Skip to content
cezc Trust centre
Last updated 2026-09-20

Test

test

Controls

Updated 2026-09-23 4 of 15 in place

What we have in place, per subject. Green means the controls behind it are met and backed by current evidence or a passing automatic check; grey means not yet.

Infrastructure security

1 of 5 in place
  • Information is classified and labelled according to the classification scheme — in place
  • All information and IT assets are in an up-to-date register with an owner — not yet in place
  • Backups are made, protected and periodically restore-tested — not yet in place
  • Logs are monitored; deviations lead to follow-up — not yet in place
  • Relevant events are logged and protected against manipulation — not yet in place

Organisational security

3 of 5 in place
  • All employees follow awareness training periodically — in place
  • Policy and underlying documents are established and current — in place
  • Roles, tasks and responsibilities for security are assigned — in place
  • Management establishes the information security policy and promotes it — not yet in place
  • Suppliers are assessed risk-based before and during the relationship — not yet in place

Product security

0 of 3 in place
  • Access is granted on the basis of least privilege and need-to-know — not yet in place
  • MFA is enforced for external access and management interfaces — not yet in place
  • MFA is enforced for privileged accounts — not yet in place

Internal procedures

0 of 2 in place
  • Incident response has roles, procedures and escalation paths — not yet in place
  • Incidents are reported, registered and classified — not yet in place