CCM in the Cloud (Harmony's communication platform) has been running to the full satisfaction of various customers for several years. The focus here is not only on the functionality offered, but safety is also just as important a factor. How do you ensure that your platform remains workable, but also meets strict security requirements? Koos Wijdenes (Harmony's Security & Privacy Officer) gives you insight into the various components that together provide an optimally secured CCM in the Cloud platform.
Architecture
Harmony has designed an architecture that covers functionality while also meeting the necessary security principles. This architecture has been tested by Harmony's Security Officer and by an external party that specializes in securing Cloud solutions. This external review took place in a few sessions. First, to properly understand what the functionalities of CCM are, then to test the actual security with the help of a penetration test. This penetration test has gone through several phases:
The “black box” test: the external party has no access to the CCM platform and tries to penetrate by taking advantage of possible vulnerabilities.
The “white box” test: the external party tests whether authorizations obtained (similar to authorizations received by customers or supporting parties) allow access to parts of the platform that were not authorized.
These intensive tests are repeated annually and any recommendations or findings are addressed or remedied by Harmony.
Information Security Management System (ISMS)
Harmony has an information security management system (ISMS), not only for CCM but for all management services. With the help of this ISMS, the management supervises and controls its proper functioning. This means that:
- information security policies and procedures in accordance with ISO27001 are defined
- these are operationally invested with those responsible
- a quarterly assessment by the management takes place to determine whether the goals of information security have been achieved
- an internal audit takes place annually.
In doing so, Harmony goes through the Plan-Do-Check-Act cycle on a frequent basis and ensures continuous improvement in the field of information security.
ISO27001 Certification
As of 2019, Harmony's ISMS is ISO27001 certified. An independent external auditor annually assesses whether Harmony's ISMS meets all requirements. The ISMS and also the 114 measures in the Annex to ISO27001 (Annex A) will then be reviewed. By certifying, the ISO27001 auditor makes a statement that the ISMS meets the requirements.
ISAE3000 Assurance statement CCM
In 2022, CCM will go further than just ISO27001 certification. The 50 main measures in the annex to ISO27001 are subject to an annual audit by an auditor who assesses the design, existence and functioning of the measures specific to CCM. At a ISAE3000 audit is reviewed over a period (calendar year) of whether CCM has complied with its own measures. This is done with intensive partial observation that provides a real reflection of what has taken place. This allows Harmony to give its customers the certainty (“Assurance”) that the processing by CCM takes place in a safe manner.
Would like to know more about what our CCM in the Cloud can do a solution for you? Then feel free to contact with us.