MaikyMaiky
Maiky

Maiky

30

Frameworks

1

Public Documents

Security Controls

We maintain a comprehensive set of security controls across all areas of our platform and operations.

Configuration Management

Review of user access rights
100% coverage
Removal or adjustment of access rights
100% coverage
Information Access Restriction
100% coverage
Information security requirements analysis and specification
100% coverage

Security Operations

Documented Operating Procedures
100% coverage

Human Resources Security

Confidentiality or non-disclosure agreements
100% coverage
Acceptable use of assets
100% coverage
Information transfer policies and procedures
100% coverage
Agreements on information transfer
100% coverage
Information security roles and responsibilities
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage

Project & Resource Management

Information security requirements analysis and specification
100% coverage
Information security in project management
100% coverage
System change control procedures
100% coverage

Data Classification & Handling

Information transfer policies and procedures
100% coverage
Handling of assets
100% coverage
Management of removable media
100% coverage
Protection of records
100% coverage
Classification of Information
100% coverage
Labelling of information
100% coverage
Physical media transfer
100% coverage
Disposal of media
100% coverage

Information Assurance

System security testing
100% coverage

Incident Response

Responsibilities and procedures
100% coverage
Reporting information security events
100% coverage
Reporting information security weaknesses
100% coverage
Response to information security incidents
100% coverage
Learning from information security incidents
100% coverage
Collection of evidence
100% coverage
Assessment of and decision on information security events
100% coverage

Privacy

Privacy and protection of personally identifiable information
100% coverage
Technical compliance review
100% coverage

Security Awareness & Training

Information Security Awareness & Training
100% coverage

Change Management

System change control procedures
100% coverage
Change management
100% coverage
Technical review of applications after operating platform changes
100% coverage

Compliance

Information systems audit controls
100% coverage
Identification of applicable legislation and contractual requirements
100% coverage
Independent review of information security
100% coverage
Compliance with security policies and standards
100% coverage

Security & Privacy Governance

Review of the policies for information security
100% coverage
Contact with authorities
100% coverage
Contact with special interest groups
100% coverage

Physical & Environmental Security

Delivery and loading areas
100% coverage
Physical security perimeter
100% coverage
Physical entry controls
100% coverage
Securing offices, rooms and facilities
100% coverage
Protecting against external and environmental threats
100% coverage
Working in secure areas
100% coverage
Clear desk and clear screen policy
100% coverage
Equipment siting and protection
100% coverage
Supporting utilities
100% coverage
Cabling security
100% coverage

Risk Management

Privacy and protection of personally identifiable information
100% coverage

Maintenance

Equipment maintenance
100% coverage

Vulnerability & Patch Management

Management of technical vulnerabilities
100% coverage

Cryptographic Protections

Information Access Restriction
100% coverage
Information security roles and responsibilities
100% coverage
Screening
100% coverage
Management Responsibilities
100% coverage
Inventory of assets
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Secure development policy
100% coverage
Secure system engineering principles
100% coverage
Protection of test data
100% coverage
Information security in project management
100% coverage
Physical media transfer
100% coverage
Controls against mal- ware
100% coverage
Installation of software on operational systems
100% coverage
Identification of applicable legislation and contractual requirements
100% coverage
Secure logon procedures
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Policy on the use of cryptographic controls
100% coverage
Key management
100% coverage
Review of the policies for information security
100% coverage
Management of privileged access rights
100% coverage
Management of technical vulnerabilities
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage

Data Privacy

Information Access Restriction
100% coverage
Acceptable use of assets
100% coverage
Information security roles and responsibilities
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Ownership of assets
100% coverage
Access control to source code
100% coverage
Protection of test data
100% coverage
Information security in project management
100% coverage
Protection of records
100% coverage
Privacy and protection of personally identifiable information
100% coverage
Information Security Awareness & Training
100% coverage
Identification of applicable legislation and contractual requirements
100% coverage
Compliance with security policies and standards
100% coverage
Secure logon procedures
100% coverage
Review of the policies for information security
100% coverage
Contact with authorities
100% coverage
Contact with special interest groups
100% coverage
Physical security perimeter
100% coverage
Physical entry controls
100% coverage
Securing offices, rooms and facilities
100% coverage
Protecting against external and environmental threats
100% coverage
Management of privileged access rights
100% coverage
Password Management System
100% coverage
Use of privileged utility programs
100% coverage
Management of technical vulnerabilities
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Network Security

