Transparency & compliance

Our policies.

We're committed to operating responsibly and transparently. Our policies set out our commitments to the people and organisations we work with.

  • Equality and Diversity

    An equality, diversity and inclusion policy 


    SafalSolutions Ltd is committed to encouraging equality, diversity and inclusion among our workforce, and eliminating unlawful discrimination.




    The aim is for our workforce to be truly representative of all sections of society and our customers, and for each employee to feel respected and able to give their best.


    The organisation - in providing goods and/or services and/or facilities - is also committed against unlawful discrimination of customers or the public.




    Our policy’s purpose


    This policy’s purpose is to:




    1. Provide equality, fairness and respect for all in our employment, whether temporary, part-time or full-time




    2. Not unlawfully discriminate because of the Equality Act 2010 protected characteristics of:


    ·      age


    ·      disability


    ·      gender reassignment


    ·      marriage or civil partnership


    ·      pregnancy and maternity


    ·      race (including colour, nationality, and ethnic or national origin)


    ·      religion or belief


    ·      sex


    ·      sexual orientation


     


    3. Oppose and avoid all forms of unlawful discrimination. This includes in:


    ·      pay and benefits


    ·      terms and conditions of employment


    ·      dealing with grievances and discipline


    ·      dismissal


    ·      redundancy


    ·      leave for parents


    ·      requests for flexible working


    ·      selection for employment, promotion, training or other developmental opportunities




    4. We are committed to improving our practices to combat slavery and human trafficking. We recognise that slavery and human trafficking is a real yet hidden issue in our society. We will not tolerate slavery and human trafficking in our business or supply chain.






    Our commitments


    The organisation commits to:


    1. Encourage equality, diversity and inclusion in the workplace as they are good practice and make business sense



    2. Create a working environment free of bullying, harassment, victimisation and unlawful discrimination, promoting dignity and respect for all, and where individual differences and the contributions of all staff are recognised and valued.


    This commitment includes training managers and all other employees about their rights and responsibilities under the equality, diversity and inclusion policy. Responsibilities include staff conducting themselves to help the organisation provide equal opportunities in employment, and prevent bullying, harassment, victimisation and unlawful discrimination.


    All staff should understand they, as well as their employer, can be held liable for acts of bullying, harassment, victimisation and unlawful discrimination, in the course of their employment, against fellow employees, customers, suppliers and the public



    3. Take seriously complaints of bullying, harassment, victimisation and unlawful discrimination by fellow employees, customers, suppliers, visitors, the public and any others in the course of the organisation’s work activities.


    4. We are committed to improving our practices to combat slavery and human trafficking. We recognise that slavery and human trafficking is a real yet hidden issue in our society. We will not tolerate slavery and human trafficking in our business or supply chain.


    Such acts will be dealt with as misconduct under the organisation’s grievance and/or disciplinary procedures, and appropriate action will be taken. Particularly serious complaints could amount to gross misconduct and lead to dismissal without notice.


    Further, sexual harassment may amount to both an employment rights matter and a criminal matter, such as in sexual assault allegations. In addition, harassment under the Protection from Harassment Act 1997 – which is not limited to circumstances where harassment relates to a protected characteristic – is a criminal offence.



    4. Make opportunities for training, development and progress available to all staff, who will be helped and encouraged to develop their full potential, so their talents and resources can be fully utilised to maximise the efficiency of the organisation.



    5. Make decisions concerning staff being based on merit (apart from in any necessary and limited exemptions and exceptions allowed under the Equality Act).



    6. Review employment practices and procedures when necessary to ensure fairness, and also update them and the policy to take account of changes in the law.



    7. Monitor the make-up of the workforce regarding information such as age, sex, ethnic background, sexual orientation, religion or belief, and disability in encouraging equality, diversity and inclusion, and in meeting the aims and commitments set out in the equality, diversity and inclusion policy.




