Information Security Policy

Confidentiality, integrity and availability of ukg systems and certification data.

Purpose

confidentiality, integrity and availability of UKG systems and certification data

Scope

This policy applies to UKG personnel, contractors, subject-matter experts, assessors, decision-makers, administrators and candidates to the extent relevant to their role.

Mandatory controls

  • Role-based access and least privilege are applied.
  • Administrator authentication, password controls and 2FA are used according to risk.
  • Sensitive files are stored outside direct public access where practical.
  • Backups, restore testing, logging and incident handling are maintained.
  • Software updates are controlled and tested before production use.
  • Secrets such as API and payment keys are encrypted or protected server-side.

Required records

  • Access logs, backup records, update records and incident register.

Review and control

This controlled document is reviewed at least annually and whenever there is a material legal, scheme, technology, risk or accreditation change. The English master controls; translations must be reviewed after a material English change.

WhatsApp