Technical and Organisational Measures (TOMS)

Terms last updated: May 2025.

Purpose: To define the technical and organisational measures implemented to protect personal data in line with GDPR Article 32, ISO 27001, Cyber Essentials Plus, and NCSC guidance.

1. Access Control

Authentication

MFA is enforced for all administrative and remote access accounts. Unique credentials are assigned to all users.

Authorisation

Access is granted on a least privilege basis and reviewed quarterly. Role-based access controls (RBAC) are in place.

User Account Management

Joiners, movers, and leavers processes are enforced. Dormant accounts are disabled after 30 days.

2. Physical and Environmental Security

Physical Access

Offices and data centres use badge entry systems. Visitor access is logged and supervised.

Environmental Controls

Data centres have fire suppression systems, climate control, and UPS-backed power supplies.

Device Security

All company-issued devices are encrypted and asset-tracked. USB ports are restricted by policy.

 

3. Network Security

Firewalls

Hardware and software firewalls are configured with default-deny policies. External exposure is minimised.

Segmentation

Network zones separate internal systems, external-facing services, and critical infrastructure.

Monitoring

Intrusion detection and prevention systems (IDS/IPS) are in place. Network traffic is logged and monitored.

4. Endpoint Security

Anti-malware

All endpoints run centrally managed anti-malware with real-time protection and automatic updates.

Patch Management

Critical security patches are applied within 14 days. Automated patching is used for OS and apps.

Secure Configuration

Devices are hardened using CIS benchmarks and checked periodically using automated tools.

5. Encryption and Data Protection

Data at Rest

Encryption using AES-256 is enforced for all storage devices and databases.

Data in Transit

TLS 1.2+ is enforced for all external and internal communications.

Backups

Encrypted, segregated backups are taken daily, tested monthly, and retained per retention policy.

6. Monitoring, Logging and Alerting

Log Collection

Centralised logging (e.g., SIEM) is in place for servers, endpoints, and security devices.

Alerting

Real-time alerts for suspicious activity. Incident thresholds and escalation procedures are defined.

Audit Trails

Logs are retained for 12 months minimum and reviewed regularly for anomalies.

7. Vulnerability and Threat Management

Penetration Testing

Annual independent penetration testing is conducted (Cyber Essentials Plus certified).

Vulnerability Scanning

Weekly automated scans of systems and dependencies. Remediation tracked via ticketing system.

Threat Intelligence

Subscribed to trusted feeds (e.g., NCSC, NIST). IOC feeds inform automated and manual actions.

8. Incident Response

Response Plan

A tested incident response plan is in place, aligned with NCSC’s guidance and ISO27001:2013

Breach Notification

Personal data breach procedures meet GDPR Article 33/34 requirements (72-hour window).

Team Training

Incident response team is trained and exercises tabletop simulations quarterly.

9. Organisational Measures

Policies

Data Protection, Acceptable Use, Remote Work, and Information Security policies are enforced.

Training

Mandatory annual training on cybersecurity and data protection for all employees.

Governance

Information Security Officer appointed. Governance structure aligns with ISO 27001 clauses.

Supplier Management

Supplier risk assessments and data processing agreements (DPAs) are maintained.

10. Risk Management and Compliance

Risk Assessment

Annual ISO 27001-compliant risk assessments conducted. Controls tracked in a risk register.

DPIAs

Required for high-risk processing activities. Templates and guidance follow ICO recommendations.

Audit and Review

Quarterly internal audits. External ISO 27001 and Cyber Essentials Plus audits annually.

Alignment Summary

Framework and Coverage

GDPR (Art. 32)

Full coverage through documented security controls, risk management, and breach response

ISO 27001:2013

Orbis Protect is certified to ISO27001 by Alcumus ISOQAR, Certificate Number: 1209-ISMS-012, Renewal Date 10/08/2025

Cyber Essentials Plus

Orbis Protect is certified to Cyber Essentials by Periculo,  bd4ec673-3754-4c68-8777-1e9de54a19e2, Renewal 24/10/2025

NCSC

Aligned with NCSC’s 10 Steps to Cyber Security and Cloud Security Principles, and certified via alignment to the controls under ISO27001 and Cyber Essentials Plus