    8. SafalSolutions is committed to preventing slavery and human trafficking occurring in any of its corporate activities. As a membership and professional services organisation, our services are delivered to our member companies and clients. Our commitment is to ensure that those organisations that we actually contract with to receive goods and services are aware of our policies in order to comply with the Modern Slavery Act.



    Monitoring will also include assessing how the equality, diversity and inclusion policy, and any supporting action plan, are working in practice, reviewing them annually, and considering and taking action to address any issues.


    Agreement to follow this policy




    The equality, diversity and inclusion policy is fully supported by senior management and has been agreed with trade unions and/or employee representatives 



    Our disciplinary and grievance procedures


    Details of the organisation’s grievance and disciplinary policies and procedures can be found at Company sharepoint -> NLT Policies and Procedures. This includes with whom an employee should raise a grievance – usually their line manager.


    Use of the organisation’s grievance or disciplinary procedures does not affect an employee’s right to make a claim to an employment tribunal within three months of the alleged discrimination.

  • Health and Safety



     Health and Safety policy  



    Part 1: Statement of intent 


    Our health and safety policy is to:




    - prevent accidents and cases of work-related ill health


    - manage health and safety risks in our workplace


    - provide clear instructions and information, and adequate training, to ensure employees are competent to do their work


    - consult with our employees on matters affecting their health and safety


    - maintain safe and healthy working conditions


    - implement emergency procedures, including evacuation in case of fire or other significant incident


    - review and revise this policy regularly




    Part 2: Responsibilities for Health and Safety


     - Overall and final responsibility for health and safety:  Satyajit Singh




    - To ensure health and safety standards are maintained/improved, the following people have responsibility in the following areas: 




    Satyajit Singh, Ayesha Pujji – safety, risk assessments, consulting employees, accidents, first aid and work-related ill health



    Satyajit Singh– monitoring, accident and ill-health investigation, emergency procedures, fire and evacuation



    Satyajit Singh – maintaining equipment, information, instruction and supervision, training



    - All employees should: 


    co-operate with supervisors and managers on health and safety matters; 

    take reasonable care of their own health and safety; and 

    report all health and safety concerns to an appropriate person (as detailed above). 





    Part 3: Arrangements for Health and Safety


    - Risk assessment 




    We will complete relevant risk assessments and take action. 

    We will review risk assessments when working habits or conditions change.



    - Training




    We will give staff and subcontractors health and safety induction and provide appropriate training (including working at height, asbestos awareness and electrical safety).

    We will provide personal protective equipment. 

    We will make sure suitable arrangements are in place for employees who work remotely.



    - Consultation 


    We will consult staff routinely on health and safety matters as they arise and formally when we review health and safety.



    - Evacuation 


    We will make sure escape routes are well signed and kept clear at all times. 

    Evacuation plans are tested from time to time and updated if necessary.


  • Modern Slavery Act 2015

    SafalSolutions is committed to the principles of the Modern Slavery Act 2015 and the abolition of modern slavery and human trafficking.


    As an equal opportunities employer, we are committed to creating and ensuring a non-discriminatory and respectful working environment for our staff. We want all our staff to feel confident that they can expose wrongdoing without any risk to themselves and as such the company has an established whistleblowing policy which all staff can access alongside all other company policies on the staff intranet.


    Our recruitment and people management processes are designed to ensure that all prospective employees are legally entitled to work in the UK, and where applicable subject to DBS checks in order to safeguard employees and apprentices from any abuse or coercion.


    Our commitment, is to ensure that those organisations that we actually contract with to receive goods and services are aware of our policies in order to comply with the Modern Slavery Act. We do not enter into business with any organisation, in the UK or abroad, which knowingly supports or is found to be involved in slavery, servitude and forced or compulsory labour.


    Our contracts with our members & customers allow us to terminate for convenience under a wide ranging all encompassing reputational damage contract clause which covers those to be found in breach of the modern slavery act.


