Technical and Organisational Measures (TOMS)
Terms last updated: May 2025.
Purpose: To define the technical and organisational measures implemented to protect personal data in line with GDPR Article 32, ISO 27001, Cyber Essentials Plus, and NCSC guidance.
1. Access Control
Authentication
MFA is enforced for all administrative and remote access accounts. Unique credentials are assigned to all users.
Authorisation
Access is granted on a least privilege basis and reviewed quarterly. Role-based access controls (RBAC) are in place.
User Account Management
Joiners, movers, and leavers processes are enforced. Dormant accounts are disabled after 30 days.
2. Physical and Environmental Security
Physical Access
Offices and data centres use badge entry systems. Visitor access is logged and supervised.
Environmental Controls
Data centres have fire suppression systems, climate control, and UPS-backed power supplies.
Device Security
All company-issued devices are encrypted and asset-tracked. USB ports are restricted by policy.
3. Network Security
Firewalls
Hardware and software firewalls are configured with default-deny policies. External exposure is minimised.
Segmentation
Network zones separate internal systems, external-facing services, and critical infrastructure.
Monitoring
Intrusion detection and prevention systems (IDS/IPS) are in place. Network traffic is logged and monitored.
4. Endpoint Security
Anti-malware
All endpoints run centrally managed anti-malware with real-time protection and automatic updates.
Patch Management
Critical security patches are applied within 14 days. Automated patching is used for OS and apps.
Secure Configuration
Devices are hardened using CIS benchmarks and checked periodically using automated tools.
5. Encryption and Data Protection
Data at Rest
Encryption using AES-256 is enforced for all storage devices and databases.
Data in Transit
TLS 1.2+ is enforced for all external and internal communications.
Backups
Encrypted, segregated backups are taken daily, tested monthly, and retained per retention policy.
6. Monitoring, Logging and Alerting
Log Collection
Centralised logging (e.g., SIEM) is in place for servers, endpoints, and security devices.
Alerting
Real-time alerts for suspicious activity. Incident thresholds and escalation procedures are defined.
Audit Trails
Logs are retained for 12 months minimum and reviewed regularly for anomalies.
7. Vulnerability and Threat Management
Penetration Testing
Annual independent penetration testing is conducted (Cyber Essentials Plus certified).
Vulnerability Scanning
Weekly automated scans of systems and dependencies. Remediation tracked via ticketing system.
Threat Intelligence
Subscribed to trusted feeds (e.g., NCSC, NIST). IOC feeds inform automated and manual actions.
8. Incident Response
Response Plan
A tested incident response plan is in place, aligned with NCSC’s guidance and ISO27001:2013
Breach Notification
Personal data breach procedures meet GDPR Article 33/34 requirements (72-hour window).
Team Training
Incident response team is trained and exercises tabletop simulations quarterly.
9. Organisational Measures
Policies
Data Protection, Acceptable Use, Remote Work, and Information Security policies are enforced.
Training
Mandatory annual training on cybersecurity and data protection for all employees.
Governance
Information Security Officer appointed. Governance structure aligns with ISO 27001 clauses.
Supplier Management
Supplier risk assessments and data processing agreements (DPAs) are maintained.
10. Risk Management and Compliance
Risk Assessment
Annual ISO 27001-compliant risk assessments conducted. Controls tracked in a risk register.
DPIAs
Required for high-risk processing activities. Templates and guidance follow ICO recommendations.
Audit and Review
Quarterly internal audits. External ISO 27001 and Cyber Essentials Plus audits annually.
Alignment Summary
Framework and Coverage
GDPR (Art. 32)
Full coverage through documented security controls, risk management, and breach response
ISO 27001:2013
Orbis Protect is certified to ISO27001 by Alcumus ISOQAR, Certificate Number: 1209-ISMS-012, Renewal Date 10/08/2025
Cyber Essentials Plus
Orbis Protect is certified to Cyber Essentials by Periculo, bd4ec673-3754-4c68-8777-1e9de54a19e2, Renewal 24/10/2025
NCSC
Aligned with NCSC’s 10 Steps to Cyber Security and Cloud Security Principles, and certified via alignment to the controls under ISO27001 and Cyber Essentials Plus