Trust Center
Trust Center
Sleak is the AI Coach that develops your team's professional skills and knowledge through conversation. Managers define what their team needs to learn or improve — Sleak's Coach teaches it, trains it through realistic simulated conversations, and evaluates progress against your own standards of excellence.
Controls
The 89 implemented Annex A controls of our ISO/IEC 27001:2022-certified information security management system.
Organizational security
37 controls- Information security policiesThe company maintains a set of information security policies that are approved by management, communicated to employees, and reviewed at planned intervals.
- Information security roles and responsibilitiesThe company defines and allocates information security roles and responsibilities across the organization.
- Segregation of dutiesConflicting duties and areas of responsibility are segregated to reduce the risk of unauthorized or unintentional modification or misuse of the company's assets.
- Management responsibilitiesManagement requires all personnel to apply information security in accordance with the established policies and procedures.
- Contact with authoritiesThe company maintains appropriate contacts with relevant authorities, such as data protection or law enforcement bodies.
- Contact with special interest groupsThe company maintains contact with special interest groups, security forums and professional associations relevant to information security.
- Threat intelligenceThe company collects and analyzes information relating to information security threats to produce threat intelligence.
- Information security in project managementInformation security is integrated into the company's project management processes.
- Inventory of information and other associated assetsThe company maintains an inventory of information and other assets associated with information and information processing facilities.
- Acceptable use of information and other associated assetsThe company documents and implements rules for the acceptable use of information and associated assets.
- Return of assetsPersonnel and external parties return all company assets in their possession upon termination of their employment, contract or agreement.
- Classification of informationInformation is classified in terms of confidentiality, integrity, availability and other requirements based on legal and business needs.
- Labelling of informationThe company develops and implements procedures for information labelling in accordance with its classification scheme.
- Information transferInformation transfer rules, procedures and agreements are in place for transfers within the company and with external parties.
- Access controlRules to control physical and logical access to information and other associated assets are established based on business and security requirements.
- Identity managementThe full lifecycle of identities is managed to ensure unique identification of individuals and systems, and appropriate assignment of access rights.
- Authentication informationAllocation and management of authentication information is controlled by a management process, including advice on appropriate handling.
- Access rightsAccess rights to information and other associated assets are provisioned, reviewed, modified and removed in accordance with the company's access control policy.
- Information security in supplier relationshipsProcesses and procedures are defined and implemented to manage the information security risks associated with the use of suppliers' products or services.
- Addressing information security within supplier agreementsRelevant information security requirements are agreed with each supplier based on the type of supplier relationship.
- Managing information security in the ICT supply chainProcesses and procedures are in place to manage the information security risks associated with the ICT products and services supply chain.
- Monitoring, review and change management of supplier servicesThe company regularly monitors, reviews and audits supplier service delivery, and manages changes to supplier services.
- Information security for use of cloud servicesProcesses for acquisition, use, management and exit from cloud services are established in accordance with the company's information security requirements.
- Information security incident management planning and preparationThe company plans and prepares for managing information security incidents by defining roles, responsibilities and procedures.
- Assessment and decision on information security eventsInformation security events are assessed and it is decided if they are to be categorized as information security incidents.
- Response to information security incidentsInformation security incidents are responded to in accordance with documented procedures.
- Learning from information security incidentsKnowledge gained from information security incidents is used to strengthen and improve information security controls.
- Collection of evidenceThe company defines and applies procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
- Information security during disruptionThe company plans how to maintain information security at an appropriate level during disruption.
- ICT readiness for business continuityICT readiness is planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.
- Legal, statutory, regulatory and contractual requirementsLegal, statutory, regulatory and contractual requirements relevant to information security are identified, documented and kept up to date.
- Intellectual property rightsThe company implements procedures to protect intellectual property rights and the use of proprietary software products.
- Protection of recordsRecords are protected from loss, destruction, falsification, unauthorized access and unauthorized release.
- Privacy and protection of PIIThe company identifies and meets requirements regarding the preservation of privacy and protection of personally identifiable information (PII).
- Independent review of information securityThe company's approach to managing information security is reviewed independently at planned intervals or when significant changes occur.
- Compliance with policies, rules and standardsCompliance with the company's information security policy, topic-specific policies, rules and standards is regularly reviewed.
- Documented operating proceduresOperating procedures for information processing facilities are documented and made available to personnel who need them.
People security
8 controls- ScreeningBackground verification checks on candidates are carried out prior to joining the company, proportional to business requirements and applicable laws.
- Terms and conditions of employmentEmployment contracts state personnel's and the company's responsibilities for information security.
- Information security awareness, education and trainingPersonnel receive appropriate information security awareness education and training, and regular updates on company policies and procedures.
- Disciplinary processA disciplinary process is in place to take action against personnel who have committed an information security policy violation.
