# Parasail Trust Center

## Monitoring

Continuously monitored by Secureframe

### Change Management

- Configuration and Asset Management Policy
- Baseline Configurations
- Secure Development Policy

### Availability

- Backup Restoration Testing
- Uptime and Availability Monitoring
- Testing the Business Continuity and Disaster Recovery Plan

### Organizational Management

- New Hire Screening
- Personnel Acknowledge Security Policies
- Advisor Meetings on Security

### Confidentiality

- Data Classification Policy
- Data Retention and Disposal Policy

### Vulnerability Management

- Vulnerability and Patch Management Policy
- Third-Party Penetration Test

### Incident Response

- Lessons Learned
- Incident Response Plan Testing
- Tracking a Security Incident

### Risk Assessment

- Vendor Due Diligence Review
- Risk Assessment
- Risk Register

### Network Security

- Network Traffic Monitoring
- Automated Alerting for Security Events
- Network Security Policy

### Access Security

- Unique Access IDs
- Encryption-in-Transit
- Encryption and Key Management Policy

### Physical Security

- Physical Access Reviews
- Physical Access Restrictions
- Physical Security Policy

### Monitoring

### Change Management

**Configuration and Asset Management Policy**  
A Configuration and Asset Management Policy governs configurations for new sensitive systems.

**Baseline Configurations**  
Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.

**Secure Development Policy**  
A Secure Development Policy defines the requirements for secure software and system development and maintenance.

**Change Management Policy**  
A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes.

**Production Data Use is Restricted**  
Production data is not used in the development and testing environments, unless required for debugging customer issues.

**Segregation of Environments**  
Development, staging, and production environments are segregated.

### Availability

**Backup Restoration Testing**  
Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups.

**Uptime and Availability Monitoring**  
System tools monitor for uptime and availability based on predetermined criteria.

**Testing the Business Continuity and Disaster Recovery Plan**  
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. Management makes changes based on test results.

**Business Continuity and Disaster Recovery Policy**  
Governs required processes for restoring service or supporting infrastructure after a disaster or disruption.

### Organizational Management

**New Hire Screening**  
Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency. New hires sign confidentiality agreements upon hire.

**Personnel Acknowledge Security Policies**  
Internal personnel review and accept applicable information security policies at least annually.

**Advisor Meetings on Security**  
Senior management and/or board of directors meets at least annually to review business goals, initiatives, and risks. The security team meets to discuss security risks, roles & responsibilities, and audit results.

**Information Security Policy**  
Establishes the security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data.

**Disciplinary Action**  
Violations of security policies result in documented disciplinary action.

**Internal Control Monitoring**  
A continuous monitoring solution for internal controls used in achieving service commitments.

**Information Security Program Review**  
Management reviews the organization's security policies and procedures at least annually.

**Security Awareness Training**  
Internal personnel complete annual training on information security obligations and responsibilities.

**Acceptable Use Policy**  
Defines standards for appropriate and secure use of company hardware and systems.

**Code of Conduct**  
Outlines ethical expectations and behavior standards.

**Performance Reviews**  
Personnel are evaluated via a formal performance review at least annually.

**Cybersecurity Insurance**  
Procured to minimize the financial impact of cybersecurity loss events.

**Organizational Chart**  
Management maintains and publishes a formal organizational chart identifying positions of authority.

**Performance Review Policy**  
Provides context and transparency into personnel performance and career development processes.

**Internal Control Policy**  
Identifies how controls are maintained to safeguard assets and promote efficiency.

**Independent Advisor**  
Includes independent senior management and external advisors overseeing cybersecurity.

**Roles and Responsibilities**  
Outlines information security roles and responsibilities for personnel.

### Confidentiality

**Data Classification Policy**  
Details security and handling protocols for sensitive data.

**Data Retention and Disposal Policy**  
Specifies how customer data is retained and disposed based on compliance requirements.

### Vulnerability Management

**Vulnerability and Patch Management Policy**  
Outlines processes for responding to identified vulnerabilities.

**Third-Party Penetration Test**  
Annual penetration test by an external party; critical findings are tracked.

### Incident Response

**Lessons Learned**  
Management provides a "Lessons Learned" document post-security incidents.

**Incident Response Plan Testing**  
Periodic testing of the Incident Response Plan; management may modify the plan based on results.

**Tracking a Security Incident**  
Documenting and analyzing identified incidents according to the Incident Response Plan.

**Incident Response Plan**  
Outlines processes for identifying, prioritizing, and resolving security incidents.

### Risk Assessment

**Vendor Due Diligence Review**  
Vendor SOC 2 reports are collected and reviewed annually.

**Risk Assessment**  
Performed to identify relevant threats related to security, availability, confidentiality, and fraud.

**Risk Register**  
Records risk mitigation strategies for identified risks and development of controls.

**Vendor Risk Management Policy**  
Defines a framework for onboarding and managing vendor relationships.

**Risk Assessment and Treatment Policy**  
Governs conducting risk assessments considering threats and vulnerabilities.

**Vendor Risk Assessment**  
New vendors assessed prior to engagement; reassessment occurs annually.

### Network Security

**Network Traffic Monitoring**  
Security tools provide monitoring of network traffic to the production environment.

**Automated Alerting for Security Events**  
Notifies teams of potential security events.

**Network Security Policy**  
Identifies requirements for protecting information and systems across networks.

### Access Security

**Unique Access IDs**  
Personnel assigned unique IDs for accessing sensitive systems.

**Encryption-in-Transit**  
Service data transmitted over the internet is encrypted.

**Encryption and Key Management Policy**  
Supports the secure use of cryptographic controls.

**Administrative Access is Restricted**  
Restricted based on least privilege principles.

**Removal of Access**  
Access is removed upon termination or when no longer needed.

**User Access Reviews**  
Scheduled reviews of user access to validate it according to job responsibilities.

**Access Control and Termination Policy**  
Governs authentication and access to applicable systems.

**Access to Product is Restricted**  
Non-console access to production infrastructure is restricted.

### Physical Security

**Physical Access Reviews**  
Periodic reviews of physical access based on job responsibilities.

**Physical Access Restrictions**  
Processes for modifying physical access based on needs.

**Physical Security Policy**  
Details physical security requirements for company facilities.

**Visitor Control**  
All visitors to production facilities must formally sign in unless pre authorized.

### Communications

**Description of Services**  
Descriptions of the company's services are available to personnel and external users.

**Communication of Security Commitments**  
Security expectations are communicated via the company's website.

**Privacy Policy**  
Details the company's privacy commitments to users.

**Communication of Critical Information**  
Critical information is communicated to external parties as needed.

**Confidential Reporting Channel**  
Available for internal personnel and external parties to report security concerns.

**Terms of Service**  
Published or shared with external users.
