---
title: "Security Policy"
canonical: "https://docs.eficode.io/space/SEC/1867784/Security%20Policy"
format: markdown
---
# Introduction

This security policy is the public version of the Eficode security policy. The aim of the documentation is to give an overview of security and compliance in regards to Eficode services and products. It omits significant parts e.g. details of the security organization and detailed descriptions of internal security on purpose. 

The security policy is the basis of Eficode’s information security management system. The policy has been endorsed by the management to be used in relevant Eficode offices and lines of business. Complying to the security policy is the responsibility of all Eficode employees (both internal and external), contractors, associates, business partners and all other parties with access to Eficode premises, networks, computers and/or other systems and/or other sensitive information owned or administered by Eficode.

The security policy has been produced in line with the requirements and guidance contained in ISO 27001:2022.  

# Table of contents

> Macro (toc)

# Scope

The security policy applies to all Eficode employees (both internal and external), contractors, associates, business partners and all other parties with access to Eficode networks, computers and/or other systems. The policy applies also to all users of information and/or property owned or administered by Eficode.

# Top Management Commitment and Continuous Improvement

Eficode’s top management is fully committed to the establishment, implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS). This commitment is demonstrated through active leadership, resource allocation, and the integration of security into strategic planning and business operations.

Eficode continuously improves its ISMS by regularly evaluating security objectives, reviewing risks, incorporating feedback from audits and incidents, and adapting to changes in the regulatory, technological, and business environment to ensure ongoing effectiveness and relevance.

# Information security objectives

The objectives for the policy are to: 

- Establish rules and framework to ensure the protection of vital Eficode resources and assets (including but not limited to computers, mobile devices, cloud services, software and data)
- Assign responsibility and provide guidelines to to mitigate the risks associated with the theft, loss, misuse, damage or abuse of information systems
- Ensure security is part of everyday work and that all users understand their own responsibilities for protecting the confidentiality and integrity of the data that they handle
- Ensure secure, reliable services are delivered for customers who purchase Eficode services
- Ensure organizational ability to recover from security related negative events
- Be compliant with legal and regulatory requirements relevant to the organization in the field of information security, as well as with contractual obligations

All the objectives are reviewed at least once a year. Security is audited by independent auditors from time to time subject to customer requirements.

Eficode measures the fulfilment of all the objectives. The measurements will be performed regularly and reported to top management as input materials for the Management review.

# Security organization and responsibilities

|  |  |
| --- | --- |
| Managing Director | Overall responsibility of the security organization |
| Top Management | Responsible for reviewing and endorsing the security policy and ensuring security matters will be considered as a high priority in making any business decisions.<br>Responsible for reviewing and agreeing with Eficode's Information Security Objectives.<br>Committed to allocate sufficient human, technical and financial resources to information security management, and to take appropriate action in response to all violations of the security policy. |
| Security team | In charge of establishing and maintaining the Information Security Management System (ISMS) as described in the security policy document and its appendices.<br>Arranges risk assessments, risk treatments and internal audits at least annually.<br>Responsible for informing the top management of possible problems and/or threats to company security as well as continuously improving overall security at Eficode including updating the policy and the practices detailed within it. The security team is assisted by security experts when necessary. |
| Head of Security | Responsible for the operation of the Security team.<br>Responsible for organizing continuous security training and ensuring that the staff and partners can understand and commit to the company's security policies. |
| Data Protection Officer | Inform, advise and train staff on their obligations to General Data Protection Regulation and/or Member State data protection provisions.<br>Monitor compliance with General Data Protection Regulation and/or EU Member State data protection provisions.<br>Provide advice where requested as regards to data protection.<br>Co-operation with the supervisory authority and acting as contact point for the supervisory authority. |
| Head of IT | In charge of Information Security in relation to ICT infrastructure and company-wide IT information systems.<br>IT Manager will report to the Security Manager in security related matters. |
| Heads of Departments | Responsible for the department specific information systems (e.g. HR/Sales/Finance).<br>Responsible for supporting reviews, internal audits and risk assessments within their area of responsibility.<br>Responsible for the security of information produced, provided or held within their area of responsibility. |
| Line managers / team leads | Responsible for ensuring commitment to the security policy and that security practices are being utilized on a daily basis by the individual employees.<br>Responsible for ensuring their team members are aware of and remain compliant with all information security policies, processes and work instructions, and that they receive appropriate training.<br>Responsible for additional (intensive) security training based on the needs of the team is provided, assisted by the security team. |
| Human Resources | Responsible for organizing basic security training for new employees.<br>Responsible for maintaining control of proper employment lifecycle management practises which include security considerations. |
| Employees, contractors and third-party users | All employees will adhere to the security policy and associated procedures. Their responsibility is to raise any issues of noncompliance, information risk or incidents with either their line manager or directly with the Security team.<br>Each employee and contracted worker must participate in mandatory basic security training at least yearly. |

