Workstation and endpoint controls. ASUME has not published a standalone endpoint-security standard; items below are in progress or planned.

Workstation hardening

ASUME is defining how workstations used to build and operate the Service are configured and restricted, including baseline settings that reduce the chance of unauthorized software or access.

A published workstation-hardening standard is still being formalized and is not independently verified.

Anti-malware

ASUME is extending protection against malware, spyware, and common exploits on devices used to operate the Service.

Enforcement of a named EDR or anti-malware product on every endpoint is not yet in place and is not independently verified.

Endpoint detection and response

A published endpoint detection and response (EDR) programme — continuous monitoring and behavioural analysis on every employee endpoint — is a roadmap item.

Listing EDR here is not a representation that an EDR product is deployed on all devices today.

Threat intelligence

Feeding Indicators of Compromise and other threat-intelligence sources into a SIEM for automated analysis is a roadmap item.

Until that programme is in place, ASUME reviews public advisories as part of how vulnerabilities are handled. Listing threat intelligence here is not a current claim.

Threat detection

Custom SIEM use cases that are continuously updated for new threats are a roadmap item.

Until a SIEM programme is in place, detection follows the logging and review practices in Security Measures.