Access Control Policy
We are committed to robust access control, ensuring that access to our systems, data, and resources is carefully managed and protected. We have a documented Access Control Policy that outlines the procedures for granting, managing, and revoking access, including for elevated privileges, employee transfers, temporary access, and emergency situations. Our approach includes the use of Role-Based Access Control (RBAC) for both institutional accounts and internal staff, with automated provisioning handled by Okta. We also conduct quarterly reviews of access lists for privileged accounts to maintain security.
Asset Management Policy
Data Classification Policy
We have a robust Data Classification and Handling Policy that outlines how we categorize and protect company, employee, and customer data based on its sensitivity and criticality. This policy provides clear guidance to our personnel on appropriate data management and protection, ensuring all data processed, transmitted, or stored on our systems is handled securely. Our Director of Security enforces this policy through periodic audits, and our Security Committee reviews and updates it annually to align with evolving requirements.
Information Security Policy
We are deeply committed to protecting our information assets and maintaining a secure environment for our customers. We achieve this through a comprehensive Information Security Policy, which serves as the overarching framework for all our security policies and procedures. This policy is regularly evaluated and approved by our Director of Security to ensure it remains robust and aligned with evolving security landscapes.
Network Security Policy
Secure Software Development Policy
We have a documented Software Development Lifecycle (SDLC) Policy that guides our entire software development process. This policy ensures that information security principles are integrated throughout the product lifecycle. Our change management process is meticulously planned, authorized, and supported by documentation, testing, and reviews to minimize risks.
Backup Policy
Backups are encrypted and access is restricted to authorized personnel. We also regularly test and validate our Business Continuity and Disaster Recovery Plans, which include our backup and recovery strategies, at least once a year to ensure their effectiveness.
Change Management Policy
We have a formal Change Management Policy that outlines our established plans and procedures for overseeing and controlling modifications to our infrastructure, systems, and applications. This structured approach ensures that every code modification is streamlined, purposeful, and carries minimal risks and disruptions. We meticulously plan every proposed change to ensure it is prioritized, authorized, documented, tested, reviewed, and includes version annotations and rollback strategies if needed. Our JIRA system employs workflows to ensure precision and seamless execution of these processes.
Data Retention Policy
Incident Response Policy
Password Policy
We prioritize the security of user accounts by implementing a robust password policy. We utilize a password manager application to securely store and manage user credentials in an encrypted database. Our approach is further strengthened by requiring Single Sign-On (SSO) and Multi-Factor Authentication (MFA) for production systems and accounts, where feasible. We also enforce strong password requirements, including minimum length, complexity, and regular expiration for systems not using SSO/MFA.
Physical Security Policy
We are deeply committed to physical security, which is a critical component of protecting our facilities, assets, and personnel from unauthorized access, damage, or theft. We implement and enforce stringent physical security measures, including annual Security Awareness sessions for all personnel. Our digital landscape is protected by security protocols, and we partner with AWS, our cloud service provider, for the physical and foundational cloud security of our operations.
Risk Assessment/Management Policy
We have a comprehensive Risk Management Policy and a structured framework to identify, evaluate, and mitigate potential risks to our operations, assets, and information. We conduct annual risk assessments and quarterly risk evaluations to maintain constant vigilance against evolving threats, ensuring prompt mitigation of identified vulnerabilities. Our approach integrates policies like Vendor Management and Vulnerability Management to proactively address risks and ensure the integrity and resilience of our operations.
Vendor Management Policy
We have a documented Vendor Management Policy that details our due diligence process for managing vendors, their access to customer data, and their impact on security, availability, confidentiality, and privacy. We perform security assessments of third-party companies with which we share data. We also use tools like Bitsight and other vendor management tools to track, assess, and follow up with our third parties.
Vulnerability Management Policy
We have a comprehensive Vulnerability Management Policy that systematically identifies, assesses, and remediates security weaknesses within our systems and applications. This policy is integrated into our robust risk assessment process, allowing us to anticipate, evaluate, and respond to potential risks effectively. Our dedicated security team, which includes a Vulnerability Management Analyst, continuously monitors and evaluates our controls to ensure their efficacy and relevance.
Was this article helpful?
Articles in this section
- App security
- Data handling & security controls for BioRender Graphing
- Compliance documents (SOC 2 Type 2, VPAT, SOC 3)
- BioRender's data policies
- Data privacy & security at BioRender
- BioRender's AI security controls
- Infrastructure at BioRender: BioRender AWS hosting
- Access control
- BioRender's employee training policy
- BioRender's endpoint security