The management and employees have to be committed to the security policy for it to be effective.

# Security management, monitoring and review 

Security undergoes continuous improvements and is monitored regularly. Possibilities offered by new technology are utilized in improving security. Employees with security responsibilities are tasked to improve their knowledge level and they are offered training as required.  

The security policy is to be updated regularly and at least yearly. Version history of the security instructions has to be maintained and any significant updates need to be communicated to the organization and partners.

# Supporting Policies, Procedures, Processes and Guidelines 

Supporting policies, procedures, processes and guidelines have been developed to strengthen and reinforce the security policy statement. 

## Information risk management

Security and information risk management plays an essential role in Eficode’s Information Security Management System. The risk management is a structured procedure based on ISO 31000 guidelines and the process has the following steps:

1. Risk identification: identifying threats and vulnerabilities related to assets
2. Risk assessment: evaluating  the likelihood and effect of risks
3. Risk treatment or mitigation according to the defined risk acceptance criteria:
  1. Avoid
  2. Modify/mitigate
  3. Transfer
  4. Accept/retain
4. Follow-up: evaluating the effectiveness of used mitigations and controls

The risk assessment process is coordinated by the Security team, identification of threats and vulnerabilities and the assessment of consequences and likelihood is performed by risk owners.  Risk assessment covering all ISMS is conducted at least once a year or when significant changes have been made.

## Human resources security

Human resources are responsible for maintaining control of proper employment lifecycle management practises which include security considerations. These include but are not limited to screening new Eficode employees in relation to their work role, ensuring employees and contracted workers are committed and aware of their security related responsibilities  and invoking disciplinary procedures in case policy violation is committed.

## Asset management

Eficode maintains an Inventory of Assets, including relevant information assets and supporting assets such as software, devices and personnel. The Inventory of assets details the asset owners who are responsible for the asset’s life cycle. The inventory of assets is reviewed and updated at least annually.

Acceptable use of assets have been defined and the rules detail how information assets and their supporting assets should be used in an acceptable manner and in accordance with ISMS related policies and processes. 

## Information Classification Policy 

Information assets shall be classified and handled in accordance with the Information Classification Policy, which details how information assets of different sensitivities shall be classified, managed, handled, processed, stored and disposed when no longer required.

### Information ownership

All sensitive information and material (confidential or secure) have an owner. The owner is responsible for assigning and governing access to the information. The following table describes the default owner of the information and/or material.


|  |  |
| --- | --- |
| **Type of information** | **Default owner** |
| Project related information (including but not limited to project specific NDA's, access rights to project related material, documentation, source code, configurations, specifications, plans and access information such as passwords) | Project manager of said project |
| Customer related information (including but not limited to contracts, offers and other agreements) | Customer representative for said customer |
| Security related information (including but not limited to access management, premises security, general NDA's, personnel background check information and visitor security, excluding IT security) | Head of Security |
| Information security related information (including but not limited to server security and configurations, firewalls, virus and other digital threat protection, IT related access management and documents related to recovery from such incidents) | Head of IT |
| Information containing personal information on employees | Business unit director |
| Contracts and other general agreements | Business unit director or operations manager |
| Other information | Business unit director or operations manager |

### Information classification scheme

All documents, whether written text or other types, are classified based on the required confidentiality level of the said documents. This classification is printed or otherwise clearly marked on the documents. The classification scheme is detailed in the table below. In case the company material has no classification it is presumed to be "internal" or in case it is customer related  information, it is presumed to be “confidential”. This classification scheme also applies to documents received from outside of the organization.  


