AmagisTech
  • Aree di servizio

    Cybersecurity gestitaSOC 24/7, detection e responseIdentity & ComplianceSSO, MFA, NIS2, DORA, ISOObservability & SecOpsMonitoring, log, SecOpsCloud & InfrastructureGoogle Cloud e AWS gestiti

    Certificazioni

    ISO 27001SOC 2NIS2DORAISO 9001ISO 42001ISO 22301
    Tutte le soluzioni
  • Chi siamo
  • Blog
Parla con noi

Aree di servizio

Cybersecurity gestitaIdentity & ComplianceObservability & SecOpsCloud & Infrastructure

Certificazioni

ISO 27001SOC 2NIS2DORAISO 9001ISO 42001ISO 22301

Azienda

Tutte le soluzioniChi siamoBlogParla con noi

AmagisTech

Servizi

Chi siamo

Blog

Parla con noi

Validating Our Commitment to Excellence

Amagistech aims for continual improvement within its Information Security system and complies with the requirements of ISO 27001:2022 for its services, demonstrating a strong dedication to security.

Here’s a summary of the measures in place for the availability, authenticity, integrity, and confidentiality in relation to data, including personal data, designed to enhance your understanding of AmagisTech Ltd’s data handling and security posture:

1. Confidentiality Measures

  • Policy and Personnel Obligations:
    • Company personnel are obligated to process personal data only when their job duties require it and are forbidden from processing it for unrelated reasons. They must collect only the personal data necessary for their duties.
    • All employees and relevant personnel are required to sign confidentiality agreements as a condition of employment, which remain in effect even after departure. A separate ‘data protection form’ is also signed upon hiring.
    • Any employment or engagement contract contains provisions relating to confidentiality and non-disclosure of information.
  • Access Controls and Segregation:
    • The company utilizes a Cloud-based system with segregation of information on a need-to-know basis. This means personnel only have access to information essential for their specific functions.
    • Privileges are allocated on a need-to-know basis by the Security Team, and elevated access privileges are closely monitored, logged, and periodically reviewed.
    • Shared access accounts are discouraged and, if necessary, require additional controls such as annual review, password changes upon departure, and access log reviews.
    • Access to company systems and data for departing personnel is terminated immediately or as soon as reasonably possible, disabling accounts and revoking privileges.
  • Encryption and Data Handling:
    • Strong encryption is used for all external transmissions across open networks, covering both authentication data and the data itself.
    • Google Workspace backups are encrypted with AES 256-bit at rest and TLS 1.3 in transit.
    • Portable flash media use is strictly forbidden without prior approval from the Security Team; if used, data must be encrypted on the device.
    • The company prioritizes data minimization, ensuring that the gathering, routing, processing, storing, archiving, and visualization of sensitive personal data are kept to the absolute minimum necessary.
  • Physical Security and Clean Desk Policy:
    • Strict physical security measures are in place at the company’s premises.
    • The Clean Desk Guidelines require sensitive/confidential information (hardcopy or electronic) to be secured in the work area at the end of the day or when unoccupied. This includes locking computing devices, removing restricted information from desks, and securing file cabinets.
    • Passwords are strictly forbidden to be left on sticky notes or in accessible locations.

2. Integrity Measures

  • Data Accuracy Principle:
    • The company commits to processing personal data that is accurate and kept up to date, taking every reasonable step to ensure inaccurate data is rectified without delay.
    • Accuracy is checked at the point of collection and at regular intervals.
  • System Controls and Logging:
    • Security controls are implemented at the operating system, database, and application levels to restrict access to computer resources and prevent unauthorized alterations.
    • Host security log files are configured and reviewed for anomalies and must be of sufficient size (at least 90 days) to provide useful information in case of a security event. All security-related events are logged and audited by the Security Team to identify inappropriate access or malicious use.
    • The company maintains audit trails of log files electronically for at least one year.
  • Backup and Recovery:
    • Amagistech employs Google Workspace’s Vault to keep and retain backups of emails, files, and/or conversations with clients in case any relevant matter may arise in the future.
    • Physical security of removable media is maintained, and plans are in place for recovery from unexpected problems. 
    • The Business Continuity & Disaster Recovery Plan (BC&DRP) includes procedures for restoring backed-up data and ensuring operational continuity in the event of system failures or disruptions. 

