Security and Protection of Stakeholder Data
Protecting stakeholder data is a normal part of how we operate. It is considered in the way we manage access, develop software, secure devices, monitor our environment, and respond to incidents.
Our security practices are informed by recognised standards and good practice, including alignment with ISO 27001 principles. Our application security approach is also guided by OWASP ASVS. While we are not currently ISO 27001 certified, these frameworks influence how we structure our controls and improve them over time.
We maintain internal policies and standards covering information security, acceptable use, access management, endpoint security, incident response, vulnerability management, secure software development, encryption, backups, data handling, and third-party vendor management.
Access to systems and data is managed on a least privilege basis. Multi-factor authentication is enforced across key systems, and access changes are handled through formal onboarding, role change, and offboarding processes. Administrative access is subject to tighter controls than standard user access.
We protect data in transit using modern encryption standards. Company-managed devices are encrypted and centrally managed, and where appropriate we apply encryption at rest using managed cloud security controls.
Endpoint protections include anti-malware, threat detection, patching, device hardening, firewall controls, and compliance-based access requirements.
We maintain centralised monitoring across relevant parts of our environment to support detection, investigation, and incident response. Vulnerabilities are managed through patching, dependency review, and regular security testing, including independent penetration testing.
Security is also incorporated into our software development lifecycle through peer review, formal change control, internal standards, and release governance.
We maintain backup and disaster recovery arrangements aligned to operational and contractual requirements, and we apply layered protections to email and collaboration systems to reduce the risk of phishing, malware, and account compromise.
Where third-party providers are used, they are subject to review and appropriate contractual controls. Staff are required to follow security policies and complete security awareness training, including phishing-related awareness activities.
If a security incident affects stakeholder data, notifications are handled in line with applicable contractual and regulatory obligations.
Security is reviewed and improved over time as our systems, risks, and business requirements evolve.
Please contact info@ccitracc.com for any queries.