    Much of the supply chain is engaged on their terms & conditions, although modern slavery and anti-bribery elements are incorporated into the award of new or renewing contracts.

  • Anti-bribery policy

    SafalSolutions is committed to conducting business with the utmost integrity.

    Our business ethics do not allow anyone offering or accepting a gift, entertainment or any payment in return for business or personal advantage and it is the responsibility of all employees to ensure prevention and detection.


    As part of its code of conduct, the  Anti-Bribery Policy applies to all individual employees, temporary agency staff and contractors, agents, sponsors, intermediaries, consultants or any other people or bodies associated with the Company or any of its employees. The provision or offer to provide or the acceptance of any inducement or any reward , is prohibited under this policy.


    The company encourages and fully supports all employees in reporting any improper practices, providing a confidential reporting process to allow anyone freely and confidentially to alert the company to any concern.


    All employees including temporary agency staff and contractors are required to:


    Act honestly and with integrity at all times and to safeguard the company resources for which they are responsible

    Comply with the laws and regulation of all countries in which SafalSolution operates or hopes to operate in respect of the lawful and responsible conduct of business

    Respect SafalSolution's customers, suppliers or other parties with whom it interacts by conducting business in an ethical, lawful and professional manner

  • Privacy Policy

    We take privacy matters very seriously. We are committed to respecting and protecting

    your privacy and that of our clients and their customers. This policy explains how SafalSolution

    handles personal information and what we expect from you.


    We are committed to

    • Collecting and using personal information

    fairly and lawfully.

    • Ensuring personal information held is secure,

    accurate and up to date.

    • Respecting individual’s rights in respect of their

    personal information.

    • Only disclosing personal information to those

    who are authorised to receive it.

    • Not holding excessive amounts of information

    or keeping it longer than is necessary.


    What you should expect from us

    • We will conduct our business in a way that

    prevents unwarranted intrusion into people’s

    privacy and protects their personal information.

    • We will act in accordance with Data Protection

    Legislation that sets out the principles we must

    follow to ensure that personal information is

    lawfully held, securely stored, accurate and

    used for the right purpose.


  • Compliments and Complaints

    We, SafalSolutions Ltd., are dedicated to providing excellence in service to clients, both employers and apprentices. We recognise that superior complaints management – including ease of access for complainants, senior business engagement and timely resolution – will help us with service improvements and changes that positively impact upon our employers and apprentices. This policy also applies for complaints about GDPR data breaches. To ensure that complaints are understood in full, and investigations are undertaken on the root cause of client issues, all complaints are required in writing to: complaints@safalsolutions.co.uk   Our Policy can be downloaded here  .

  • Environmental Policy

    At Safal Solution we are commited to creating a safe and environmentally sustainable workplace for all our stakeholders. Our priority is the health and safety of our employees, and we ensure this by actively adopting the right Health, Safety and

    Environmental (HSE) practices, by complying with relevant legislation, preventing pollution, and by reducing HSE risks in all areas

    of our business. 


    We are committed to:


    • Keeping our employees safe.


    • Providing the necessary training and equipment toenable our employees to do their jobs safely and to ensure protection of the environment.


    • Providing safe and healthy working conditions

    (physical and mental*) and conducting our

    business activities in a manner that seeks to

    prevent injury and the ill health of our people from

    the specific nature of our HSE risks and

    opportunities.


    • Ensuring our decision making seeks to prevent

    pollution, reduce greenhouse gas emissions, and

    minimise our environmental impacts.


    • Fulfilling health, safety and environmental legal,

    moral, and other obligations that apply to us

    wherever we operate, periodically auditing activities

    to ensure compliance.


    • Regularly consulting and collaborating on

    HSE matters, with colleagues and where

    they exist, workers’ representatives.


