Volkis is a cyber security organisation that seeks to improve the security of our customers and the wider community. Our part in this is protecting ourselves and the data and access that we are entrusted with.
Context of the organisation
Volkis has specific security requirements that are unique to a boutique cyber security consulting organisation. These include:
- We are a fully remote organisation that heavily relies on Software-as-a-Service for supporting delivery of work and internal processes.
- We handle sensitive information and access on behalf of customers. This information and access could cause a material incident in customer environments if it is misused.
- We are a small organisation with potential single sources of failure in both technology and personnel.
- We are a high visibility potential target due to the data and access we hold.
- Given our field, a compromise in our systems could lead to a loss of trust in Volkis as an organisation. In a competitive environment this could impact our customer relationships and revenue sources.
- We have strict regulatory requirements, including with legal responsibilities, contractual responsibilities, and regulation.
Interested parties and stakeholders
The following parties are affected by our security and must be considered when designing, implementing, and governing our internal cyber security:
- Clients: Our clients expect that we maintain the confidentiality, integrity, and availability of data and access entrusted to us. They require us to meet our contractual and compliance obligations.
- Partners: Our partners expect that we maintain the security of their data as well as the data and access that their customers provide us. They require us to keep their commercial information safe and private.
- Staff: We must ensure a safe working environment for our staff, including protecting their personal and professional information.
- Suppliers and software-as-a-service providers: We require and depend on our suppliers to meet the security, data sovereignty, and incident response requirements of our internal security.
- Government authorities: Require us to maintain compliance with laws and regulations.
- Cyber risk insurance: Requires timely engagement in the event of a security incident.
Scope of the Information Security Management System
As part of Volkis’ ISO 27001 compliance, we have put together an Information Security Management System (ISMS), that governs cyber security in the organisation. The scope of the ISMS includes:
- Volkis Pty Ltd as a full legal entity.
- All staff including consultants, project management, relationship management, and directors.
- All systems, including endpoints, servers, infrastructure-as-a-service, and software-as-a-service.
Client owned systems, including those that we use for consulting work within client environments, are not in scope for the ISMS.
Internal security objectives
We (specifically Matthew and Alexei, the founders and directors of Volkis), are committed to making Volkis a safe place for our clients, staff, and the community. Internal cyber security is a core part of our business strategy and delivery of services. Our overall objectives are to:
- Minimise the risk of the compromise of sensitive information and access entrusted to us: We need to place appropriate controls on the storage, processing, and transfer of sensitive information.
- Ensure our services maintain the security of our clients: Our consultants are often placed in a privileged position in our clients infrastructure. We need to maintain the security and integrity of the systems and tools we use, and use sensible precautions when performing activities that may have detrimental effects for client infrastructure.
- Support Volkis operations and continued service delivery: Our personnel are supported by our IT systems. The continued availability of our infrastructure is needed to ensure the continuity of our service.
- Keep the data of our staff and the wider community safe and private: We must maintain the security of our own staff as well as ensuring any personal information entrusted to us is safe and removed where it’s not needed.
A core philosophy of Volkis is “open but secure”. We publish a lot of information, including through this handbook, but we must always ensure that confidential information is kept confidential.
Key principles
When implementing information technology systems in Volkis, we follow these principles:
- Least privilege: People should only have access to what they need for their work and no more.
- Segregation of access and duties: Where possible, actions that affect security should require approval.
Roles and responsibilities
The following roles relevant to information security have been defined within Volkis:
- Information Security Officer: Matthew Strahan
- Responsibility for IT Infrastructure: Alexei Doudkine
- Incident managers: Matthew Strahan, Alexei Doudkine
- Maintenance of asset register: Victoria Pirovani
Other roles may be defined on a specific basis.
How Volkis handles risk
Volkis attempts to minimise the risk of compromise to our clients, our client's data, and the data of their customers.
We undertake risk around our operations in order to be innovative and improve our efficiency.
Laws, regulations, and compliance
Volkis have obligations under the following laws:
- Australian Privacy Act: We are not a consumer facing organisation and do not store Personally Identifiable Information (PII) of customers. We may store workplace information of our client contacts. While testing, we may encounter PII on client systems. This PII must not be retained as per our data retention policy.
We seek to comply with the following frameworks:
- ISO 27001: We seek to maintain an ISMS that complies with the ISO 27001 standard. This is both for internal security, federal government, and client requirements.
- Essential 8: The Essential 8 maintains a baseline set of technical security and process requirements. We need to comply for federal government and client requirements.
Industry partners
Volkis maintains relationships with industry bodies and special interest groups. This includes the Australian Signals Directorate (ASD), and state security bodies.