Security governance
This page describes how the security of the service is organised: who is accountable for it, how access is managed, how an incident is handled. It contains no certification, audit or availability commitment that has not been established.
- Technical and organisational measures deployed, with their scope.
- Existing audits and attestations: nature, scope, auditor, date, validity.
- Documented incident procedure and applicable notification time limits.
- Vulnerability reporting channel and handling arrangements.
- Hosting and location of processing, subcontractors concerned.
This block is visible in internal review only. No working text appears on published pages.
Governance
Security is the responsibility of an identified function within the entity, with periodic reviews and a risk assessment specific to the activity. The corresponding elements are presented in the documentation file, with their scope and date.
Access management
Access to systems and data is granted according to role, reviewed and logged. The rights matrix applicable to a programme is settled at the scoping stage.
Monitoring and incidents
An incident follows a procedure: qualification, handling, informing the parties concerned, lessons learned. The applicable notification time limits are those provided for by the regulations and by the contract, not a general commercial commitment.