Sleak
Trust Center

Trust Center

Sleak is the AI Coach that develops your team's professional skills and knowledge through conversation. Managers define what their team needs to learn or improve — Sleak's Coach teaches it, trains it through realistic simulated conversations, and evaluates progress against your own standards of excellence.

Controls

The 89 implemented Annex A controls of our ISO/IEC 27001:2022-certified information security management system.

Organizational security

37 controls
  • Information security policiesThe company maintains a set of information security policies that are approved by management, communicated to employees, and reviewed at planned intervals.
  • Information security roles and responsibilitiesThe company defines and allocates information security roles and responsibilities across the organization.
  • Segregation of dutiesConflicting duties and areas of responsibility are segregated to reduce the risk of unauthorized or unintentional modification or misuse of the company's assets.
  • Management responsibilitiesManagement requires all personnel to apply information security in accordance with the established policies and procedures.
  • Contact with authoritiesThe company maintains appropriate contacts with relevant authorities, such as data protection or law enforcement bodies.
  • Contact with special interest groupsThe company maintains contact with special interest groups, security forums and professional associations relevant to information security.
  • Threat intelligenceThe company collects and analyzes information relating to information security threats to produce threat intelligence.
  • Information security in project managementInformation security is integrated into the company's project management processes.
  • Inventory of information and other associated assetsThe company maintains an inventory of information and other assets associated with information and information processing facilities.
  • Acceptable use of information and other associated assetsThe company documents and implements rules for the acceptable use of information and associated assets.
  • Return of assetsPersonnel and external parties return all company assets in their possession upon termination of their employment, contract or agreement.
  • Classification of informationInformation is classified in terms of confidentiality, integrity, availability and other requirements based on legal and business needs.
  • Labelling of informationThe company develops and implements procedures for information labelling in accordance with its classification scheme.
  • Information transferInformation transfer rules, procedures and agreements are in place for transfers within the company and with external parties.
  • Access controlRules to control physical and logical access to information and other associated assets are established based on business and security requirements.
  • Identity managementThe full lifecycle of identities is managed to ensure unique identification of individuals and systems, and appropriate assignment of access rights.
  • Authentication informationAllocation and management of authentication information is controlled by a management process, including advice on appropriate handling.
  • Access rightsAccess rights to information and other associated assets are provisioned, reviewed, modified and removed in accordance with the company's access control policy.
  • Information security in supplier relationshipsProcesses and procedures are defined and implemented to manage the information security risks associated with the use of suppliers' products or services.
  • Addressing information security within supplier agreementsRelevant information security requirements are agreed with each supplier based on the type of supplier relationship.
  • Managing information security in the ICT supply chainProcesses and procedures are in place to manage the information security risks associated with the ICT products and services supply chain.
  • Monitoring, review and change management of supplier servicesThe company regularly monitors, reviews and audits supplier service delivery, and manages changes to supplier services.
  • Information security for use of cloud servicesProcesses for acquisition, use, management and exit from cloud services are established in accordance with the company's information security requirements.
  • Information security incident management planning and preparationThe company plans and prepares for managing information security incidents by defining roles, responsibilities and procedures.
  • Assessment and decision on information security eventsInformation security events are assessed and it is decided if they are to be categorized as information security incidents.
  • Response to information security incidentsInformation security incidents are responded to in accordance with documented procedures.
  • Learning from information security incidentsKnowledge gained from information security incidents is used to strengthen and improve information security controls.
  • Collection of evidenceThe company defines and applies procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
  • Information security during disruptionThe company plans how to maintain information security at an appropriate level during disruption.
  • ICT readiness for business continuityICT readiness is planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.
  • Legal, statutory, regulatory and contractual requirementsLegal, statutory, regulatory and contractual requirements relevant to information security are identified, documented and kept up to date.
  • Intellectual property rightsThe company implements procedures to protect intellectual property rights and the use of proprietary software products.
  • Protection of recordsRecords are protected from loss, destruction, falsification, unauthorized access and unauthorized release.
  • Privacy and protection of PIIThe company identifies and meets requirements regarding the preservation of privacy and protection of personally identifiable information (PII).
  • Independent review of information securityThe company's approach to managing information security is reviewed independently at planned intervals or when significant changes occur.
  • Compliance with policies, rules and standardsCompliance with the company's information security policy, topic-specific policies, rules and standards is regularly reviewed.
  • Documented operating proceduresOperating procedures for information processing facilities are documented and made available to personnel who need them.

