Trust Center - Happeo

Happeo

Happeo is the leading AI-powered intranet platform that connects people, knowledge, and tools all in one place. Trusted by companies like Rayonier, Gant, and Neste, Happeo helps organizations improve collaboration, streamline internal communication, and make knowledge easy to find.

Founded in 2017, Happeo serves hundreds of customers across borders and industries, with offices in New York, USA, Helsinki, Finland, Amsterdam, The Netherlands and Cluj, Romania.

Controls

Updated 8 minutes ago

Infrastructure security

Control Status
Information security for use of cloud services
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements.
Protecting against physical and environmental threats
Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented.
Information deletion
Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.
Data masking
Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration.
Data leakage prevention
Data leakage prevention measures shall be applied to systems, networks and any other devices that process, store or transmit sensitive information.
Information backup
Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
Monitoring activities
Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
Clock synchronization
The clocks of information processing systems used by the organization shall be synchronized to approved time sources.
Use of privileged utility programs
The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
Installation of software on operational systems
Procedures and measures shall be implemented to securely manage software installation on operational systems.

Organizational security

Control Status
Return of assets
Personnel and other interested parties as appropriate shall return all the organization’s assets in their possession upon change or termination of their employment, contract or agreement.
Intellectual property rights
The organization shall implement appropriate procedures to protect intellectual property rights.
Security of assets off-premises
Off-site assets shall be protected.
Storage media
Storage media shall be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organization’s classification scheme and handling requirements.
Redundancy of information processing facilities
Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.
Capacity management
The use of resources shall be monitored and adjusted in line with current and expected capacity requirements.
Internal Audit Program
The organization shall plan, establish, implement and maintain an audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.
When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits.
The organization shall:
a) define the audit criteria and scope for each audit;
b) select auditors and conduct audits that ensure objectivity and the impartiality of the audit process;
c) ensure that the results of the audits are reported to relevant management;
Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.
Legal, statutory, regulatory and contractual requirements
Legal, statutory, regulatory and contractual requirements relevant to information security and the organization’s approach to meet these requirements shall be identified, documented and kept up to date.
Independent review of information security
The organization’s approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur.
Information transfer
Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.

Product security

Control Status
Secure disposal or re-use of equipment
Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
Access to source code
Read and write access to source code, development tools and software libraries shall be appropriately managed.
Secure coding
Secure coding principles shall be applied to software development.
Separation of development, test and production environments
Development, testing and production environments shall be separated and secured.
Information security in supplier relationships
Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.
Managing information security in the ICT supply chain
Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.

Internal security procedures

Control Status
ICT readiness for business continuity
ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.
Acceptable use of information and other associated assets
Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented.
Documented operating procedures
Operating procedures for information processing facilities shall be documented and made available to personnel who need them.
Disciplinary process
A disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation
Response to information security incidents
Information security incidents shall be responded to in accordance with the documented procedures.
Learning from information security incidents
Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls.
Security testing in development and acceptance
Security testing processes shall be defined and implemented in the development life cycle.

Data and privacy

Control Status
Equipment maintenance
Equipment shall be maintained correctly to ensure availability, integrity and confidentiality of information.
Cabling security
Cables carrying power, data or supporting information services shall be protected from interception, interference or damage.