Section 3 — Security

Enterprise cyber security

Access control, network monitoring, and a documented incident-response plan. Procuring a firewall is not sufficient.

01

Access control

Open remote access, shared credentials, and unconstrained paths between departments are brought under control so an incident cannot spread across the organization.

02

Actionable monitoring

Alerts are configured so the operations team can act, rather than a volume of ignored warnings.

03

Incident-response plan

Responsible contacts, first isolation steps, and recovery procedure are documented so the first hour is not improvised.

04

CCTV within the security architecture

Video surveillance is not a separate island; it is integrated with the network and access policy so it does not become an unintended entry path.