{"id":136483,"date":"2019-01-07T10:12:50","date_gmt":"2019-01-07T10:12:50","guid":{"rendered":"http:\/\/welovesalt.com\/ca\/?page_id=136483"},"modified":"2024-11-05T12:20:42","modified_gmt":"2024-11-05T17:20:42","slug":"it-security-statement","status":"publish","type":"page","link":"https:\/\/welovesalt.com\/ca\/it-security-statement\/","title":{"rendered":"IT Security Statement"},"content":{"rendered":"
IT <\/strong>Commitment <\/strong><\/span><\/p>\n It is Salt\u2019s policy to carry out business safely and in a transparent manner in accordance with relevant data protection laws.<\/p>\n In accordance with the General Data Protection Regulation (EU) 2016\/679 (\u2018GDPR\u2019) that came into effect on 25 May 2018, we updated our data privacy policies:<\/p>\n All backups are logged and failed backups or missed backups are monitored by the Network Operations Team (NOC).<\/td>\n<\/tr>\n From a Salt point of view, we are a Microsoft Office 365 customer and for this reason, we use a cloud-based CRM system, Salt users can work from anywhere in the event of a disaster where an internet connection is available.<\/p>\n Microsoft has 40+ data centres, as part of Microsoft Office 365, there is multiple site replication.<\/p>\n In addition, Salt has a Disaster Recovery Plan in place which can be requested from the IT\/ Project Manager.<\/td>\n<\/tr>\n Our MSP partners with a number of suppliers for the hosting, back up and storage of data. Microsoft holds a number of certifications including ISO27001. All of these can be found here:<\/p>\n https:\/\/www.microsoft.com\/en-us\/trustcenter\/compliance\/complianceofferings<\/a><\/p>\n Mitol and Solarwinds are also ISO 27001 certified.<\/td>\n<\/tr>\n Hardware, Software, and Networking<\/strong><\/span><\/p>\n\n\n
\n Question <\/strong><\/span><\/td>\n Answer <\/strong><\/span><\/td>\n<\/tr>\n \n Who\/What do you use for your Hosting?<\/td>\n Our MSP hosts our emails and documents in Microsoft Office 365. Our in-house server has a shared drive for our accounting department. We also use Dropbox for internal file sharing.<\/td>\n<\/tr>\n \n What does our MSP do with our data?<\/td>\n Our MSP store the data in the Microsoft cloud and\/or on our server(s). They back up any data outside of the Microsoft cloud into a number of secure data centres. Data stored in Microsoft Azure is backed up and snapshots are taken by Microsoft. Our MSP also provides admin functions on some customer data as directed by Salt.<\/td>\n<\/tr>\n \n Is Salt data segregated?<\/td>\n Data in the Microsoft cloud is segregated from other Microsoft customers. Microsoft uses logical isolation to segregate customers to ensure complete confidentiality and separation.<\/td>\n<\/tr>\n \n Is traffic encrypted?<\/td>\n Data on the Salt network is not encrypted; however, data is kept behind a secure company firewall. Data in the Microsoft cloud is encrypted in transit and at rest.<\/td>\n<\/tr>\n \n Is data encrypted?<\/td>\n Data in the Microsoft cloud is encrypted in transit and at rest. Our MSP uses IT\u2019s backup Partners (MITOL and Solarwinds) who use encryption (AES256) for all data stored.<\/td>\n<\/tr>\n \n Are Salt computers encrypted?<\/td>\n Directors, Accounts and HR departments all have their portable devices encrypted through EM+S.<\/td>\n<\/tr>\n \n Are Salt\u2019s files or emails encrypted?<\/td>\n Office 365 allows Salt to encrypt files and emails using Azure Rights Management.<\/td>\n<\/tr>\n \n How are Passwords stored?<\/td>\n Our MSP does not store any passwords. Regarding the processing of our core data, we use Jobscience (Salesforce), this is an industry standard CRM and Helpdesk system and the data is stored in the Microsoft Cloud. Access to this system is via MFA (Multi-Factor authentication) only and so only authorised personnel are able to access this system. We furthermore have a Password Policy in place to manage how passwords are updated, shared and saved within our business.<\/td>\n<\/tr>\n \n How does Salt monitor Breaches \/ How do we monitor unusual activity \/ How do we report data breaches?<\/td>\n Our MSP have a Network Operations team (NOC) who monitor the safety of our accounts proactively on a daily basis. Our MSP uses an industry standard system provided by Solarwinds. In addition, Microsoft provides alerts and reporting on access and activity. Salt furthermore has a Data Breach Policy in place to adequately manage and report a breach to the competent authorities.<\/td>\n<\/tr>\n \n What is Salt\u2019s backup policy?<\/td>\n Our in-house server has a nightly backup with a 30-day retention. Microsoft data (Office 365) is backed up and retained for 30 days. Our CRM system and Dropbox are webhosted applications in the Cloud.<\/p>\n \n What is our Disaster Recovery procedure?<\/td>\n Our MSP has everything in the cloud in terms of emails, files, remote monitoring, and CRM and Ticketing. Phones are VoIP and so in the event of a disaster, the MSP team would work from home \/ remote offices.<\/p>\n \n <\/td>\n <\/td>\n<\/tr>\n \n What training has been provided for GDPR\/ IT security?<\/td>\n Salt has provided in-house training to their staff on data protection and IT security. Salt has introduced a Code of Conduct that outlines how staff members need to manage data and people\u2019s knowledge is tested by doing a GDPR\/IT Security competency test.<\/td>\n<\/tr>\n \n How does Salt protect access to their servers?<\/td>\n Microsoft servers are secured via access control. Only authorised personnel are allowed in to Microsoft Data Centres. MITOL and Solarwinds servers are secured via access control. Only authorised personnel are allowed into Microsoft Data Centres.<\/td>\n<\/tr>\n \n What Certifications and accreditations do you hold?<\/td>\n Our MSP have ITIL and Microsoft trained staff.<\/p>\n \n How does Salt control access to their data?<\/td>\n Salt uses Office 365 and Dropbox which are both protected by MFA (Multi-Factor authentication). This ensures that staff are the only ones that can log in.<\/td>\n<\/tr>\n \n Who can request information or changes by our MSP?<\/td>\n Our MSP defines an approver list at the outset of working with Salt. Only approved users are able to request new users, leavers, password changes from our MSP.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n