People security

8 controls
  • ScreeningBackground verification checks on candidates are carried out prior to joining the company, proportional to business requirements and applicable laws.
  • Terms and conditions of employmentEmployment contracts state personnel's and the company's responsibilities for information security.
  • Information security awareness, education and trainingPersonnel receive appropriate information security awareness education and training, and regular updates on company policies and procedures.
  • Disciplinary processA disciplinary process is in place to take action against personnel who have committed an information security policy violation.
  • Responsibilities after termination or change of employmentInformation security responsibilities and duties that remain valid after termination or change of employment are defined, communicated and enforced.
  • Confidentiality or non-disclosure agreementsConfidentiality or non-disclosure agreements reflecting the company's needs for the protection of information are identified, documented, reviewed and signed by personnel.
  • Remote workingSecurity measures are implemented when personnel work remotely, to protect information accessed, processed or stored outside company premises.
  • Information security event reportingPersonnel report observed or suspected information security events through appropriate channels in a timely manner.

Physical security

11 controls
  • Physical security perimetersSecurity perimeters are defined and used to protect areas that contain information and other associated assets.
  • Physical entrySecure areas are protected by appropriate entry controls and access points.
  • Securing offices, rooms and facilitiesPhysical security for offices, rooms and facilities is designed and implemented.
  • Physical security monitoringPremises are continuously monitored for unauthorized physical access.
  • Protecting against physical and environmental threatsProtection against physical and environmental threats, such as natural disasters and other intentional or unintentional threats, is designed and implemented.
  • Clear desk and clear screenClear desk rules for papers and removable storage media, and clear screen rules for information processing facilities, are defined and appropriately enforced.
  • Security of assets off-premisesOff-site assets are protected, taking into account the different risks of working outside the company's premises.
  • Storage mediaStorage media are managed through their lifecycle of acquisition, use, transportation and disposal in accordance with the classification scheme and handling requirements.
  • Supporting utilitiesInformation processing facilities are protected from power failures and other disruptions caused by failures in supporting utilities.
  • Equipment maintenanceEquipment is maintained correctly to ensure availability, integrity and confidentiality of information.
  • Secure disposal or re-use of equipmentEquipment containing storage media is verified to ensure any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.

Technological security

33 controls
  • User endpoint devicesInformation stored on, processed by or accessible via user endpoint devices is protected.
  • Privileged access rightsThe allocation and use of privileged access rights is restricted and managed.
  • Information access restrictionAccess to information and other associated assets is restricted in accordance with the company's access control policy.
  • Access to source codeRead and write access to source code, development tools and software libraries is appropriately managed.
  • Secure authenticationSecure authentication technologies and procedures are implemented based on information access restrictions and the access control policy.
  • Capacity managementThe use of resources is monitored and adjusted in line with current and expected capacity requirements.
  • Protection against malwareProtection against malware is implemented and supported by appropriate user awareness.
  • Management of technical vulnerabilitiesInformation about technical vulnerabilities is obtained, the company's exposure is evaluated, and appropriate measures are taken.
  • Configuration managementConfigurations, including security configurations, of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.
  • Information deletionInformation stored in systems, devices or removable media is deleted when no longer required.
  • Data maskingData masking is used in accordance with the company's access control policy and other related policies, and business requirements.
  • Data leakage preventionMeasures are applied to systems, networks and other devices that process, store or transmit sensitive information to prevent data leakage.
  • Information backupBackup copies of information, software and systems are maintained and regularly tested in accordance with an agreed backup policy.
  • Redundancy of information processing facilitiesInformation processing facilities are implemented with redundancy sufficient to meet availability requirements.
  • LoggingLogs that record activities, exceptions, faults and other relevant events are produced, kept, protected and analyzed.
  • Monitoring activitiesNetworks, systems and applications are monitored for anomalous behavior, and appropriate actions are taken to evaluate potential information security incidents.
  • Clock synchronizationThe clocks of information processing systems are synchronized to approved time sources.
  • Use of privileged utility programsThe use of utility programs that can override system and application controls is restricted and tightly controlled.
  • Installation of software on operational systemsProcedures and measures are implemented to securely manage software installation on operational systems.
  • Networks securityNetworks and network devices are secured, managed and controlled to protect information in systems and applications.
  • Security of network servicesSecurity mechanisms, service levels and requirements of network services are identified, implemented and monitored.
  • Segregation of networksGroups of information services, users and systems are segregated on the company's networks.
  • Web filteringAccess to external websites is managed to reduce exposure to malicious content.
  • Use of cryptographyRules for the effective use of cryptography, including cryptographic key management, are defined and implemented.
  • Secure development life cycleRules for the secure development of software and systems are established and applied.
  • Application security requirementsInformation security requirements are identified, specified and approved when developing or acquiring applications.
  • Secure system architecture and engineering principlesPrinciples for engineering secure systems are established, documented, maintained and applied to any information system development activity.
  • Secure codingSecure coding principles are applied to software development.
  • Security testing in development and acceptanceSecurity testing processes are defined and implemented in the development life cycle.
  • Separation of development, test and production environmentsDevelopment, testing and production environments are separated and secured.
  • Change managementChanges to information processing facilities and systems are subject to change management procedures.
  • Test informationTest information is appropriately selected, protected and managed.
  • Protection of information systems during audit testingAudit tests and other assurance activities involving assessment of operational systems are planned and agreed between the tester and appropriate management.