Trust Center - Ben

Ben Trust Center

Ben is the all-in-one global employee benefits platform that’s flexible, automated, and budget-friendly. We adhere to industry best practices for security across our entire organisation, with robust measures upheld at all levels, from the boardroom to daily operations.

security@thanksben.com

Controls

Updated 14 minutes ago

Infrastructure security

Control Status
Information transfer
Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.
Secure authentication
Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.
Use of privileged utility programs
The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
Web filtering
Access to external websites shall be managed to reduce exposure to malicious content.
Clock synchronization
The clocks of information processing systems used by the organization shall be synchronized to approved time sources.
Application security requirements
Information security requirements shall be identified, specified and approved when developing or acquiring applications.
Secure system architecture and engineering principles
Principles for engineering secure systems shall be established, documented, maintained and applied to any information system development activities.
Threat Intelligence
Information relating to information security threats shall be collected and analyzed to produce threat intelligence.
Segregation of networks
Groups of information services, users and information systems shall be segregated in the organization’s networks.
Information security for use of cloud services
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements.

Organizational security

Control Status
Determining the scope of the information security management system
The organization shall determine the boundaries and applicability of the information security management system to establish its scope. When determining this scope, the organization shall consider:
a) the external and internal issues referred to in 4.1;
b) the requirements referred to in 4.2;
c) interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations.
The scope shall be available as documented information.
Intellectual property rights
The organization shall implement appropriate procedures to protect intellectual property rights.
Storage media
Storage media shall be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organization’s classification scheme and handling requirements.
Screening
Background verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis taking into consideration applicable laws, regulations and ethics and be proportional to the business requirements, the classification of the information to be accessed and the perceived risks.
Terms and conditions of employment
The employment contractual agreements shall state the personnel’s and the organization’s responsibilities for information security.
Confidentiality or non-disclosure agreements
Confidentiality or non-disclosure agreements reflecting the organization’s needs for the protection of information shall be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.
Physical security perimeters
Security perimeters shall be defined and used to protect areas that contain information and other associated assets.
Physical entry
Secure areas shall be protected by appropriate entry controls and access points.
Securing offices, rooms and facilities
Physical security for offices, rooms and facilities shall be designed and implemented.
Physical security monitoring
Premises shall be continuously monitored for unauthorized physical access.

Product security

Control Status
Secure development life cycle
Rules for the secure development of software and systems shall be established and applied.
Secure coding
Secure coding principles shall be applied to software development.
Security testing in development and acceptance
Security testing processes shall be defined and implemented in the development life cycle.
Separation of development, test and production environments
Development, testing and production environments shall be separated and secured.
Test information
Test information shall be appropriately selected, protected and managed.

Internal security procedures

Control Status
ICT readiness for business continuity
ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.
Information backup
Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
Planning of Changes
When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.
Installation of software on operational systems
Procedures and measures shall be implemented to securely manage software installation on operational systems.
Internal Audit - General
The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system:
a) conforms to
1. the organization’s own requirements for its information security management system;

2. the requirements of this document;

b) is effectively implemented and maintained.
Internal Audit Program
The organization shall plan, establish, implement and maintain an audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.
When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits.
The organization shall:
a) define the audit criteria and scope for each audit;
b) select auditors and conduct audits that ensure objectivity and the impartiality of the audit process;
c) ensure that the results of the audits are reported to relevant management;
Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.
Legal, statutory, regulatory and contractual requirements
Legal, statutory, regulatory and contractual requirements relevant to information security and the organization’s approach to meet these requirements shall be identified, documented and kept up to date.
Independent review of information security
The organization’s approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur.
Protection of information systems during audit testing
Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.
Understanding the organization and its context
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system.

Data and privacy

Control Status
Acceptable use of information and other associated assets
Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented.
Classification of information
Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements.
Labelling of information
An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organization.
Information deletion
Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.
Data masking
Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration.
Privacy and protection of PII
The organization shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.
Protection of records
Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release.