Technical & Organisational Measures
Introduction
This document describes the technical and organisational security measures Oxford Economics implement to protect personally identifiable information. Oxford Economics operates with security by design, focusing on Confidentially, Availability, Integrity and Privacy. Oxford Economics reserves the right to revise our technical and organisational measures at any time, providing it does not reduce or weaken the protection provided.
Measures
The organisation will use the following measures to protect personal data:
-
Access Control
- Principle of Least Privilege
- Access control systems (access card/access code)
Identity cards
Procedure for visitors (staff must accompany visitors at all times & complete the visitor log)
CCTV for sensitive areas
Secured entrance
Security desk
Occupied Reception desk
Locked cabinets sorting personal or sensitive data
-
Authentication & Authorisation Controls
Unique User Accounts
Access only upon successful login
Role-based permissions
Licence-controlled environments
Regular password change policy
Behaviour Analysis (unusual location detection, risk assessment, conditional access policies)
Multi-factor Authentication
Standardisation of security systems (e.g. using SAML SSO authentication where possible)
Automatic inactivity lockout
Automatic account blocking after a defined number of unsuccessful logins
Password complexity requirements
Periodic log analysis
-
Integrity Controls
Separation of duties
Separation of testing, staging and production environments
Linking records for specific purposes
Anonymisation or Pseudonymisation of personal data where possible
Read-only automated log management
Quarterly vendor account reviews
Data validation rules
Intercompany sub-processing agreements
Secure data erasure and disposal
Use of corporate devices to make and receive business calls
-
Technical Controls
-
Enterprise Firewalls
Advanced Malware Protection systems
Intrusion Prevention Systems
Content Filtering
Layer 7 Packet Inspection
SD-WAN
SSL VPN
Site-to-Site VPN
-
Endpoint Protection
Firewall
On-access scanning
Signature-less detection (Machine Learning)
Web Threat Protection
Ransomware Mitigation
Automatic Disinfection and Removal
Device Control
-
Email Security
Inbound protection
Internal protection
Outbound protection
Data Loss Prevention
URL Sandbox/rewrite
Attachment Sandbox
AI Threat Detection
-
Automated Vulnerability and penetration testing
Monthly Vulnerability testing
Half-yearly Penetration testing
-
Centralised Device Management
Active Directory
Group Policy
Mobile Device Management
High Availability
Fault Tolerance
-
Data Controls
Logical separation of data assets
Encryption in transit
Encryption at rest
Data Classification measures and policy
Data Loss Prevention systems
Data lifecycle procedure (Live, Cold, Archive)
Shared responsibility model with clients
-
Contractual vendor requirements
Only have access to data required to fulfil the contractual requirements
Must have the same or better security measures in place
Employees must not have access to our environment
-
Availability Controls
- Multisite replication
Off-site/Offline backup
Use of uninterrupted power supplies (UPS)
Storage systems with redundancy
Formal backup, recovery, business continuity and disaster recovery processes
Change Management Process
Monthly Technical Board (review impending changes from vendors)
Cloud-Centric Environment
-
Privacy Management
Annual and Ad-hoc Staff Awareness Training
Online Training
Monthly Awareness campaigns (IT Newsletter)
Evaluation and preparation of upcoming legislations
Staff Contractual Non-Disclosure Agreements
Clear Desk Policy
Prohibiting the sharing of passwords
Unusual behaviour alerting (unsuccessful login, login from unknown location)
Designated Data Protection Officer
-
Accreditations
ISO 27001:2022
Cyber Essentials Plus
- PCI-DSS SAQ C
Sub-Processors
General
Organisation
Purpose
Applicable Service
Location
Freshworks Inc
(Freshservice)
Technical Support Centre
Used for the technical support of prospective or existing clients
United Kingdom
Google LLC (Analytics)
Website Analytics
Used for website analytics and performance enhancement purposes
United States
Microsoft Ireland Operations Limited
(Microsoft Office365)
Communication
Used for email and instant message communication. Communication Metadata
Austria, Finland, France, Ireland, Netherlands
*Data is transported to the local computer using encryption
Mimecast Services Limited
Email Security Gateway
Used for the protection of inbound and outbound emails. Communication Metadata
United Kingdom
ON24, Inc.
Webinar Platform
Webinar platform used to deliver live and pre-recorded webinars to enrolled users.
United Kingdom
Roxhill Media Ltd
Customer Relationship
Management Database
Record Store and Email Delivery for Media
United Kingdom
Salesloft, Inc.
Sales Engagement Platform
Sales Engagement Automation Platform
United States
ZoomInfo Technologies, Inc.
Customer Relationship
Management Database
B2B Sales Platform
United States
Subscription
Organisation
Purpose
Applicable Service
Location
Amazon Web Services, Inc.
User Provisioning and Management
Used for the provisioning of users to our services and hosting of systems
United Kingdom
Okta, Inc. (Formally Auth0® Inc.)
Identity & Access Management
Used for authentication of users to our website, databanks and support platform
United States
Microsoft Ireland Operations Limited
(Azure)
User Provisioning and Management
Used for the provisioning of users to our services and hosting of systems
United Kingdom & Netherlands
OwnBackup, Inc.
Salesforce Backup Solution
Hosted backup service for Customer Relationship Management system.
United Kingdom
Content Catalyst Limited
Content Management System
Used for the hosting of subscription content
United States
Salesforce, Inc.
Customer Relationship Management Database
Data hosting provider for prospective and existing client records
United Kingdom
SAP SE
Accounts Receivable and Payable
Used to generate customer invoices and process payments
Germany
SendGrid, Inc.
Subscription Emails
Used for distribution of subscription email content
United States
Oxford Economics Sub-Processors
Organisation
Purpose
Location
BIS Oxford Economics Australia Pty. Ltd
Services & Support
Australia
Oxford Economics Africa
Services & Support
South Africa
Oxford Economics Asia Pacific & Middle East Pte. Ltd
Services & Support
Singapore
Oxford Economics Australia Pty. Ltd
Services & Support
Australia
Oxford Economics Canada Inc
Services & Support
Canada
Oxford Economics France
Services & Support
France
Oxford Economics GmbH
Services & Support
Germany
Oxford Economics Hong Kong
Services & Support
Hong Kong
Oxford Economics Japan KK
Services & Support
Japan
Oxford Economics Ltd
Services & Support
United Kingdom
Oxford Economics Mexico & Latin America
Services & Support
Mexico
Oxford Economics Middle East DMCC
Services & Support
Dubai
Oxford Economics Nordics Filial
Services & Support
Sweden
Oxford Economics SRL
Services & Support
Italy
Oxford Economics USA Inc
Services & Support
United States
Stone McCarthy Research Associates
Services & Support
United States
Tourism Economics LLC
Services & Support
United States & United Kingdom