|  |  |  |  |
| --- | --- | --- | --- |
| **Classification** | **Labeling ** | **Classification criteria** | **Access restriction** |
| Public | (unlabeled) | Making the information public cannot harm the organization in any way | Information is freely available |
| Internal | INTERNAL | Unauthorized access to information may cause minor damage and/or inconvenience to the organization | Information is for Eficode internal use or for external partners if a non disclosure agreement is in effect with them |
| Confidential | CONFIDENTIAL | Unauthorized access to information may considerably damage the business and/or the organization's reputation | The information has confidentiality constraints. |
| Secure | SECURE | Unauthorized access to information may cause catastrophic (irreparable) damage to business and/or to the organization's reputation | The owner of the information will decide on distribution case per case |


The information owners are responsible of labelling the information according to the classification schema. 

### Personal information

Working with Personal Information (information related to actual persons) has special requirements as set by legislation on both national level and internationally (e.g. EU GDPR). Working with personal information is controlled and all personnel working with Personal Information are trained to use Personal Information properly. All Personal Information is considered confidential.

### Handling classified information 

All persons accessing classified information must follow the rules listed in the following table. 

|  |  |  |  |
| --- | --- | --- | --- |
| **Classification** | **Storing information** | **Distributing information** | **Disposing information** |
| PUBLIC | Information can be stored freely | Information can be distributed freely | There are no restrictions on disposal |
| INTERNAL | Information is stored in Eficode premises and/or services managed by Eficode. Information should be stored with care and for example have backups available | Information can be shared freely within the company. Information can be shared to external partners if a non disclosure agreement is in effect with them. | Information should be disposed of properly, that is: rendered unusable |
| CONFIDENTIAL | Information is stored in Eficode premises and/or services managed by Eficode. Access to information should be limited or the information otherwise protected. Information should be stored with care and for example have backups available. Also backup usage needs to be controlled. | Information can be shared to those Eficode employees that need it in their work. In special cases a valid non disclosure agreement must be in effect. Information can be shared to external partners if they require it with their collaboration with Eficode and a non disclosure agreement is in effect with them<br>Preferably sensitive information is not distributed by regular mail unless it has been encrypted properly. | Information should be disposed of properly, that is: rendered unusable |
| SECURE | Information is stored in Eficode premises and/or services managed by Eficode. Access to information should be limited or the information otherwise protected. Information should be stored with care and for example have backups available. Also backup usage needs to be controlled | Distribution list must be available and all parties using the information known. Access to the information has to be restricted and logged. Secure delivery and/or obfuscated methods of distribution should be used. | Information should be disposed of properly, that is: rendered unusable |

## Data Policy

Data Policy ensures the protection of data assets by safeguarding confidentiality, integrity, and availability across all data types, assigning responsibilities to asset owners, custodians, employees, contractors, and customers. It mandates data classification, secure storage, legal compliance, and safe transfer methods, along with regular backups, retention, and secure disposal. Access is restricted, audits ensure compliance, and incident management processes address breaches, with annual reviews to maintain relevance and potential disciplinary actions for non-compliance.

## Access Control Policy 

Eficode has adopted the “need-to-know” and “need-to-use” principles and by default employees have access only to systems and documents that they need in their work or they update regularly.

### User access management

#### User accounts

All systems require an user account for accessing and/or editing data. User accounts and basic privileges are created once an employee starts working at Eficode or a partnership is formed and are revoked immediately after the working contract or partnership agreement ends. 

Each user is identified by a unique user ID so that individuals can be held accountable for their actions. The identification methods have been implemented to use secured connections and methods and the authentication information is not stored in human readable form. The use of shared identities is permitted only where they are suitable, such as training accounts.

Passwords have minimum security constraints such as complexity, length and regular password rotation. 

#### Privilege accounts

The allocation of privilege rights are restricted and controlled and not provided by default. 

Individuals who hold privileged administration accounts also have a non-privileged account for routine business use. Privileged accounts are not used for standard activities; they are for program installation and system reconfiguration, not for program use, unless it is otherwise impossible to operate the program.

Administrative privileges are only allocated on a strict business need basis and they should never be used ‘for convenience’.

