Security at Rasa

Security at Rasa

Introduction

We are a mid-sized company serving some of the world's largest brands. This means that every single one of us takes our security responsibilities seriously.

When it comes to information security, we combine the approach of defence in depth as well as Kerckhoff’s Principle (which states that a cryptosystem should be secure, even if everything about the system, except the key, is public knowledge). That is to say that, we believe information security is a broad domain that requires multiple approaches but it should be transparent and straightforward.

We have put together this page to provide information on the security controls we put in place in an effort to achieve confidentiality, integrity and availability of our information assets. Should you require further information, please don’t hesitate to reach out to us at security@rasa.com

Although our controls are aligned with the requirements of ISO 27002, we have broken down the sections below to align with the ISO 27001 domains to allow for our customers and prospects to easily cross reference with their requirements as well as demonstrate our commitment to implementing industry best practices across our organization.

Information Security Policies

Objective: To ensure that our information security policies align with the needs of our organization.

Controls: We have implemented certain information security policies here at Rasa. These information security policies help us define our usage of systems/applications and are regularly reviewed and updated with a frequency no less than once a year. The policies include:

Organization of Information Security

Objective: To ensure the management and implementation of our information security controls aligns the needs of the organization.

Controls: Information security roles and responsibilities are defined, documented and have been communicated across the organization. Everyone at Rasa is fully committed to their role and embraces honest and transparent conversations when it comes to security.

Human Resources Security

Objective: To ensure that all employees (full-time, part-time and contract) understand their requirements before, during and after their term of employment. This includes conducting background checks, adhering to information security policies and attending necessary training.

Controls: All employee contracts include:

Furthermore, employee screening such background checks and other checks are done for employees that meet the required criteria in accordance with the law.

We have also implemented a Security Awareness Program to provide regular security training in the form of digests, lunch and learns, technical training, etc.

Asset Management

Objective: To identify, classify and prevent the disclosure of Rasa’s information and assets.

Controls: Asset management is one of the most important and fundamental controls when it comes to information security. We understand this at Rasa and have put together an asset register with key information on the assets and their owners. This is regularly reviewed and updated.

Some key things to note:

Access Control

Objective: To prevent the unauthorized disclosure of information and ensure non-repudiation.

Control:

Cryptography

Objective: To maintain confidentiality, integrity and authenticity of critical assets through encryption and key management.

Controls:

Physical and Environmental Security

Objective: To prevent unauthorized access to information that may cause loss or interruption to operations.

Controls: As we are a fully remote company, we do not have offices that are used daily. We do have an office site that can be used from time to time. The following security measures are in place:

It is important to note that this office is a small site with limited capabilities and isn’t used frequently.

Systems Acquisition, Development and Maintenance

Objective: To ensure that information security requirements are established across the lifecycle of information systems and included when updating existing systems or implementing new systems.

Controls: We have implemented an Application Security policy that provides guidelines for:

Some key things to note:

Supplier Relationships

Objective: To ensure that any valuable Rasa assets that can be accessed by suppliers remain protected, and maintain the required level of information security.

Controls: When onboarding new suppliers, the security team performs a vendor risk assessment. This is done by first collating relevant information from the vendors through the completion of the following:

Information Security Incident Management

Objective: To ensure that information security incidents are managed effectively and consistently.

Controls: We have defined and implemented a detailed security incident management process. The process includes a detailed plan of action that includes detection and analysis steps, incident prioritization, communication, notification, and escalation. It also includes a detailed containment strategy, direction on evidence handling and crisis management. A copy can be provided on request.

Some key things to note:

Business Continuity Planning

Objective: To ensure the continuation of information security in respect to our Business Continuity/Disaster Recovery (BC/DR) plans.

Controls: We have implemented a Business Continuity and Disaster Recovery (BC/DR) plan. During the implementation, we performed a business impact assessment and identified key risk areas as well as key stakeholders. All relevant parties have been notified of their roles and responsibilities within the plan and a communication plan has been devised and disseminated accordingly.

Some key things to note:

Compliance

Objective: To avoid information security breaches of a legal, statutory, regulatory or contractual nature and ensure that information security is carried out according to Rasa’s needs.

Controls: We have worked to ensure our security controls are aligned with ISO 27002 and we apply industry best practices wherever applicable. We are always happy to provide evidence to the case, on any controls relevant to us. Just reach out!

Responsible Disclosure

Security is an ongoing process and we are always looking for ways to improve so feedback is really important to us. Although we do not have a monetary bug bounty program in place, we do have a

responsible disclosure policy. Please review and feel free to reach out to us if you have any further questions.

Questions?

Contact security@rasa.com or visit rasa.com for more information.