Governance
A security policy backed by senior management
Security at Make IT Safe relies on an information security management system (ISMS) built along the ISO/IEC 27001 standard. Its scope covers the development, delivery and operation of the platform.
The CISO sits on the management team and reports every month to the chief executive, who sets the budgets for the security policy. This policy is reviewed every year, or whenever a major change occurs.
Security requirements are passed on to our suppliers. Their contracts carry security clauses, and we assess them in our own solution.
Three levels of documents
The information security policy sets the principles. Directives apply them topic by topic, then procedures describe their technical and organisational implementation.
Named roles
A CISO, a data protection officer, administrators and a product owner, who is accountable for secure development practices.
Trained staff
Every employee signs an information system charter and a confidentiality undertaking, then follows a security awareness and training programme.
Data protection
What happens to your data, from hosting to the end of the contract
Hosted in France
The platform is hosted in France on OVHcloud and 3DS OUTSCALE, in ISO 27001 and ISO 27701 certified datacentres. A dedicated SecNumCloud offer is available.
Encryption
Databases are encrypted, with a key managed by Make IT Safe. All exchanges with the platform go through encrypted connections, and passwords are never stored in clear text.
Backups
Data and systems are backed up every day, with one month of history, a monthly copy and a yearly copy. Copies are encrypted and stored on a remote site.
Reversibility
At the end of the contract, your data is returned to you in an open format, through an encrypted channel. It is then deleted from servers and backups, and a destruction certificate is issued within 30 days.
Access control
Access limited to what is strictly needed
- Access rights follow two rules: need to know and least privilege. In the solution, permission profiles apply them to your own users.
- Accounts are personal, including administration accounts. Generic accounts are forbidden.
- Access to production environments is reviewed every six months, and an employee’s rights are revoked when they leave.
- Administration actions are logged. Logs are centralised and time-stamped, and an administrator cannot alter an event once it has been collected.
- The network is split into zones separated by firewalls, where every flow is denied by default. The hosting provider supplies protection against denial-of-service attacks.
Development
Security built into the development cycle
- Every development is assessed against the OWASP Top 10, and developers are trained on this framework.
- Development, test and production environments are segregated. Acceptance environments only use fictitious data.
- A release is qualified in pre-production, then approved by the product owner before going live.
- Vulnerability monitoring triggers the fixes. Security updates are deployed automatically, with a rollback available.
- Security tests take place every six months: penetration tests, configuration audit or code audit.
Incidents and continuity
From the report to the return to normal
Any employee and any customer can report an incident or a security flaw. The report then follows the same process, whatever its origin.
Handled incidents are reviewed in committee, to track their status and check that the service levels set in the contract are met.
Qualification and severity
Every report is qualified by a single point of contact, then ranked on four severity levels, assessed on availability, integrity, confidentiality and proof.
Crisis unit
Critical incidents are escalated to a crisis unit. Any personal data breach is notified to the customers concerned.
Post-incident review
Every incident is reviewed with the people involved, and a report records the changes made to security measures.
Business continuity
A continuity plan covers major failures and disasters. It is tested at least once a year through realistic exercises.
Personal data
Our commitments as a processor under the GDPR
For the data you enter in the platform, you are the controller and Make IT Safe is the processor. A data protection officer oversees compliance with the regulation.
Processing on www.makeitsafe.fr is described in the privacy policy, and the conditions of use of the platform in the terms of use.
Make IT Safe undertakes to:
- Process data only for the purposes set out in the contract.
- Keep a record of the processing carried out on behalf of its customers.
- Help its customers respond to data subject requests.
- Only use sub-processors that provide sufficient guarantees.
- Keep no copy of the data after the end of the contract, and provide proof of it.
Documents and audits
What our customers can request and verify
Detailed security documents are shared with our customers, on request.
On request
Security Assurance Plan
The reference document: organisation, technical and organisational measures, set out chapter by chapter along the ISO/IEC 27001 standard. It is shared with our customers. The document is in French.
On request
ISMS audit summary
The information security management system is audited every year. A summary of the results can be presented to customers.
One month’s notice
Customer audit
A customer can audit the platform at its own expense, directly or through a third party. Make IT Safe gives access to the documents and people required, and proposes a remediation plan if a shortcoming is found.
One month’s notice
Customer penetration test
A customer can commission a penetration test at its own expense, under an audit agreement signed before each test, which sets out its duration, type and scope.
In practice
Frequently asked questions
Where is the platform data hosted?
In France, on OVHcloud and 3DS OUTSCALE, in ISO 27001 and ISO 27701 certified datacentres. A dedicated SecNumCloud offer is available for organisations that need it.
What happens to our data at the end of the contract?
It is returned to you in an open format, through an encrypted channel. It is then deleted from servers and backups, irreversibly. A destruction certificate is issued within 30 days.
Can Make IT Safe be audited?
Yes. A customer can carry out an audit or a penetration test, directly or through a third party, by giving Make IT Safe one month’s written notice. The third party must not be a competitor, and a penetration test requires an audit agreement signed beforehand.
What is Make IT Safe’s role under the GDPR?
For the data you enter in the platform, you are the controller and Make IT Safe is the processor. For the data collected on this website, Make IT Safe is the controller: the privacy policy describes that processing.
How do I report an incident or a security flaw?
By email to support@makeitsafe.fr, or by phone during business hours. No technical information should travel in clear text: details are exchanged in an encrypted archive.