Controls
Updated 2026-09-23 4 of 15 in placeWhat we have in place, per subject. Green means the controls behind it are met and backed by current evidence or a passing automatic check; grey means not yet.
Infrastructure security
1 of 5 in place- Information is classified and labelled according to the classification scheme — in place
- All information and IT assets are in an up-to-date register with an owner — not yet in place
- Backups are made, protected and periodically restore-tested — not yet in place
- Logs are monitored; deviations lead to follow-up — not yet in place
- Relevant events are logged and protected against manipulation — not yet in place
Organisational security
3 of 5 in place- All employees follow awareness training periodically — in place
- Policy and underlying documents are established and current — in place
- Roles, tasks and responsibilities for security are assigned — in place
- Management establishes the information security policy and promotes it — not yet in place
- Suppliers are assessed risk-based before and during the relationship — not yet in place
Product security
0 of 3 in place- Access is granted on the basis of least privilege and need-to-know — not yet in place
- MFA is enforced for external access and management interfaces — not yet in place
- MFA is enforced for privileged accounts — not yet in place
Internal procedures
0 of 2 in place- Incident response has roles, procedures and escalation paths — not yet in place
- Incidents are reported, registered and classified — not yet in place