    What you should expect from us:


    • Every leader and manager is responsible for the

    safety of their teams, and for communicating and

    promoting HSE awareness and responsibilities to

    their teams. Our HSE Standard and Procedures will

    describe clear instructions and specific

    responsibilities and will equip our employees with

    the tools and knowledge to keep them safe and

    meet their health, safety, and environmental duties.


    • Leaders and managers are responsible

    for HSE in their respective teams, creating a

    workplace that is safe, and supports the health and

    the safety of our employees.


    What we expect from you :


    • To follow our HSE procedures and guidance that

    apply to your role, seeking advice from managers

    where needed.

    • Promptly complete all health, safety and environmental training

    that applies to you.


    • Look out for your colleagues and always report HSE incidents,

    near misses, hazards or any health and safety concerns to your

    local HSE representative without worry of reprisal.


    • Adopt environmentally friendly working practices reducing

    business travel and energy use where possible, reducing,

    reusing, and recycling and considering the environment and

    carbon reduction when purchasing goods and services.


    • Use the HSE Escalation Process or if necessary,

    Speak Up Policy to raise any health, safety, or environmental

    concerns.


    How we will achieve this:


    • We will implement, regularly review, and continuously improve

     

    • We will communicate to stakeholders any lessons learned to

    enable continuous improvement of HSE performance.


    • We will work with stakeholders, including our 

    business partners to promote continuous improvement of HSE

    practices in the workplace.


    • We will monitor, review, and report our health, safety, and

    environmental performance, to the relevant stakeholders of the

    business, measured against set targets. 


  • Security Policy

    Information Security Policy — Safal Solutions Ltd.

    Version: 1.0

    Owner: Information Security

    Approved by: Managing Director

    Effective date: 2026-08-01

    Review cycle: Annual or upon major change


    1. Purpose

    This policy sets out Safal Solutions Ltd.’s approach to protecting information and information systems to preserve confidentiality, integrity, and availability.


    2. Scope

    This policy applies to all employees, contractors, temporary staff, and third parties who access Safal Solutions Ltd. information or systems. It applies to all information assets, including data in electronic, paper, and verbal form.


    3. Objectives


    Protect sensitive and business‑critical information

    Ensure legal, regulatory, and contractual compliance

    Reduce risk of security incidents

    Enable safe and effective business operations

    4. Roles and Responsibilities


    Managing Director: Overall accountability for information security

    Information Security Lead (or delegated role): Policy ownership, risk management, monitoring, incident management

    IT/Systems Owners: Implementation of technical controls and secure configuration

    All Users: Compliance with this policy and reporting security concerns

    5. Information Risk Management


    Information security risks are identified, assessed, treated, and reviewed at least annually and when significant changes occur.

    Risk acceptance must be documented and approved by senior management.

    6. Information Classification and Handling

    Information is classified and handled according to sensitivity:


    Public

    Internal

    Confidential

    Restricted

    Handling rules include secure storage, controlled access, encryption where appropriate, and secure disposal.


    7. Access Control and User Privileges


    Access is granted on a least‑privilege, need‑to‑know basis.

    User access is approved by asset owners and reviewed regularly.

    Privileged accounts are limited, monitored, and protected with multi‑factor authentication.

    8. Asset Management


    An inventory of information assets is maintained and reviewed.

    Each asset has a defined owner responsible for appropriate protection and acceptable use.

    9. Secure Configuration and Change Management


    Systems are securely configured to reduce attack surface.

    Changes are assessed for security impact, approved, and documented.

    10. Malware Prevention


    Malware protection tools are deployed and maintained across systems.

    Users must not disable or bypass security controls.

    11. Removable Media


    Use of removable media is controlled and risk assessed.

    Only approved, encrypted media may be used for business data.

    12. Network Security


    Network boundaries are protected by firewalls and monitored.

    Secure protocols are used for administration and data transfer.

    13. Logging and Monitoring


    Security‑relevant events are logged and monitored.

    Alerts are investigated and responded to promptly.

