0x
005558
2024-06-24

Cybersecurity Controls for Geo-Zone Web Services

What Cybersecurity Controls does Dlubal provide for the Geo-Zone web services?


Answer:

Technical Controls

  • Multi-Level Security Model: We have in place a multi-level security model to protect our data and systems.
  • NGFW Firewalls and Intrusion Detection and Protection Systems (IDS/IPS): We employ advanced firewalls and IDS/IPS, including AI detection core, to protect our technical infrastructure from unauthorized access and threats.
  • WAF Proxy and Application Gateways: We utilize WAF proxies, application gateways, OWASP standards, fast zero-day protection, and custom rulesets to tailor WAF implementation to organization-specific policies.
  • Encryption: Data in transit and at rest is encrypted using industry-standard protocols to ensure confidentiality and integrity.

Access Controls: We enforce strict access controls and role-based access controls (RBAC) to limit access to sensitive data and systems.

  • Endpoint Protection: Our endpoint protection includes ransomware and data-stealth protection, EDR/XDR, and AI-based security measures.
  • Regular Security Audits and Vulnerability Assessments: We conduct regular security audits and vulnerability assessments through third-party providers to identify and remediate potential security weaknesses.

Cyber Intelligence Detection

  • Continuous Monitoring: We have systems in place for continuous monitoring of network traffic and system activities to detect anomalies and potential threats using AI intelligence.
  • Threat Intelligence: We leverage threat intelligence feeds and services to stay updated on the latest cyber threats and enhance our detection capabilities.

Cyber Incident Reporting Protocol

  • Incident Response Plan: We have a comprehensive incident response plan that outlines the steps to be taken in the event of a cybersecurity incident.
  • Incident Reporting: All incidents are reported to our security team immediately, and a detailed incident report is generated. This includes an assessment of the impact, mitigation steps taken, and lessons learned.
  • Communication Protocol: We have a defined communication protocol to ensure timely and effective communication with all stakeholders during and after an incident.

Supporting Documents

We have several documents detailing our cybersecurity controls, incident response plans, and threat intelligence measures. These include:

  • Security Policy Documentation
  • Incident Response Plan
  • Threat Intelligence Reports
  • Audit and Assessment Reports

However, we are not sharing them for security reasons because they contain sensitive information that could potentially compromise our security.

Our internal documents and workflows are based on ISO/IEC 27001 and NIST CSF recommendations.



;