Governance (domain 1)
Policies, roles, risk management and periodic review. We document the technical controls behind them and supply the inputs to your risk register.
Defense (domain 2)
Identity and access management with MFA for remote access and privileged accounts, email and network protection, patching, backup, logging and monitoring.
Resilience (domain 3)
Backup, recovery and continuity arrangements that are tested, with the records to prove it.
Third parties (4-1)
Contract terms, pre-contract risk assessment and periodic review. Where a managed cybersecurity service is delivered remotely, ECC requires the monitoring and operations centre to be fully in the Kingdom (4-1-3-2). We tell you where each service is delivered from.
Cloud and hosting (4-2)
Cloud requirements identified, approved and implemented, with data classification driving what goes where.
Assessment and audit
A standing evidence pack for self-assessment, compliance-tool reporting and audit, with independent review scheduled under control 1-8.