ASUME

Trust Center

Human Resource Security

Personnel and contractor controls documented in Security Measures. Formal background-check, training, and SSO programmes are still being built out.

Personnel controls

Personnel who may access Customer Data, Processor Personal Data, production systems, or security information receive access only as needed for authorised responsibilities. Current personnel controls are described in Security Measures.

Authentication appropriate to system sensitivity, individually attributable accounts, and access lifecycle controls are described in Security Measures.

Contractor controls

Contractors who may access Customer Data or production systems are engaged under the same access, confidentiality, and vendor controls as personnel, as described in Security Measures.

Vendor access is limited to what is reasonably necessary for the relevant service.

Confidentiality agreements

Personnel and contractors who may access Customer Data, Processor Personal Data, production systems, security information, or ASUME confidential information are subject to confidentiality obligations appropriate to their role, as described in Security Measures.

A published requirement that every employee signs a standalone NDA on day one, with a downloadable template, is not independently verified. Treat the confidentiality obligations in Security Measures as the current baseline.

Access removal on offboarding

ASUME maintains processes for granting, modifying, and revoking relevant system access when personnel or contractors join, change roles, or leave, as described in Security Measures.

Access is removed or adjusted when a person leaves ASUME, changes responsibilities, or no longer requires access. See also Security Measures.

Internal SSO and MFA

ASUME is extending single sign-on (SSO) and multi-factor authentication (MFA) for internal systems so that access can be granted and revoked in one place and privileged access has a stronger authentication factor. Authentication appropriate to system sensitivity, including stronger controls for privileged systems where implemented, is described in Security Measures.

SSO and MFA are not yet uniformly required across every internal system. Until they are, treat the current authentication controls as the published baseline.

Employee training

Personnel with access to material systems or information receive security guidance, instructions, or awareness appropriate to their responsibilities, as described in Security Measures. Broader programme work lives on Training.

A mandatory annual information-security course, regular phishing simulations, and a security newsletter are still being formalized and are not independently verified.

Background checks

ASUME is defining background-check expectations for relevant roles as a condition of access to sensitive systems and information.

A published requirement that every senior manager completes a background check before employment is still being formalized and is not independently verified.

Incident response

ASUME maintains procedures for identifying, reporting, triaging, investigating, containing, and recovering from material security incidents, as described in Security Measures. The Trust Center page for Incident Response has the current detail.

A regularly tested, standalone incident-response plan published as an HR-security artefact is still being formalized and is not independently verified.

Asset management practices

ASUME is defining how organisational assets are identified, cataloged, and assigned ownership and protection requirements. Current work lives on Asset Management.

A centralized, real-time inventory across the entire infrastructure, reviewed annually as a formal HR-security control, is not independently verified.

Penetration testing

Independent third-party penetration testing of the Service is a roadmap item. Listing it here is not a representation that an annual pentest has been completed.

Until a report is published, vulnerability handling follows Security Measures and the Vulnerability Management page.