JobzMall Trust Center
Welcome to JobzMall's Trust Center. We are committed to keeping customer data safe and secure. Use this Trust Center to learn about our security posture and request access to our security documentation.
Controls
Updated recentlyInfrastructure
Production data backed up
JobzMall performs daily backups of in-scope production data. Backup copies are protected and maintained separately from active production environments according to documented retention and recovery requirements.
Firewall access restricted
The company restricts privileged access to the firewall to authorized users with a business need.
Network firewalls utilized
The company uses firewalls and configures them to prevent unauthorized access.
Network and system hardening standards maintained
The company's network and system hardening standards are documented in the Operations Security Policy and the relevant policy is reviewed at least annually.
Unique production infrastructure authentication enforced
The company requires authentication to production datastores to use authorized secure authentication mechanisms, such as unique SSH key.
Production data backup procedures in place
The company's data backup policy documents requirements for backup and recovery of customer data.
Inventory of production assets maintained
The company maintains a formal inventory of production system assets.
Network segmentation implemented
The company's network is segmented to prevent unauthorized access to customer data.
Business Continuity and Disaster Recovery Plans in place
The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel.
Business Continuity and Disaster Recovery Plans tested
The company has a documented business continuity/disaster recovery (BC/DR) plan and tests it at least annually.
Operations
Vulnerabilities scanned and remediated
Host-based vulnerability scans are performed at least quarterly on all external-facing systems. Critical and high vulnerabilities are tracked to remediation.
Vulnerability and system monitoring procedures established
The company's formal policies outline the requirements for the following functions related to IT / Engineering:
- vulnerability management;
- system monitoring.
Penetration testing performed
The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities.
Anti-malware technology deployed
The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems.
Incident response plan tested
The company tests their incident response plan at least annually.
Incident response plan in place
The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.
Security incident management procedures followed
The company's security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management according to the company's security incident response policy and procedures.
Log management utilized
The company utilizes a log management tool to identify events that may have a potential impact on the company's ability to achieve its security objectives.
Production code changes reviewed
Changes to production code are version-controlled and require peer review and approval before deployment. Branch protections are used to prevent unauthorized or unreviewed changes.
Automated testing performed
Production changes are subject to automated security, dependency, and functional testing before deployment. Failed required checks prevent the change from progressing through the standard deployment process.
Access Controls
Access control procedures in place
The company's access control policy documents the requirements for the following access control functions:
- adding new users;
- modifying users; and/or
- removing an existing user's access.
Access reviews conducted
JobzMall reviews access to in-scope applications and systems at least quarterly. Required access changes are documented and tracked to completion.
Access revoked upon termination
The company completes termination checklists to ensure that access is revoked for terminated employees within SLAs.
Access requests required
The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned.
Remote access MFA enforced
The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
Password policy enforced
The company requires passwords for in-scope system components to be configured according to the company's policy.
Production application access restricted
System access restricted to authorized access only.
Physical access processes established
The company has processes in place for granting, changing, and terminating physical access to company data centers based on an authorization from control owners.
Third Parties & Communication
Vendor management program established
The company has a vendor management program in place. Components of this program include:
- critical third-party vendor inventory;
- vendor's security and privacy requirements; and
- review of critical third-party vendors at least annually.
Third-party agreements established
The company has written agreements in place with vendors and related third-parties. These agreements include confidentiality and privacy commitments applicable to that entity.
System changes externally communicated
The company notifies customers of critical system changes that may affect their processing.
Support system in place
The company has an external-facing support system in place that allows users to report system information on failures, incidents, concerns, and other complaints to appropriate personnel.
Service description communicated
The company provides a description of its products and services to internal and external users.
System changes communicated
The company communicates system changes to authorized internal users.
Data and Privacy
Data retention procedures maintained
JobzMall retains personal information and customer data according to documented retention requirements based on the data type, processing purpose, account status, contractual commitments, and applicable legal, security, and fraud-prevention needs. Information is deleted or de-identified when it is no longer required, subject to approved exceptions and backup-retention schedules.
Customer data classification policy in place
The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel.
Customer data deletion procedures in place
The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service.
Customer data encrypted in transit
The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
Customer data encrypted at rest
The company's datastores housing sensitive customer data are encrypted at rest.
Encryption key access restricted
The company restricts privileged access to encryption keys to authorized users with a business need.
Organizational & Risk
Security policies established and reviewed
The company's information security policies and procedures are documented and reviewed at least annually.
Information security roles and responsibilities specified
Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in job descriptions and/or the Roles and Responsibilities policy.
Risk management program established
The company has a documented risk management program in place that includes guidance on the identification of potential threats, rating the significance of the risks associated with the identified threats, and mitigation strategies for those risks.
Risk assessment objectives specified
The company specifies its objectives to enable the identification and assessment of risk related to the objectives.
Risks assessments performed
The company's risk assessments are performed at least annually. As part of this process, threats and changes (environmental, regulatory, and technological) to service commitments are identified and the risks are formally assessed. The risk assessment includes a consideration of the potential for fraud and how fraud may impact the achievement of objectives.
Security awareness training implemented
The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.
Employee background checks performed
The company performs background checks on new employees.