Security
Employee Pooling values our customers’ trust and confidence in our business processing services for all our clients, partners, and stakeholders, including insurance carriers, distributors, and related financial institutions. Recognizing the importance of safeguarding information on behalf of our customers, we are committed to investing the resources and expertise necessary to promote a “culture of security” across our firm.
Organizational Controls
Strategic program and organizational controls
- Executive support and direction
- Documented policy framework
- Risk-based decision making
- Dedicated budget
- Internal and external expertise
- Defined responsibilities and accountabilities
- Key performance metrics
- Routine audits and reviews
- Cyber liability coverage
People Controls
People-centered controls necessary to guide ethical, lawful and “security-minded” behaviors at all levels of the organization.
- Culture of ethics and compliance
- Documented operating procedures
- Background screening
- Non-disclosure agreements
- Ongoing monitoring and supervision
- Fair and consistent enforcement
- Security-focused training and awareness
Physical Controls
Physical and environmental controls necessary to safeguard facilities and computing assets from damage or destruction.
- Restricted facilities entry/exit
- 24/7 CCTV monitoring
- Shredding containers
- Clear desk requirements
- Strict prohibitions on personal devices
- Secure data center
- Backup power generation
Technological Controls
The detective, preventative and corrective controls necessary to safeguard information and information systems.
- Cloud-based infrastructure
- Strong identity and access controls
- Encrypted messaging and storage
- System logging and monitoring
- Configurations and patch management
- Internet filtering