91果冻传媒

91果冻传媒 Security Summary

Introduction

91果冻传媒鈥檚 Corporate Information Security Program has implemented administrative, technical and physical safeguards that help to protect the confidentiality, integrity and availability of systems, networks, and information. To secure the internal systems and networks that support Enterprise Services (鈥91果冻传媒 Assets鈥), 91果冻传媒 operates in a manner consistent with its information security policies and maintains physical, technical, and administrative safeguards appropriate to protect 91果冻传媒 Assets.聽聽 While 91果冻传媒 information security policies are based on generally accepted industry practices, individual Enterprise Services may have different and/or additional security features. 91果冻传媒鈥檚 substantial investment in the people, processes and tools necessary to secure the products and services that our customers trust and depend on, demonstrates our commitment to security excellence every day. Our continuous improvement strategy strives to stay ahead of the curve by implementing forward thinking security controls and techniques to protect customer data and the 91果冻传媒 Network.

91果冻传媒 scope for securing Internal Systems includes the following:

Maintaining an information security policy.

  • 91果冻传媒 maintains a formal, documented information security policy, which is based on various recognized industry security standards and is aligned to the NIST Cybersecurity Framework and is applicable to all 91果冻传媒 employees and Authorized Users on 91果冻传媒 Assets
  • 91果冻传媒 maintains information security teams to promote and assist in the enforcement of 91果冻传媒鈥檚 information security policy and practices.
  • 91果冻传媒 has a formal Cyber Security Awareness Program to ensure 91果冻传媒 personnel are provided with cybersecurity awareness education and are adequately trained to perform their information security-related duties and responsibilities consistent with policy and the underlying control framework.
  • 91果冻传媒 develops and maintains systems designed to secure Customer Data through privacy and cybersecurity risk assessments, and where appropriate uses automation in the development lifecycle to enforce controls, among other practices.
  • 91果冻传媒 complies with applicable privacy laws and regulations to which 91果冻传媒 is subject.

Building and maintaining a secure network.

  • 91果冻传媒 uses a variety of industry-recognized security practices to protect our internal networks, including appropriately configured firewalls, network segmentation and networking monitoring.
  • 91果冻传媒 implements security continuous monitoring which includes logging and monitoring access to 91果冻传媒鈥檚 networks and assets. Hardware and software-based tools have been deployed throughout the 91果冻传媒 network to provide real-time alerting from devices such as firewalls, intrusion detection systems, routers and switches.
  • 91果冻传媒 changes vendor-supplied defaults for system passwords and other security parameters.
  • 91果冻传媒 regularly tests systems and processes utilized for network security to maximize operational capacity.
  • 91果冻传媒 develops and maintains systems designed to secure Customer Data through privacy and cybersecurity risk assessments, and where appropriate uses automation in the development lifecycle to enforce controls, among other practices.

Protecting sensitive information.

  • 91果冻传媒 maintains a 91果冻传媒 Code of Conduct for 91果冻传媒 employees (available to the public at ) which requires that they comply with information security policies and procedures.
  • 91果冻传媒 uses contractual and other measures to obtain third party suppliers鈥 compliance with appropriate information security requirements, such as 91果冻传媒鈥檚 baseline security requirements for suppliers, our Supplier Code of Conduct and other materials.
  • 91果冻传媒 develops and maintains systems designed to secure Customer Data through privacy and cybersecurity risk assessments, and where appropriate uses automation in the development lifecycle to enforce controls, among other practices.
  • 91果冻传媒 manages data protection in a systematic and structured manner to enforce confidentiality requirements throughout the data鈥檚 lifecycle of creation, transmission, storage, modification, retention and destruction. Based on risk, industry standard encryption is used to protect data-in-transit and data-at-rest.
  • 91果冻传媒 provides physical security controls for each computer room, data center, and similar facilities that may contain sensitive information.
  • 91果冻传媒 complies with applicable laws and regulations related to protecting sensitive information stored by 91果冻传媒.

Maintaining a vulnerability management program.

  • 91果冻传媒 uses anti-virus software on systems to address malware threats against its systems.
  • 91果冻传媒 has an established patch management process for production hardware and software installed on the 91果冻传媒 network.
  • 91果冻传媒 schedules, monitors, controls, and tracks significant changes affecting 91果冻传媒 Assets.
  • 91果冻传媒 performs internal and external vulnerability scans on a periodic basis.聽 System owners may schedule real-time vulnerability system scans as needed to adapt to changing threat vectors.

Implementing strong access control measures.

  • Logical access control policies are defined, documented and managed to ensure that only authorized personnel have access to critical business applications and systems based on position and job requirements.
  • Access to 91果冻传媒 Assets requires the use of multi-factor authentication. Where appropriate and based on risk, network integrity is further protected by incorporating network segregation between production systems.
  • 91果冻传媒 assigns a unique ID, consistent with 91果冻传媒鈥檚 information security policies, for employees, agents, and contractors to use when accessing 91果冻传媒 Assets.
  • 91果冻传媒 implements controls to restrict physical access to facilities housing 91果冻传媒 systems to authorized personnel. Depending on the type of facility, access may be permitted by electronic card access readers, keys, security guards, or local company personnel.
  • 91果冻传媒 utilizes the Principle of Least Privilege to manage access for each of its systems. Privileged access for production network, system or application functions are controlled and restricted to as few personnel as operationally feasible and is authorized on a 鈥渘eed to know鈥 or 鈥渆vent by event鈥 basis.

Disaster recovery

  • 91果冻传媒 maintains business continuity and disaster recovery protocols designed to enhance 91果冻传媒鈥檚 ability to respond to significant events that might disrupt 91果冻传媒鈥檚 networks and facilities or otherwise impair 91果冻传媒鈥檚 ability to provide service.
  • 91果冻传媒鈥檚 business continuity and disaster recovery practices identify potential recovery risks to 91果冻传媒 Assets, and implement measures designed to help minimize and mitigate those risks using industry-accepted practices.

Incident management

  • 91果冻传媒 maintains a written, actionable incident response plan to ensure timely reaction to Security Events, Security Incidents and Data Breaches by the 91果冻传媒 Threat Management Center.
  • 91果冻传媒 addresses the identification, management, and resolution of security issues requiring attention.
  • 91果冻传媒 communicates, consistent with contractual and legal obligations, the status of material issues affecting the Customer.

Last update, September, 2020