    14. Incident Management


    Security incidents are reported immediately to the Information Security Lead.

    Incidents are recorded, investigated, and resolved according to incident response procedures.

    Lessons learned are documented and improvements implemented.

    15. Business Continuity and Backup


    Backup procedures are in place and tested regularly.

    Recovery objectives are defined for critical systems.

    16. Supplier and Third‑Party Security


    Supplier risk is assessed before engagement.

    Contracts include appropriate information security requirements.

    17. Personnel Security


    Pre‑employment screening is conducted where appropriate.

    Staff receive security awareness training at induction and annually.

    Responsibilities for security are included in employment terms.

    18. Acceptable Use


    Systems and data are used only for legitimate business purposes.

    Users must follow acceptable use standards and report policy violations.

    19. Compliance


    Non‑compliance may result in disciplinary action.

    This policy supports compliance with relevant laws, regulations, and contractual obligations.

    20. Policy Review

    This policy is reviewed at least annually or when significant changes occur to business, systems, or threats.

  • Vulnerability Management Policy

    1.0 Purpose: This policy defines requirements for identifying, assessing, and remediating software and hardware vulnerabilities. Implementing this framework reduces the organisation's attack surface and ensures compliance with regulatory requirements such as SOC 2, ISO 27001, and PCI-DSS.2.0 Scope This policy applies to all information resources owned or operated by [Company Name], including: On-premises infrastructure, servers, and endpoints. Cloud-native workloads, environments, and containers.Internally developed applications, software, and source code.Network components, routers, switches, and IoT devices.3.0 Policy Statements3.1 Asset Discovery & InventoryInventory Tracking: All hardware and software assets must be explicitly identified, classified, and maintained in a centralized configuration management database (CMDB).Ownership: Every system must have a designated internal business owner responsible for risk sign-offs.3.2 Vulnerability Scanning & Identification. External Networks: Automated scans of public-facing endpoints must run at least weekly.Internal Networks: Full internal network and endpoint infrastructure scans must run monthly, or immediately following a significant environmental change.Code Repositories: Static (SAST) and dynamic (DAST) testing must integrate into the CI/CD pipeline.Penetration Testing: Third-party penetration tests must be conducted at least annually.3.3 Risk Assessment & Triage: Vulnerabilities will be triaged using the Common Vulnerability Scoring System (CVSS) and contextual business risk: Critical (CVSS 9.0–10.0): Immediate threat to critical data, often with an active exploit available.High (CVSS 7.0–8.9): Potential for major privilege escalation or data loss.Medium (CVSS 4.0–6.9): Requires specific configurations or multi-step execution to exploit.Low (CVSS 0.1–3.9): Minimal risk, typically limited to information disclosure.3.4 Remediation Service Level Agreements (SLAs)Upon confirmation, findings must be addressed within the following strict timeframes:Severity LevelRemediation WindowCriticalWithin 48 hoursHighWithin 14 business daysMediumWithin 30 business daysLowWithin 90 business days or next scheduled release3.5 Exception ProcessCompensating Controls: If a patch cannot be applied immediately due to business disruption, security teams must deploy compensating controls (e.g., WAF rules, network isolation).Formal Sign-off: Exceptions must be documented, approved by the Chief Information Security Officer (CISO), and re-reviewed quarterly.4.0 Roles and Responsibilities Security Team (PSIRT/SecOps): Responsible for configuring scanning tools, reviewing raw data, tracking remediation trends, and running verification tests.IT Operations / DevOps: Responsible for deploying patches, updates, and configuration fixes within the defined SLA windows.System Owners: Accountable for acknowledging risks and accepting downtime for critical remediation work.5.0 Policy Enforcement & Review Enforcement: Non-compliance with remediation schedules may result in temporary system isolation from the corporate network.Audits: Retain scan results and patch logs for at least 12 months to fulfil audit requirements.Revision: The IT Security Department maintains this document and reviews it annually.

