Security

Revell Research Systems takes security very seriously. We have established a robust approach, implementing good governance underpinned by a range of management and technical measures to keep all of our stakeholders safe when they engage with us.

We set out below the security measures that we have implemented to keep you safe when interacting with us.

We may update these security measures at any time as part of our commitment to continuous improvement but any modifications that we do make will not result in the degradation of the overall security of the services we provide.

Revell Research Systems operates an Information Security Policy Framework that sets out how we manage our information security. We also have formal policies that cover risk management across the business.

Our policies are approved by the Board of Directors and are all formally reviewed at least annually.

We communicate these policies internally to all our staff and associates and actively monitor compliance.

We train those working for us and regularly check security behaviour across the business. We conduct annual training, which starts when anyone joins us to ensure everyone knows their responsibilities.

Our Service Desk operates a robust security incident management process that is designed to quickly investigate and respond to security incidents.

We will inform you if your personal identifiable information is impacted by a data breach and provide you with details of the incident, where appropriate.

We maintain asset registers for data repositories, devices, systems and software so we know exactly what we must protect and what is at stake.

In particular, we carefully track where personal identifiable information is stored and used across our information assets.

We conduct regular information risk assessments to identify risks and to assess the likelihood and impact of them materialising. We take active steps to mitigate these information security risks so that we can maintain the confidentiality, integrity and availability of our information assets.

The status of our information security risks are regularly reported to the Board of Directors and senior management.

We control our IT systems carefully. We patch our systems regularly to remove known vulnerabilities and reduce the threat to them. We implement careful change control to minimise the risks associated with updates to our IT systems, data and business.

We carefully control access to our premises and ensure appropriate levels of physical security, monitoring and detection are in place. We regularly test our intruder detection and fire alarm measures.

Visitor access to our premises is controlled. Visitors are accompanied at all times.

We position our equipment within our premises to minimise the visibility of confidential information and instruct staff and associates to take particular care of mobile devices such as laptops, tablets and phones when they are being used in public spaces.

We require staff and associates to obtain permission from asset owners prior to removing equipment from our premises. We also instruct them to keep mobile equipment secure at all times and to be vigilant about the inherent risks of using mobile equipment outside of the office.

We encrypt data whenever we perceive it is at risk.

We record all physical hardware assets in asset registers. These are kept up-to-date by asset owners, who are responsible for ensuring the accuracy of the information stored about each asset.

We require staff and associates to operate a clear desk policy and lock any confidential information away when not at their desks.

We also require our staff and associates to lock their systems when they are away from them.

We exercise careful access control to prevent unauthorised people from gaining access to our systems to ensure that data cannot be read, copied, altered or removed without authorisation. This includes any personal data that we may process.

We only grant the minimum permissions needed to staff and associates for them to perform their work.

We audit and actively monitor access to information assets.

We also control access to software development environments and ensure that only staff and associates who need access to them are authorised to do so.

We require the use of unique user credentials and strong passwords when using our systems. We use two factor authentication to protect critical systems to minimize the potential for unauthorised access.

We store user credentials in highly secure password management systems that audit access and use of credentials.

We protect our systems with anti-virus software and anti-malware tools that are configured to automatically update, monitor and scan for threats. We enforce their use on servers and all user devices. We scan all files and email content crossing our system boundaries, quarantining or deleting items as appropriate.

We also use an anti-spam system that blocks or quarantines suspicious email.

We implement a sophisticated firewall solution that blocks unwanted ingress traffic and protects against unexpected egress traffic as well as inspecting content, where appropriate.

We also operate intrusion detection systems and actively monitor hosts trying to connect to our systems. We actively log traffic activity.

We regularly scan our systems for known vulnerabilities and conduct routine testing of our security measures.

We periodically commission external tests of our defences to ensure we maintain the highest security standards possible.

We have emergency and business continuity plans in place to help overcome any unexpected incidents at our premises, to key personnel or to any important systems that we rely on for day to day to operations. The plans are designed to enable us to resume activities whether the situation is one of full or partial loss of key assets.

We make all our staff and associates aware of the plan in their induction and subsequent refresher training. If there are any significant changes to the plan, we communicate these changes to them.

We are registered with the Information Commissioner's Office (ICO) under Notification Number Z186392X.

We are actively seeking accreditation against external standards that we believe we conform to.