- Responsibilities after termination or change of employmentInformation security responsibilities and duties that remain valid after termination or change of employment are defined, communicated and enforced.
- Confidentiality or non-disclosure agreementsConfidentiality or non-disclosure agreements reflecting the company's needs for the protection of information are identified, documented, reviewed and signed by personnel.
- Remote workingSecurity measures are implemented when personnel work remotely, to protect information accessed, processed or stored outside company premises.
- Information security event reportingPersonnel report observed or suspected information security events through appropriate channels in a timely manner.
Physical security
11 controls- Physical security perimetersSecurity perimeters are defined and used to protect areas that contain information and other associated assets.
- Physical entrySecure areas are protected by appropriate entry controls and access points.
- Securing offices, rooms and facilitiesPhysical security for offices, rooms and facilities is designed and implemented.
- Physical security monitoringPremises are continuously monitored for unauthorized physical access.
- Protecting against physical and environmental threatsProtection against physical and environmental threats, such as natural disasters and other intentional or unintentional threats, is designed and implemented.
- Clear desk and clear screenClear desk rules for papers and removable storage media, and clear screen rules for information processing facilities, are defined and appropriately enforced.
- Security of assets off-premisesOff-site assets are protected, taking into account the different risks of working outside the company's premises.
- Storage mediaStorage media are managed through their lifecycle of acquisition, use, transportation and disposal in accordance with the classification scheme and handling requirements.
- Supporting utilitiesInformation processing facilities are protected from power failures and other disruptions caused by failures in supporting utilities.
- Equipment maintenanceEquipment is maintained correctly to ensure availability, integrity and confidentiality of information.
- Secure disposal or re-use of equipmentEquipment containing storage media is verified to ensure any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
Technological security
33 controls- User endpoint devicesInformation stored on, processed by or accessible via user endpoint devices is protected.
- Privileged access rightsThe allocation and use of privileged access rights is restricted and managed.
- Information access restrictionAccess to information and other associated assets is restricted in accordance with the company's access control policy.
- Access to source codeRead and write access to source code, development tools and software libraries is appropriately managed.
- Secure authenticationSecure authentication technologies and procedures are implemented based on information access restrictions and the access control policy.
- Capacity managementThe use of resources is monitored and adjusted in line with current and expected capacity requirements.
- Protection against malwareProtection against malware is implemented and supported by appropriate user awareness.
- Management of technical vulnerabilitiesInformation about technical vulnerabilities is obtained, the company's exposure is evaluated, and appropriate measures are taken.
- Configuration managementConfigurations, including security configurations, of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.
- Information deletionInformation stored in systems, devices or removable media is deleted when no longer required.
- Data maskingData masking is used in accordance with the company's access control policy and other related policies, and business requirements.
- Data leakage preventionMeasures are applied to systems, networks and other devices that process, store or transmit sensitive information to prevent data leakage.
- Information backupBackup copies of information, software and systems are maintained and regularly tested in accordance with an agreed backup policy.
- Redundancy of information processing facilitiesInformation processing facilities are implemented with redundancy sufficient to meet availability requirements.
- LoggingLogs that record activities, exceptions, faults and other relevant events are produced, kept, protected and analyzed.
- Monitoring activitiesNetworks, systems and applications are monitored for anomalous behavior, and appropriate actions are taken to evaluate potential information security incidents.
- Clock synchronizationThe clocks of information processing systems are synchronized to approved time sources.
- Use of privileged utility programsThe use of utility programs that can override system and application controls is restricted and tightly controlled.
- Installation of software on operational systemsProcedures and measures are implemented to securely manage software installation on operational systems.
- Networks securityNetworks and network devices are secured, managed and controlled to protect information in systems and applications.
- Security of network servicesSecurity mechanisms, service levels and requirements of network services are identified, implemented and monitored.
- Segregation of networksGroups of information services, users and systems are segregated on the company's networks.
- Web filteringAccess to external websites is managed to reduce exposure to malicious content.
- Use of cryptographyRules for the effective use of cryptography, including cryptographic key management, are defined and implemented.
- Secure development life cycleRules for the secure development of software and systems are established and applied.
- Application security requirementsInformation security requirements are identified, specified and approved when developing or acquiring applications.
- Secure system architecture and engineering principlesPrinciples for engineering secure systems are established, documented, maintained and applied to any information system development activity.
- Secure codingSecure coding principles are applied to software development.
- Security testing in development and acceptanceSecurity testing processes are defined and implemented in the development life cycle.
- Separation of development, test and production environmentsDevelopment, testing and production environments are separated and secured.
- Change managementChanges to information processing facilities and systems are subject to change management procedures.
- Test informationTest information is appropriately selected, protected and managed.
- Protection of information systems during audit testingAudit tests and other assurance activities involving assessment of operational systems are planned and agreed between the tester and appropriate management.