Your contact information
Organization
Security Organization and Compliance
-
How is information security managed systematically?
-
How does Natuvion identify and address information security risks?
Information security risks are identified, assessed, and appropriately addressed as part of an established risk management process. The assessment and mitigation are conducted on a regular basis and whenever relevant changes or events occur.
-
How are employees involved in information security?
Employees are made aware of information security issues and receive regular training as part of established processes. Relevant security requirements and reporting procedures are communicated and continuously supported.
-
How is data protection integrated into the organization?
Data protection requirements are taken into account early on in the development of new processes and systems and are implemented through technical and organizational measures. Employees are regularly educated on these matters. Service providers are vetted before being contracted and are contractually obligated to comply.
-
How does Natuvion assess and address relevant legal requirements?
Relevant legal and regulatory requirements are identified and assessed as part of established compliance processes and, where necessary, translated into internal guidelines and measures.
-
How are external dependencies managed?
As part of its supplier management process, Natuvion evaluates suppliers and service providers for information security and data protection prior to awarding contracts. The requirements are set forth in the contract, and the collaboration is reviewed on a regular basis.
Technical and Operational Protection
-
How are internal accesses generally monitored?
Natuvion controls access to systems and information through a role-based authorization model based on the principle of least privilege. Access rights are granted, adjusted, and revoked in a controlled manner throughout the entire employment period and are reviewed on a regular basis. Stricter security requirements apply to authentication and privileged access.
-
How are technical risks and changes managed?
Technical risks, vulnerabilities, and changes are assessed and addressed appropriately as part of established security and operational processes. Changes to relevant systems are made in accordance with defined procedures.
-
How are security incidents detected and handled?
Security-related events are identified, assessed, and addressed as part of established monitoring and incident management processes. Lessons learned from security incidents are incorporated into the continuous improvement of security measures. Affected customers are notified in accordance with applicable legal and contractual requirements.
-
How does Natuvion prepare for disruptions?
Natuvion takes potential business interruptions into account as part of its established emergency and business continuity processes. Appropriate measures are in place for relevant systems to ensure the security and restoration of operations, and the effectiveness of these measures is regularly reviewed.
Contact
Would you like to learn more? Simplyfill out the contact form, and we’ll get back to you as soon as possible.
Contact Us Now