Network and Infrastructure Security
Least Privilege
AWS Security Groups employed for our infrastructure are baselined regularly to maintain least privilege. Access granted to team members for our AWS production environment is baselined on a regular basis to maintain least privilege.
How it is checked
Security groups and production access are baselined on a regular basis.
Framework requirements this speaks to
- ISO 27001 A.8.2 (privileged access rights)
- ISO 27001 A.5.18 (access rights)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.