Information Access Restriction
100% coverage
Security of network services
100% coverage
Acceptable use of assets
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Security of equipment and assets off-premises
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Protection of test data
100% coverage
Information security in project management
100% coverage
Physical media transfer
100% coverage
Network controls
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Segregation in networks
100% coverage
Contact with authorities
100% coverage
Physical entry controls
100% coverage
Working in secure areas
100% coverage
Password Management System
100% coverage
Use of privileged utility programs
100% coverage
Management of technical vulnerabilities
100% coverage
Understanding the context of the organization
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Technology Development & Acquisition

Information Access Restriction
100% coverage
Outsourced development
100% coverage
Acceptable use of assets
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Secure disposal or re- use of equipment
100% coverage
Security of equipment and assets off-premises
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Separation of development, testing and operational environments
100% coverage
Secure development policy
100% coverage
Secure system engineering principles
100% coverage
Secure development environment
100% coverage
System acceptance testing
100% coverage
Protection of test data
100% coverage
Disposal of media
100% coverage
Controls against mal- ware
100% coverage
Installation of software on operational systems
100% coverage
Information Security Awareness & Training
100% coverage
Change management
100% coverage
Secure logon procedures
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Review of the policies for information security
100% coverage
Working in secure areas
100% coverage
Clear desk and clear screen policy
100% coverage
Equipment siting and protection
100% coverage
Supporting utilities
100% coverage
Cabling security
100% coverage
Equipment maintenance
100% coverage
Management of privileged access rights
100% coverage
Password Management System
100% coverage
Use of privileged utility programs
100% coverage
Management of technical vulnerabilities
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Storage Media
100% coverage

Capacity & Performance Planning

Screening
100% coverage
Capacity management
100% coverage
Management of technical vulnerabilities
100% coverage

Secure Engineering & Architecture

Information Access Restriction
100% coverage
Acceptable use of assets
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Return of assets
100% coverage
Access control to source code
100% coverage
Secure development policy
100% coverage
Secure system engineering principles
100% coverage
Protection of test data
100% coverage
Information security in project management
100% coverage
Secure logon procedures
100% coverage
Clock synchronisation
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Contact with special interest groups
100% coverage
Understanding the context of the organization
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Identification & Authentication

Review of user access rights
100% coverage
Removal or adjustment of access rights
100% coverage
Information Access Restriction
100% coverage
Acceptable use of assets
100% coverage
Information security roles and responsibilities
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Protection of test data
100% coverage
Controls against mal- ware
100% coverage
Installation of software on operational systems
100% coverage
Information Security Awareness & Training
100% coverage
Secure logon procedures
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Review of the policies for information security
100% coverage
Contact with authorities
100% coverage
Contact with special interest groups
100% coverage
Physical security perimeter
100% coverage
Physical entry controls
100% coverage
Securing offices, rooms and facilities
100% coverage
User registration and de-registration
100% coverage
Management of privileged access rights
100% coverage
Management of secret authentication information of users
100% coverage
Use of privileged utility programs
100% coverage
Access control policy
100% coverage
Management of technical vulnerabilities
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage

Cloud Security

Information Security policy for supplier relationships
100% coverage
Return of assets
100% coverage
Secure development policy
100% coverage
Secure system engineering principles
100% coverage
Information security in project management
100% coverage
Classification of Information
100% coverage
Information Security Awareness & Training
100% coverage
Protecting against external and environmental threats
100% coverage
Understanding the context of the organization
100% coverage

Asset Management

Information and communication technology supply chain
100% coverage
Acceptable use of assets
100% coverage
Information security roles and responsibilities
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Ownership of assets
100% coverage
Return of assets
100% coverage
Intellectual property rights
100% coverage
Secure disposal or re- use of equipment
100% coverage
Security of equipment and assets off-premises
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Information security in project management
100% coverage
Classification of Information
100% coverage
Disposal of media
100% coverage
Installation of software on operational systems
100% coverage
Information Security Awareness & Training
100% coverage
Identification of applicable legislation and contractual requirements
100% coverage
Network controls
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Review of the policies for information security
100% coverage
Clear desk and clear screen policy
100% coverage
Planning information security continuity
100% coverage
Implementing information security continuity
100% coverage
Management of privileged access rights
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage
Storage Media
100% coverage