  • Change Management Policy

    1.0 Purpose: This policy establishes a standardised process to ensure all technical changes are implemented with minimal risk, maximum visibility, and zero unauthorised impact on business operations.


    2.0 Scope This policy applies to all changes made to production environments, including: Core network infrastructure, firewalls, and routing tables.Cloud environments, databases, and production servers.Application source code deployments and API updates.Enterprise SaaS configurations affecting security or access control.


    3.0 Change Classifications. All changes must be categorised into one of three tiers to determine the required level of review: Standard (Low Risk): Routine, pre-approved, repetitive tasks with predictable outcomes (e.g., standard operating system patching, routine database maintenance). Normal (Medium to High Risk): Non-routine changes that alter configurations, system behaviour, or code. Requires full review and approval.Emergency (Critical): Immediate fixes required to restore disrupted services or patch active, severe security exploits.


    4.0 Change Management Process[Draft Request] ➔ [Risk & Rollback Plan] ➔ [Peer Review / CAB] ➔ [Test Environment] ➔ [Deploy to Production]


    4.1 Request and DocumentationEvery Normal and Emergency change must be documented in the ticketing system and include:Description: Detailed explanation of the modification. Risk Assessment: Assessment of potential impact on users, security, and performance.Test Plan: Proof of success in a staging environment.Rollback Plan: Clear, step-by-step instructions to revert the system if the change fails.


    4.2 Review and ApprovalPeer Review: All source code changes require at least one independent developer sign-off.Change Advisory Board (CAB): The CAB meets weekly to review and approve all high-risk or cross-departmental Normal changes.Emergency Approvals: Emergency changes bypass the standard CAB but require immediate verbal or written sign-off from the Engineering Director or CISO.


    4.3 Scheduling and DeploymentMaintenance Windows: Normal changes must occur during designated off-peak hours to minimize user impact.Separation of Duties: To maintain compliance, the engineer who writes or requests a change must not be the sole person approving or deploying it.5.0 Roles and Responsibilities Change Requester: Drafts the proposal, tests the fix, and builds the rollback script. Change Advisory Board (CAB): Evaluates business impact, checks for schedule conflicts, and grants final deployment clearance. System Operations Team: Monitors system health and stability during and after deployment.6.0 Policy Enforcement & Retention: Unauthorised Changes: Any change deployed outside this framework is a policy violation and may trigger incident response procedures.Audit Logs: Retain change tickets, approvals, and automated deployment logs for at least 12 months for auditing purposes.

  • Joiners, Movers, and Leavers (JML) Policy

    1.0 Purpose: This policy defines the mandatory security controls for granting, modifying, and revoking access to [Company Name] identity profiles, corporate assets, and information systems when personnel join, transfer within, or exit the organisation.


    2.0 Scope. This policy applies to all personnel requiring access to company environments, including full-time employees, part-time employees, independent contractors, vendors, and third-party consultants.


    3.0 Policy Lifecycle Stages


    - 3.1 Joiners (Onboarding & Provisioning)To ensure compliance with the principle of least privilege, the onboarding workflow must adhere to the following rules: Identity Verification: Human Resources (HR) must complete background checks and verify identity documents before any system account is generated. Role-Based Access Control (RBAC): IT must provision initial system privileges based on pre-defined job profiles. Granular or administrative access outside the default profile requires formal manager sign-off.Security Training: All new joiners must complete mandatory security awareness training within 5 business days of their start date.Hardware Distribution: Corporate-managed hardware must be logged in the asset inventory system and assigned explicitly to the individual before deployment.


    -3.2 Movers (Internal Transfers & Role Changes) When an employee changes roles, departments, or geographical locations, their access must be re-evaluated: Access Accumulation Prevention: When a worker transfers to a new role, revoke all unique access permissions from their old position within 5 business days. Profile Realignment: The destination department manager must formally submit access requests for any new systems required for the new role.