#### Shared accounts

The use of a shared account is strongly discouraged, but in case it is needed, it is published by automation and the encryption is opened with a personal ID. This ensures the person who was last in question and if someone is behaving strangely.

### User access provisioning

Customer and project related rights are administered on a customer or project level. In these cases a named customer responsible person and/or project manager or similar person is in charge of updating and managing different user rights for that particular case. Roles are reviewed so that access rights do not create such work combinations that could risk the security of information.

Records, access logs and depending on the system, possible audit/change logs are always tracked on individual level and group access or sharing of individual login information to others is strictly forbidden. 

All user rights can be limited on system level as well as internally within systems to cover only for example data related to one customer or similar linked information. Rights can further be limited on read only bases as opposed to also having editing rights.

### Network access

Network accesses are given in accordance with business access control procedures and the least-privilege principle. All users who have remote access to company networks shall be authenticated using the VPN authentication mechanism.

### Physical access

Eficode restricts access to and usage of their premises and resources. Access and usage rights are maintained on a group level, however access is tracked and logged on individual basis.  All guests are to be escorted within the premises and their access to secure areas is forbidden.

Access to the premises is controlled by the use of a key card based access control system. Keys, key cards and access rights are maintained centrally and issuing them is controlled and restricted.

### Regular review of access rights

Access rights are reviewed at regular intervals to ensure the access rights granted are in line with business and security requirements.

The access rights for all the persons who have changed their employment status or contractual relationship are removed or changed by responsible persons as soon as possible.

### Third Party Audit and Testing Compliance Requirements

Vendors must sign NDAs, adhere to strict data protection policies, and limit system access, with all activities logged and monitored to ensure compliance with industry standards and company security policies. They are accountable for breaches, follow protocols for data retention and destruction, and commit to ethical conduct. A detailed Statement of Work (SoW) outlines clear expectations for tasks, deliverables, and responsibilities, with the company retaining the right to audit compliance.

## Cryptographic controls

Various methods of encryption are available and generally built-into the application. The user should be aware of the data connection being used to transmit sensitive data and if encryption is enabled for that connection. 

### Use of cryptographic controls 

Encryption is required for:

- Sensitive data should be transferred through a secure channel. A secure channel is an encrypted network connection.
- The transport of sensitive files (TLS or SCP usage to encrypt sensitive data for network file access of unencrypted files).
- Access to sensitive data via a web site, web application or mobile app. Encryption is required for accessing sensitive data from anything with a web interface, including mobile devices (i.e. use of HTTPS to encrypt sensitive data).
- All network traffic for remote access to the virtual desktop environment
- Transport of sensitive data that is part of a database query or web service call (examples SQL query to retrieve or send data from database or a web service call to retrieve or send data from a cloud application).
- Privileged access to network or server equipment for system management purposes; i.e. SSH

Encryption of Email

- Sensitive data should not be sent cleartext in emails, but to use services such as Secure email.

Use and management of SSL digital certificates

- Web servers (or devices with a web interface) that support secure (HTTPS) connections must have a valid SSL certificate installed.
- Certificates are managed either via automatic renewal or purchased from Certificate Authorities. Renewal notifications arrive from CAs to emails and are monitored from servers.

### Cryptographic key management  
  


All encryption keys must be protected to prevent their unauthorized disclosure and subsequent fraudulent use.

The loss, theft, or potential unauthorized disclosure of any encryption key must be reported immediately to the Security team, which must then apply proper actions that will be required regarding revocation of certificates or public-private key pairs. 

#### Secret Key Encryption Keys

Keys used for secret key encryption, also called symmetric cryptography, must be protected as they are distributed to all parties that will use them. During distribution, the symmetric encryption keys must be encrypted using an RSA key of at least 2048 bits. This is implemented using standard openssl libraries when using both SSH and HTTPS, which ensures proper key-exchange and storage.

#### Public Key Encryption Keys

Public key cryptography, or asymmetric cryptography, uses public-private key pairs. The public key is passed to the certificate authority to be included in the digital certificate issued to the end user. The digital certificate is available to everyone once it is issued. The private key should only be available to the end user to whom the corresponding digital certificate is issued.