Endpoint Security

Information Access Restriction
100% coverage
Information security roles and responsibilities
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Inventory of assets
100% coverage
Security of equipment and assets off-premises
100% coverage
Information security in project management
100% coverage
Classification of Information
100% coverage
Controls against mal- ware
100% coverage
Installation of software on operational systems
100% coverage
Restrictions on software installation
100% coverage
Information Security Awareness & Training
100% coverage
Secure logon procedures
100% coverage
Review of the policies for information security
100% coverage
Contact with authorities
100% coverage
Contact with special interest groups
100% coverage
Physical security perimeter
100% coverage
Physical entry controls
100% coverage
Securing offices, rooms and facilities
100% coverage
Protecting against external and environmental threats
100% coverage
Clear desk and clear screen policy
100% coverage
Equipment siting and protection
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Cybersecurity & Data Protection Governance

Information Access Restriction
100% coverage
Documented Operating Procedures
100% coverage
Acceptable use of assets
100% coverage
Information security roles and responsibilities
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Ownership of assets
100% coverage
Return of assets
100% coverage
Access control to source code
100% coverage
Information security in project management
100% coverage
Classification of Information
100% coverage
Information Security Awareness & Training
100% coverage
Secure logon procedures
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Review of the policies for information security
100% coverage
Contact with authorities
100% coverage
Contact with special interest groups
100% coverage
Physical security perimeter
100% coverage
Physical entry controls
100% coverage
Securing offices, rooms and facilities
100% coverage
Protecting against external and environmental threats
100% coverage
Management of privileged access rights
100% coverage
Password Management System
100% coverage
Use of privileged utility programs
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Continuous Monitoring

Information Access Restriction
100% coverage
Acceptable use of assets
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Employment Termination
100% coverage
Inventory of assets
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Protection of test data
100% coverage
Controls against mal- ware
100% coverage
Installation of software on operational systems
100% coverage
Information Security Awareness & Training
100% coverage
Secure logon procedures
100% coverage
Teleworking controls throughout the ISMS
100% coverage
Contact with authorities
100% coverage
Contact with special interest groups
100% coverage
Physical security perimeter
100% coverage
Working in secure areas
100% coverage
Event logging
100% coverage
Protection of log information
100% coverage
Management of privileged access rights
100% coverage
Management of technical vulnerabilities
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Business Continuity & Disaster Recovery

Information Access Restriction
100% coverage
Information security roles and responsibilities
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Inventory of assets
100% coverage
Ownership of assets
100% coverage
Capacity management
100% coverage
Access control to source code
100% coverage
Controls against mal- ware
100% coverage
Information Security Awareness & Training
100% coverage
Secure logon procedures
100% coverage
Review of the policies for information security
100% coverage
Physical security perimeter
100% coverage
Securing offices, rooms and facilities
100% coverage
Protecting against external and environmental threats
100% coverage
Information backup
100% coverage
Planning information security continuity
100% coverage
Implementing information security continuity
100% coverage
Verify, review and evaluate information security continuity
100% coverage
Availability of information processing facilities
100% coverage
Password Management System
100% coverage
Use of privileged utility programs
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage
Physical Security Monitoring
100% coverage

Third-Party Management

Managing changes to supplier services
100% coverage
Security of network services
100% coverage
Outsourced development
100% coverage
Information Security policy for supplier relationships
100% coverage
Addressing security within supplier agreements
100% coverage
Information and communication technology supply chain
100% coverage
Monitoring and review of supplier services
100% coverage
Acceptable use of assets
100% coverage
Information security roles and responsibilities
100% coverage
Segregation of duties
100% coverage
Screening
100% coverage
Terms & Conditions
100% coverage
Management Responsibilities
100% coverage
Disciplinary Process
100% coverage
Return of assets
100% coverage
Information Security Awareness & Training
100% coverage
Identification of applicable legislation and contractual requirements
100% coverage
Contact with special interest groups
100% coverage
Physical security perimeter
100% coverage
Password Management System
100% coverage
Use of privileged utility programs
100% coverage
Policies for information security
100% coverage
Understanding the context of the organization
100% coverage
Leadership commitment
100% coverage
Define scope of certification
100% coverage

Compliance Documents

Download our publicly available compliance and security documents for your review.

Maiky Information Security Whitepaper v1.3.pdf

30050887 ISMS22_English.pdf

Maiky

All the data shown is provided by the customer. Maiky takes no ownership nor confirms the accuracy of this information.