    -3.3 Leavers (Offboarding & Deprovisioning)To prevent insider threats and orphaned accounts, offboarding must follow strict operational deadlines: Termination TypeAction TimelineInvoluntary (Termination / Immediate Risk)Accounts revoked immediately (prior to or during the exit meeting)Voluntary (Resignation / Contract End)Accounts revoked at the exact local end-of-day on their final active dateAccount Disabling: IT and Security operations must disable the primary Single Sign-On (SSO) account first, which systematically blocks downstream SaaS apps. Asset Recovery: All company-owned equipment (laptops, phones, security keys) must be returned to IT within 3 business days of termination.Access Re-routing: HR must authorise email and storage forwarding to an active manager, and it must expire after 30 days.


    4.0 Governance and Auditing User Access Reviews: User access lists across all critical systems and databases must be audited quarterly to catch orphan accounts or creeping permissions.Log Retention: Account provisioning, modification, and termination logs must be maintained securely for at least 12 months for compliance auditing.


    5.0 Roles and Responsibilities: Human Resources (HR): Responsible for triggering the JML ticket requests in the ticketing system and setting clear final dates.IT Infrastructure / Security Operations: Responsible for executing the technical creation, modification, and deletion of accounts and collecting physical assets.Line Managers: Responsible for defining required tools for joiners and initiating mover modification updates promptly.

  • Cloud Infrastructure & IncidentResponse

    Multi-Cloud Network and Information Systems Governance Framework


    1. Document Control and Framework 


    Overview Purpose: This document establishes the mandatory management policies and operational processes required to govern, secure, and monitor multi-cloud network infrastructure and information systems.Scope: This framework applies to all technical assets, corporate data, and engineering workflows deployed across Amazon Web Services, Microsoft Azure, and Google Cloud Platform.Target Audience: All cloud engineers, DevOps personnel, security administrators, and system owners.Review Cycle: This policy suite is reviewed, audited, and updated bi-annually or whenever a major architectural re-engineering event occurs.


    2. Strategic Governance Policies

    • Multi-Cloud Network Security Policy: All corporate environments across AWS, Azure, and GCP must maintain strict network segmentation. Production workloads must be completely isolated from development and staging environments using Virtual Private Clouds, Virtual Networks, and explicit Cloud Firewall configurations. Default open routing is strictly prohibited, and all internal cloud-to-cloud traffic must pass through encrypted transit networks.

    • Identity and Access Governance Policy: Access to all information systems must enforce the Principle of Least Privilege and Role-Based Access Control. No user or service account may be granted broad administrative permissions by default. Centralised Identity Providers must act as the single source of truth for all authentication events.

    • Data Protection and Encryption Policy: Classify all corporate data into clear sensitivity tiers. Encrypt data at rest in cloud storage buckets, databases, and managed disks using customer-managed cryptographic keys. Data in transit across public or untrusted networks must use modern, secure cryptographic protocols.

    • System Integrity and Configuration Policy: Manual configuration changes within cloud consoles are strictly forbidden. All virtual infrastructure, cloud networks, and server configurations must be declared, version-controlled, and deployed via automated configuration frameworks to prevent environmental drift.

    3. Operational Identity Management Processes 

    • Centralised Identity Provider Integration: Synchronize corporate identities using Okta, Microsoft Entra ID, and Keycloak. Map these identity groups directly to native Cloud IAM roles across AWS, Azure, and GCP using secure single sign-on federation.
    • User Onboarding and Provisioning Workflow: Route all new access requests through an approved ticketing pipeline. Assign users to specific, pre-audited Okta or Entra ID groups based on their job function. Never attach cloud security policies directly to individual cloud IAM user accounts.
    • Mandatory Multi-Factor Authentication Process: Enforce phishing-resistant multi-factor authentication across all identity providers. Apply conditional access policies that evaluate device health, compliance posture, and geographical location before allowing system access.
    • Emergency Personnel Offboarding Process: Execute the rapid revocation checklist within 15 minutes of an HR departure notification. Terminate all active sessions inside Okta, Entra ID, and Keycloak. Revoke all cloud provider programmatic access keys, API tokens, and SSH keys. Deactivate associated repository access and automated deployment triggers.
    • Quarterly Least-Privilege Access Reviews: Run automated scripts every 90 days to review active permissions. Analyze cloud provider access logs to identify over-privileged roles. Programmatically remove any permission or entitlement that has not been exercised within the last 30 calendar days.