## Premises security

Eficode premises have the needed secure arrangements to control access into areas where sensitive documents, material and equipment are stored or processed.  Third party contracted premises such as data centre providers, will have equivalent or additional controls in place as detailed in the relevant contractual obligations. 

### Physical security requirements

At least the following measures are implemented at Eficode sites as appropriate:

#### Intrusion detection system with alarm transmission

The premises are protected by an electronic alarm system that is integrated to the access control system. The alarms are directed to a security guards company that will send a security guard to the premises as necessary.

#### Guarding

The premises have permanent security guards (lobby service) during office hours. Outside of office hours the premises are electronically protected and there are additional patrols during night time. 

#### Physical segregation and visibility limitation 

Visibility limitations are arranged from outside to project work areas, in projects where sensitive material is being handled.

#### Delivery and loading areas 

Access from delivery and loading areas are controlled and segregated from information processing facilities.

### Emergency response plan

Office premises have a documented and implemented emergency procedure including an evacuation and rescue plan as well as one or several nominated persons in charge of emergency issues.

####  Fire safety

Offices have ensured that fire safety arrangements (including fire doors, fire extinguishers, fire indication/extinction systems et cetera) comply with any national legislation.

### Physical entry controls

The premises are protected by an access control system. Outside of office hours the access is further restricted by two factor access requirements.

Physical access control system (or equivalent) is used and an individual audit trail can be tracked in the system. No collective or shared key cards are used. The system covers at least the areas where work is conducted or information is stored or processed. Areas are protected against tailgating.

### Clean desk and screen practise

Clean desk and screen practises are followed to reduce the risk of unauthorized access.

## Equipment security

Devices and equipment used for work purposes are sufficiently protected, maintained and securely disposed or re-used. Guidelines for acceptable use of equipment have been created.

Eficode requires its service providers, such as data centres, protect their environment and equipment against physical and environmental threats and  from disruptions caused by failure of supporting utilities. 

## Operational IT security

Operational IT procedures ensure correct and secure functioning of information and communication technology and services. Changes to IT systems are done in a controlled way and backups are taken regularly. Use of resources is monitored and needed actions are done to ensure proper system performance. Logs are generated based on general and individual system needs and are protected from unauthorized access and tampering.

### Change management

All changes done to the system environment(s) are tracked and monitored. Environment logs will store all access and modifications of service personnel.

Different change management processes are applied to ensure secure service delivery:

- Service requests are handled by using a ticketing system, calendar, version control and binary management

- Monthly Maintenance Break (MMB) process ensures latest security patches are installed to the system during regular pre-scheduled service breaks. This includes updates to infrastructure server OS kernels whenever applicable.

- Version level upgrades are usually done quarterly
- Regular steering meetings are kept with all customers and partners involved in service usage and development both on tactical and strategic level


### Capacity management

At least the use of CPU load, memory usage, process count and platform (tool) availability is monitored. Monitoring related notifications in general are limited to consist of information relevant for taking immediate action. The users need to log in to the monitoring system for additional information.

Maintenance and support personnel must access the monitoring system with personal user accounts and only from the Eficode internal network.

### Separation of development, testing and operational environments

Changes are deployed first to a test environment before they are installed to production.  

All customer specific environments (e.g. HW, OS) , tools, and supporting infrastructure need to be isolated from one another. All tools and supporting infrastructure are specific to a single platform instance:  platforms do not use shared backups, frontend servers or network configurations

### Controls against malware

The systems need to have at least the following protection:

- DDoS protection
- intrusion detection systems
- virus protection
- server hardening

#### Virus protection

Virus protection of customer systems are tailored according to customer requirements. 

#### Controls applied to employee devices

Security software such as anti-virus scanners are installed in all Eficode devices. Hard drives are encrypted. Using personal equipment is not allowed.

### Information backups

System wide backups are taken daily and are typically stored for 30 days. Backup monitoring is in place: alerts if backup did not work. 

Backups are regularly tested on creation and when refreshing of the staging environments.

### Logging

Centralized logging platform is used for tracking all changes on system and user level.

#### Authentication logging

Login and privilege escalation attempts are logged and monitored. The centralized system is capable of detecting both successful and unsuccessful attempts. It is possible to distinguish the IP from which the login request originated and what SSH key was used based on fingerprint.

