Effective Date: May 10, 2018
Alperton Ltd. has a dedicated security team that guides the implementation of controls, processes, and procedures governing the security of Alperton Ltd. and its customers. The Alperton Ltd. security team is responsible for developing, implementing and maintaining an information security program that reflects the following principles:
- Align security activities with Alperton Ltd.’s strategies and support Alperton Ltd.’s objectives.
- Leverage security to facilitate confidentiality, integrity, and availability of data and assets.
- Utilize Alperton Ltd.’s security resources efficiently and effectively.
- Utilize monitoring and metrics to facilitate adequate performance of security related activities.
- Manage security utilizing a risk based approach.
- Implement measures designed to manage risks and potential impacts to an acceptable level.
- Leverage industry security frameworks where relevant and applicable.
- Leverage compliance/assurance processes as necessary.
- Analyze identified or potential threats to Alperton Ltd. and its customers, provide reasonable remediation recommendations, and communicate results as appropriate.
DATA CENTER SECURITY, AVAILABILITY, AND DISASTER RECOVERY
- Alperton Ltd. leverages leading data center providers to house our physical infrastructure.
- Our data center providers utilize an array of security equipment, techniques and procedures designed to control, monitor, and record access to the facilities.
- We have implemented solutions designed to protect against and mitigate effects of DDoS attacks.
- Alperton Ltd. maintains geographically separate data centers to facilitate infrastructure and service availability and continuity.
APPLICATION LEVEL SECURITY
- Alperton Ltd. hashes passwords for user accounts and provides SSL for customers.
- Alperton Ltd. utilizes Web Application Firewall (WAF) technology.
- We analyze identified or potential threats to Alperton Ltd. and its customers, provide reasonable remediation recommendations, and communicate results as appropriate.
SYSTEMS ACCESS CONTROL
- Access to Alperton Ltd. systems is limited to appropriate personnel.
- Alperton Ltd. subscribes to the principle of least privilege (e.g., employees, system accounts, vendors, etc. are provided with the least amount of access for their job function).