# Happeo

Happeo is the leading AI-powered intranet platform that connects people, knowledge, and tools all in one place. Trusted by companies like Rayonier, Gant, and Neste, Happeo helps organizations improve collaboration, streamline internal communication, and make knowledge easy to find.

Founded in 2017, Happeo serves hundreds of customers across borders and industries, with offices in New York, USA, Helsinki, Finland, Amsterdam, The Netherlands and Cluj, Romania.

## Controls

Updated 8 minutes ago

### Infrastructure security

| Control | Status |
| --- | --- |
| Information security for use of cloud services<br>Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements. |  |
| Protecting against physical and environmental threats<br>Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented. |  |
| Information deletion<br>Information stored in information systems, devices or in any other storage media shall be deleted when no longer required. |  |
| Data masking<br>Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration. |  |
| Data leakage prevention<br>Data leakage prevention measures shall be applied to systems, networks and any other devices that process, store or transmit sensitive information. |  |
| Information backup<br>Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup. |  |
| Monitoring activities<br>Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents. |  |
| Clock synchronization<br>The clocks of information processing systems used by the organization shall be synchronized to approved time sources. |  |
| Use of privileged utility programs<br>The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled. |  |
| Installation of software on operational systems<br>Procedures and measures shall be implemented to securely manage software installation on operational systems. |  |

### Organizational security

| Control | Status |
| --- | --- |
| Return of assets<br>Personnel and other interested parties as appropriate shall return all the organization’s assets in their possession upon change or termination of their employment, contract or agreement. |  |
| Intellectual property rights<br>The organization shall implement appropriate procedures to protect intellectual property rights. |  |
| Security of assets off-premises<br>Off-site assets shall be protected. |  |
| Storage media<br>Storage media shall be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organization’s classification scheme and handling requirements. |  |
| Redundancy of information processing facilities<br>Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements. |  |
| Capacity management<br>The use of resources shall be monitored and adjusted in line with current and expected capacity requirements. |  |
| Internal Audit Program<br>The organization shall plan, establish, implement and maintain an audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.<br>When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits.<br>The organization shall:<br>a) define the audit criteria and scope for each audit;<br>b) select auditors and conduct audits that ensure objectivity and the impartiality of the audit process;<br>c) ensure that the results of the audits are reported to relevant management;<br>Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results. |  |
| Legal, statutory, regulatory and contractual requirements<br>Legal, statutory, regulatory and contractual requirements relevant to information security and the organization’s approach to meet these requirements shall be identified, documented and kept up to date. |  |
| Independent review of information security<br>The organization’s approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur. |  |
| Information transfer<br>Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties. |  |

### Product security

| Control | Status |
| --- | --- |
| Secure disposal or re-use of equipment<br>Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use. |  |
| Access to source code<br>Read and write access to source code, development tools and software libraries shall be appropriately managed. |  |
| Secure coding<br>Secure coding principles shall be applied to software development. |  |
| Separation of development, test and production environments<br>Development, testing and production environments shall be separated and secured. |  |
| Information security in supplier relationships<br>Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier’s products or services. |  |
| Managing information security in the ICT supply chain<br>Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain. |  |

### Internal security procedures

| Control | Status |
| --- | --- |
| ICT readiness for business continuity<br>ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements. |  |
| Acceptable use of information and other associated assets<br>Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented. |  |
| Documented operating procedures<br>Operating procedures for information processing facilities shall be documented and made available to personnel who need them. |  |
| Disciplinary process<br>A disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation |  |
| Response to information security incidents<br>Information security incidents shall be responded to in accordance with the documented procedures. |  |
| Learning from information security incidents<br>Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls. |  |
| Security testing in development and acceptance<br>Security testing processes shall be defined and implemented in the development life cycle. |  |

### Data and privacy

| Control | Status |
| --- | --- |
| Equipment maintenance<br>Equipment shall be maintained correctly to ensure availability, integrity and confidentiality of information. |  |
| Cabling security<br>Cables carrying power, data or supporting information services shall be protected from interception, interference or damage. |  |
