audit rights dpa residency · Privacy Policy
ProSights policy finding
“ Physical security (hosting providers). Facilities employ 24×7 professional security, CCTV, badge access, and visitor logging. Asset & media controls. Devices are inventoried and encrypted; media is sanitized consistent with NIST 800-88 upon decommissioning. Identity & access. SSO + MFA, least privilege, quarterly access reviews, privileged session logging, and emergency break-glass procedures with approval and post-use review. Identity and access practices align to NIST 800-53 control families. Network & application security. Segmentation, WAF, rate limiting, secure configuration baselines, dependency monitoring, and security headers. Monitoring & response targets (non-contractual). Centralized logging/SIEM, alerting, and vulnerability management with target response objectives: P1 (critical) initial response ≤ 1 hour; containment ≤ 4 hours. P2 (high) initial response ≤ 4 hours. P3 (moderate/low) initial response next business day. Resilience. RTO 4 hours for critical services (AI systems included). RPO 1 hour via frequent backups and resilient storage.”
- Document
- Privacy Policy
- Captured
- 2026-09-25
- Location
- Privacy Policy › “ANNEX A — SECURITY CONTROLS OVERVIEW”
- Snapshot SHA-256
- f80277babf7cbcb49e258ff753e45cb02b25a696c26e44cfe706891398305f84
Informational only, not legal advice. Terms change; verify the source and capture date.