Company / Trust & security
Review the controls for the system you will run.
Security depends on the application, hosting arrangement, configuration, people, and operating process.
Access and accountability
Define roles, privileged access, identity requirements, and the process for joining, changing roles, and leaving. Test that users can complete their work with the intended access boundaries.
Hosting and recovery
Confirm the provider, region, backup coverage, retention, and restoration process. Set recovery objectives and incident responsibilities in the agreement, then review whether the selected plan and operating process meet them.
Data and regulatory requirements
Identify the data involved and the jurisdiction-specific obligations with your responsible advisers. Certifications or controls belonging to a product, hosting provider, or partner do not automatically establish compliance for your deployment.
Questions for the security review
- Who approves and reviews privileged access?
- Who tests restores and owns incident escalation?
- What data moves to third parties and under which terms?