    4. Change Control and Infrastructure Deployment Processes 

    • Infrastructure as Code Pipeline Execution: Define all cloud networking, security groups, and storage assets using Terraform templates. Store all Terraform files in a secure, central version-control repository.
    • Configuration Management Deployment: Standardise operating system configurations, software updates, and application baselines using Ansible playbooks. Execute Ansible runs via automated pipelines to ensure absolute consistency across all virtual server fleets.
    • Mandatory Code Peer-Review Workflow: Protect all main branch infrastructure repositories. Require a minimum of two senior cloud engineering approvals via pull request before any Terraform or Ansible code can be merged into production branches.
    • Automated Security Linting and Testing: Integrate automated static security analysis tools directly into the continuous integration pipeline. Configure the pipeline to automatically reject and block any pull request that introduces insecure patterns, such as unencrypted storage buckets or overly permissive firewall rules.
    • Immutable Infrastructure Deployment Process: Execute all production changes via automated continuous delivery pipelines. Use blue-green or rolling deployment strategies to replace old infrastructure with newly built instances, completely eliminating manual in-place server patching.

    • 5. Tactical Incident Response and Containment Playbook
    • Centralised Cloud Logging and Detection: Route all cloud provider audit trails, network flow records, and system event logs to a central security monitoring engine. Trigger automated alerts for high-severity anomalies, such as root account usage, unexpected API access keys creation, or massive data downloads.
    • Multi-Cloud Network Containment Protocol: Act immediately upon verifying a resource compromise. Isolate the target asset by programmatically swapping its network rules. In AWS, apply a quarantine Security Group that denies all traffic. In Azure, apply a restrictive Network Security Group rule. In GCP, tag the instance to trigger a Deny-All VPC firewall rule. Do not terminate the instance to ensure volatile memory evidence is preserved.
    • Cryptographic Forensic Snapshot Collection: Take an immediate snapshot of the compromised resource's virtual storage drives. Move these snapshots to an isolated, read-only security forensic cloud account for analysis. Export relevant API access logs and terminal histories to a secure ledger.
    • Threat Eradication and Credential Rotation: Identify the root vulnerability or compromised credential used to gain access. Revoke the leaked API token or password immediately. Correct the vulnerability inside the source Terraform or Ansible codebase, and push the patch through the approved peer-review pipeline.
    • Post-Incident System Recovery and Smoke Testing: Deploy a fresh, clean instance into production using the updated code. Run automated testing scripts to verify service health. Re-route a small percentage of production traffic to the new instance while closely monitoring security logs for any signs of recurring malicious activity.

    6. Continuous Vulnerability Management Processes

    • Container and Base Image Registry Scanning: Run automated vulnerability scans against all application containers and virtual machine baseline images whenever new code is committed. Block the deployment pipeline automatically if a container image contains any unpatched critical or high-severity vulnerabilities.
    • Real-Time Cloud Runtime Auditing: Deploy continuous cloud security posture management tools across AWS, Azure, and GCP. Scan production environments continuously to detect manual configuration changes, alerting the security team within 5 minutes of any discovered architectural drift.
    • Bi-Annual External Perimeter Testing: Schedule and perform thorough external penetration testing twice per year. Target all public load balancers, public-facing application programming interfaces, and content delivery networks to identify zero-day vulnerabilities or perimeter weaknesses before they can be exploited.