#### Protection of logs

The logs are copied to different locations in order to protect them from tampering. Access to the logs are restricted.

#### Administrator and operator logs

System administrator and system operator activities generate audit logs and are reviewed when misuse is suspected.

### Clock synchronisation

Centralized NTP is used in servers and systems.

### Management of technical vulnerabilities

An automated process of gathering and distributing information on relevant security patches,  notices and releases related to all software products and solutions is in place.

Stable patches are applied during the regular maintenance breaks. Off-cycle updates are done when necessary.

### Standardized Operating Procedures

Security of cloud environments, office networks, vendor access, and databases, with strong configuration management practices is addressed. For cloud environments, the policy emphasizes security baselines, least privilege IAM, traffic encryption, and continuous monitoring, while vendor access is controlled with reviews, multi-factor authentication, and risk assessments. Office networks and databases follow strict access controls, segmentation, patching, auditing, and encryption, with configuration management aligned with company's change management process to ensure effective tracking of system changes.

### Acquiring and Use of Cloud-based Software and Products

Acquiring, managing, and exiting cloud-based services like SaaS and SaaP is controlled, ensuring compliance with legal and security requirements while protecting the company’s data. It applies to all departments involved in cloud service usage and assigns responsibilities across business units, legal, IT, and information security teams. Detailed documentation is required at each stage, including assessments, contracts, and audits, aligning with existing supplier security protocols.

## Network security

Networks are managed and controlled to maintain the security of the applications and data in transit. All Eficode networks are equipped with appropriate security systems and mechanisms. 

The purpose of network security is:

- The prevent unauthorized access to systems
- Identify unauthorized access and attempts to breach security
- To prevent data being transferred to outsiders
- To prevent use of data that has been compromised or transferred to outsiders
- To prevent feeding of misinformation to the systems
- To prevent changes to or destruction of data due to security problems
- To prevent data from being forwarded to wrong recipients

The basic level of security protects the data from incidental security breaches. When transferring confidential or secure data, additional security measures are taken into use.

Critical components of the telecommunication network are backed up using secondary hardware and cabling. Cabling and junctions of networks are secured by additional electronic and/or physical protection where appropriate.

### External connections and implementations

Secure tunnel connections are used for external connections. Employees connect to the office network remotely by using VPN tunneling. Different premises are also connected using similar secure connections. All interfaces to public networks are protected by firewalls. Physical firewalls (as opposed to software only) are required in secure networks. Servers visible to public networks are isolated in a dedicated network cell. External connections are monitored.

### Network separation

The company offers service options for normal security purposes (accessible from the internet) and high security purposes (not accessible from the internet). These services are separated on the network level.

### Usage monitoring

Usage of systems is monitored by maintaining necessary log files and supervising the network. Random spot checks are also used.

### Information transfer security

The sender of the data is ensured by identifying the sender. This identification can be accomplished for example using digital signatures. Access control can be enabled by physical protection measurements or using passwords. The use of any data transfer service or tool must not be possible without identifying the user.

Different levels of security can be accomplished by using groups of users based on user identification and limiting access to certain time slots. Failed login attempts and misusing or abusing access rights are recorded and monitored.

The integrity of data transfers can be ensured by using checksums combined with encryption (digital signing and sealing). Error prone cabling and transfer protocols ability to with correct errors has to be taken into account when evaluating the integrity of the transfer.

Indisputability is used to ensure that the participants of the data transfer can later not deny the sending or receiving of the said data. This can be ensured using encryption in conjunction with message acknowledgement systems.

## Security in systems development

Rules and guidelines for secure and high-quality development have been established and documented. The information security related requirements are identified and included in the requirements for project development. When identifying the requirements, at least the following are considered:

- value and sensitivity of the information involved
- legal, regulatory and contractual obligations
- where the information is accessed and processed
- business impact if the information is not available

Development is done using secure and segregated development environments and agile methods with code reviews are practised.  Minimum security standards for development have been defined and followed.

Security controls are tested as part of different forms of testing. These include e.g. unit, system, integration, performance and acceptance tests.

Confidential data, as well as data that can be related to individual persons are not used as test data. Test data should be generated when possible.