3. Availability Measures

  • Business Continuity & Disaster Recovery Plan (BC&DRP):
    • The company has a comprehensive BC&DRP designed to minimize recovery time, impact on business and clients, and identify resources for essential functions.
    • It addresses continuity from loss of floor space/building usage (e.g., fire, flood), building services (e.g., power loss), and information technology systems (e.g., communications failure, malicious attack).
    • The Business Continuity Officer (BCO) is responsible for implementing and reviewing the BC&DRP annually, including conducting tests for various scenarios like evacuation, out-of-hours emergencies, and loss of premises.
  • Cloud-Based Infrastructure:
    • The company utilizes a cloud-based system, which inherently reduces the attack surface and provides resilience compared to on-premises solutions.
    • Google Workspace and Chromebooks form the core network infrastructure, enabling remote access to essential applications for employees. This allows for continued operations even if premises are inaccessible.
  • Redundancy and Emergency Procedures:
    • In the event of a critical disruption, the BCO can decide to relocate operations to a designated contingency site or allow employees to work from home. The company provides desks, chairs, and high-speed internet at contingency sites.
    • Potential replacements are identified for key personnel to ensure continuity in case of their loss.
    • The BC&DRP includes specific actions for various threats, such as equipment failure, software failure, power outages, and environmental disasters, outlining recovery steps and responsible personnel.

4. Authenticity Measures

  • Strong Authentication:
    • All devices used for remote work must be password protected, and double authentication methods (2FA) are mandatory, with Multi-Factor Authentication (MFA) being the preferred method.
    • Authentication involves a combination of an identifier and at least two factors, such as a secure password, MFA token, IP address whitelist, physical key, or biometric data.
  • Password Policies:
    • Strong password creation guidelines are enforced, requiring passwords to contain between 12 and 100 alphanumeric characters.
    • Passwords must not be shared with anyone and are treated as sensitive, confidential company information.
    • Users are prohibited from revealing passwords over the phone, in email messages, or storing them unencrypted. The “Remember Password” feature of applications is forbidden.
    • Users are required to report any suspected password compromises immediately.
  • Identity Verification:
    • Security controls identify and verify the identity and, if necessary, the IP or location of each authorized user accessing computer resources.
    • Involved Persons must provide valid identification before being granted access to Company computing resources.

5. Personal Data Specifics and Overall Security Level

  • GDPR Compliance and Accountability:
    • The company adheres to fundamental data protection principles: Lawfulness, Fairness, Transparency, Purpose Limitation, Data Minimisation, Accuracy, Storage Limitation, Security, Integrity, Confidentiality, and Transfer Limitation.
    • The company is structured to prove and document its compliance with GDPR, embodying the “Accountability Principle”.
  • Personnel Training and Awareness:
    • All Company Personnel receive mandatory training on data protection laws and cybersecurity matters. This training covers topics like digital identities, email management, phishing awareness, use of work devices, encryption, and physical security.
  • Ongoing Monitoring and Audits:
    • Automated tools provide real-time notification of detected wrongdoing and vulnerability exploitation.
    • Regular evaluations of security programs and practices are conducted by the SOC Manager, including password strength, unauthorized devices, and remote connectivity.
    • Security measures are periodically audited to ensure robustness and effectiveness.

Trust Center

Terms of Business

Security Terms & Conditions

Google Workspace Terms & Conditions

Privacy Policy

Vanta Terms & Conditions

Penetration Test Terms & Conditions

Google Cloud Products Terms & Conditions

Linkedin

Level 4, 266 Triq ix-Xatt, GZR1020, Gzira, Malta | Via Durini 25, 20121, Milano, Italia - CF/P.IVA 12664770968 | AmagisTech

Trust Center

Terms of Business

Security Terms & Conditions

Google Workspace Terms & Conditions

Privacy Policy

Vanta Terms & Conditions

Penetration Test Terms & Conditions

Google Cloud Products Terms & Conditions

Linkedin

Level 4, 266 Triq ix-Xatt, GZR1020, Gzira, Malta |
Via Durini 25, 20121, Milano, Italia -
CF/P.IVA 12664770968 | AmagisTech

Trust Center

Terms of Business

Security Terms & Conditions

Google Workspace Terms & Conditions

Privacy Policy

Vanta Terms & Conditions

Penetration Test Terms & Conditions

Google Cloud Products Terms & Conditions

Linkedin

Level 4, 266 Triq ix-Xatt, GZR1020, Gzira, Malta | Via Durini 25, 20121, Milano, Italia
- CF/P.IVA 12664770968 | AmagisTech