Information security policy
RDMC applies a risk-based approach to preserve confidentiality, integrity, availability, traceability and resilience.
Principles
Least privilege
Access granted on a need-to-know basis.
Defense in depth
Complementary organizational, network, system and application controls.
Security by design
Requirements embedded from the design stage.
Continuous improvement
Audits, incidents, patches and lessons learned.
Technical and organizational measures
- identity and entitlement management;
- strong authentication where required;
- segmentation and separation of environments;
- logging and monitoring;
- vulnerability and patch management;
- encryption in transit and, depending on the service, at rest;
- backup, continuity and recovery according to subscribed commitments;
- securing development pipelines and secrets.
Shared responsibility
The Customer remains responsible for its users, endpoints, passwords, administrator access, configurations, data, third-party applications and its own regulatory obligations.
Incidents
RDMC qualifies incidents within its scope and implements appropriate containment, investigation, remediation and return-to-normal measures. Notifications are made under the Contract and applicable obligations.