1. Agree access before work begins
Define service scope, authorised contacts, permitted systems and approval boundaries. Grant only the access needed for the agreed task, with stronger verification appropriate to privileged access.
Security & service safeguards
Security begins with knowing what a service may access, who can approve a change and how an issue is escalated.
These boundaries reduce what this website handles. They do not guarantee that a website or connected service is free from risk. The Privacy Notice explains current website data use.
Review draft: these principles are prepared for adoption. They must be checked against COMPUREP’s operating procedures, supplier arrangements and each service agreement before being treated as contractual commitments.
Define service scope, authorised contacts, permitted systems and approval boundaries. Grant only the access needed for the agreed task, with stronger verification appropriate to privileged access.
Identify who owns accounts, licences, backups, changes and escalations. Record the handover points where COMPUREP works alongside an internal IT team or another supplier.
Use approved transfer and storage channels, limit access to relevant people, review operators and subprocessors, and agree retention and disposal requirements. Avoid placing credentials or unnecessary personal information in ordinary tickets.
Consider business impact, authorisation, maintenance timing, verification and a recovery approach. Access to a system is not blanket permission to change it.
Agree reporting and escalation routes, preserve relevant evidence, determine affected information and follow applicable notification duties. Backup scope and restoration arrangements need to be agreed and tested for the service concerned.
Review permissions during staff changes, contract changes and offboarding. Agree the return or deletion of information subject to legal retention duties, and document the transfer of operational responsibility.
If personal information may be affected, use the Information Officer contact below as well as your agreed incident channel. POPIA requires notification where its security-compromise provisions apply, as soon as reasonably possible in the circumstances. Applicable EU or UK requirements must be assessed separately; they are not interchangeable with POPIA.
Follow the Information Regulator’s current security-compromise guidance and the POPIA Act, sections 21–22. Do not wait for a website response if your existing service agreement specifies an incident escalation channel.
The Trust & Security Centre publishes explanations and policy documents. Its live concierge check reports configuration only. It is not a threat-monitoring dashboard, an uptime guarantee, an audit opinion or a claim of ISO certification or universal POPIA/GDPR compliance.