Uhubs conducts regular vulnerability scans on its infrastructure and applications, utilising industry-standard tools. Scans are scheduled at least monthly, with immediate scans triggered for any significant changes to the environment.
Integration of external threat intelligence sources to stay informed about emerging threats. Regular monitoring of these sources ensures timely awareness of potential risks.
Uhubs commissions a penetration test of the Platform at least once every 12 months, carried out by an independent qualified third party. A summary of each test is available to customers on request. Findings are remediated under the timeframes in section 2.2.
Define a clear classification system for threat severity, considering factors such as exploitability, potential impact, and affected assets.
Remediation targets by severity, measured from confirmation of the finding:
Where a fix is not available within the target, Uhubs applies a documented compensating control and records the reason for the extension. These targets apply to findings from internal scanning, third-party penetration testing, and provider security advisories alike.
Clearly defined measures for mitigating identified vulnerabilities, ranging from software patches and configuration changes to temporary workarounds.
Develop a detailed incident communication plan outlining:
Clearly define roles and responsibilities for stakeholders during a security incident. This includes communication responsibilities, technical response actions, and managerial oversight.
Conduct regular tabletop exercises to simulate security incidents. This collaborative approach helps identify gaps in the response framework and ensures effective communication among stakeholders.
Hold 'pre-mortems' before major releases or changes to predict potential security risks. This involves scenario-based discussions and risk identification to proactively address vulnerabilities.
Following any security incident, conduct a comprehensive 'post-mortem' analysis. This includes:
Implement an iterative approach to threat and vulnerability management, incorporating insights from 'pre-mortems' and 'post-mortems' into future risk assessments and response strategies.
Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.