### Secure Coding

Secure coding practices in compliance with information security standards are implemented, aiming to integrate security into all stages of software development to minimize vulnerabilities. The policy emphasizes controlled access and secure configurations in development environments, ensuring the separation of development, testing, and production systems.

### Requirements for Developing and Acquiring Applications

Security requirements for cloud-based applications, requiring multi-factor authentication (MFA), role-based access control (RBAC), and encryption of sensitive data in transit and at rest are documented. Applications must follow secure coding practices, implement logging for security events, and have incident detection and response mechanisms, along with regular security updates and transparent vulnerability management. Backup and recovery processes must be encrypted and tested, with secure deployment, user session management, and privacy controls embedded to ensure robust security throughout the application's lifecycle.

## Supplier security management

Eficode expects suppliers and other partners who have access to Eficode premises and/or systems to have comparable (same level of) security policies in effect as Eficode.

When using external services Eficode considers the credibility and security policies of the service providers and weighs that against the security classification and criticality of the data being handled using the external services. Eficode uses only service providers with well known credibility and reliability. 

### Screening

A background verification checks for individual suppliers and partners are performed. Methods include but are not limited to experience of their other clients, credit history, security policies, certifications by an independent specialized body, public references and work history.

### Contracts 

Security clauses will be included in the contract with supplier or partner and clauses which stipulate confidentiality and return of assets after the termination of the agreement are mandatory. Further, the contracts must ensure reliable delivery of the products and services, which is particularly important with cloud service providers.   


Confidentiality agreements must be made with all contractors working in Eficode projects. Access rights are limited to the actual project(s) the contractor(s) are working with. All similar background checks must be done to contractors as with Eficode employees working in the same project and as required by the customer. The needed security awareness and training is provided to suppliers and partners.

### Monitoring and review

The level of service and fulfillment of security clauses are regularly checked and monitored and  the supplier or partner is audited if needed. 

### Changes or termination of supplier services

When the contract is changed or terminated, the access rights for employees of partners/suppliers are removed according to the Access Control Policy. 

Further, when the contract is changed or terminated, all the project related equipment, software or information in electronic or paper form is returned. 

## Information Security Incident Management

Incident management procedure is created to provide a mechanism for the prompt identification, reporting, investigation and closure of information security incidents. 

All incidents are reviewed regularly to ensure recurring ones are detected, or those which may turn into major incidents on the next occasion. After analyzing the incidents, an improvement or corrective action is taken into use.  Incident related evidence is collected and preserved in case it is needed in legal and other proceedings.

## Business Continuity Management 

Situations that can have a serious effect on the continuity of the functions of the company as a whole or large portions of it have been identified. Recovery plans for these situations have been created and maintained. 

The areas covered by the business continuity plan include:

- Identifying critical items
  - Identifying critical functions, assets and external resources
  - Identifying critical personnel
  - Identifying critical external contacts and service providers
  - Identifying critical equipment, software, hardware and ICT services
  - Identifying critical networks and communication channels
  - Identifying critical documents and information (stores)

- Threat, risk and impact analysis for each critical item
- Backup measures for critical items
- Backup personnel, assets, resources, contacts, service providers, software and hardware, ITC services, networks, communication and document stores.
- Emergency communication plan (internal, customers, external)
- Ready and rehearsed solutions to identified potential interruptions to critical items usability (general availability and more targeted issues)
- Detailed response plans to handle identified potential interruptions
- General response plans to restore functions to normal under exceptional conditions in case of unexpected interruptions

Plans are reviewed and updated at least yearly and during rehearsals. We follow the ISO 27001 standard to have the necessary controls in place to ensure that all possible aspects are covered.

## Cloud Security Policy

Eficode's client-facing infrastructure is wholly provided through hosting partners and Cloud Platforms. These partners are required to maintain security standards in line with Eficode's general security posture, up to and including maintaining an ISO 27001 certification. Eficode offers no data-center services, nor manages any physical infrastructure outside of internal networks and systems. All the controls in this, and any other security policies, relate specifically to our use of hosted and cloud systems. Cloud systems use cloud specific security tooling and posture management where applicable and appropriate. As such, Eficode maintains no specific Cloud Security Policy.