Data security policy
Data Security Policy
NextGen Assure protects information entrusted to us through documented governance, risk-based controls, competent personnel, responsible suppliers, and continuous improvement. This policy describes the security principles that guide our services and internal operations; detailed procedures, roles, and records are maintained in the applicable control system.
Purpose and scope
This policy applies to information assets, services, people, facilities, technology, and suppliers used to deliver NextGen Assure services or support our operations. It covers client information, engagement evidence, credentials, business records, systems, and communications in our custody or control.
Governance and accountability
Leadership establishes security objectives, approves the policy, assigns accountable owners, reviews material risks, and monitors improvement. Each information asset and service has an owner responsible for classification, access, retention, continuity, and issue escalation. Personnel must follow approved procedures and report suspected events promptly.
Risk management and control review
We identify threats, vulnerabilities, dependencies, and potential impact across services and information assets. Risks are recorded, prioritized, assigned, and reviewed as the environment changes. Control performance, exceptions, incidents, and corrective actions are tracked to closure with evidence of review.
Information classification and handling
Information is classified according to sensitivity, contractual expectations, business impact, and intended audience. Handling requirements address collection, use, storage, transmission, sharing, retention, secure disposal, and approved communication channels. Client evidence is shared only with authorized recipients for an agreed purpose.
Identity and access management
Access is authorized for a defined business need and least-privilege role. Joiner, mover, and leaver events are recorded; privileged access receives additional approval and monitoring. Access is reviewed periodically, credentials are protected, and access is removed promptly when no longer required.
Secure technology and change
We use proportionate safeguards for endpoint, cloud, application, network, and data security. Changes are requested, assessed, approved, tested, and recorded according to risk. Vulnerabilities are identified and prioritized, security updates are applied within defined targets, and exceptions require documented ownership and review.
Operational security and monitoring
Security-relevant activity is logged where appropriate to support accountability, troubleshooting, detection, and investigation. Monitoring is proportionate to the system and risk. We maintain procedures for secure configuration, malware protection, capacity, backup, recovery, and operational continuity.
Incident response
Security events are recorded, triaged, assessed, escalated, contained, investigated, and resolved through a documented response process. We preserve relevant evidence, communicate with affected stakeholders according to contractual and legal requirements, track corrective actions, and use post-incident learning to improve controls.
Resilience, backup, and recovery
Critical services and information dependencies are identified through continuity planning. Backups and recovery procedures are designed, protected, tested, and reviewed for the applicable recovery objectives. Continuity exercises and real events produce tracked improvements.
Supplier and personnel responsibilities
Personnel receive role-appropriate security, privacy, acceptable-use, incident-reporting, and evidence-handling guidance. Suppliers are evaluated according to the information and services they handle. Contracts document confidentiality, security expectations, access, incident notification, return or deletion, and cooperation requirements where appropriate.
Privacy and responsible data use
We collect and use personal information for defined, legitimate business purposes and limit access to what is necessary. Retention, rights requests, disclosures, transfers, and deletion are managed through documented processes appropriate to the applicable requirements and engagement context.
Assurance and continuous improvement
Internal reviews, control testing, management review, customer questions, incidents, exercises, and supplier assessments inform improvement. We distinguish internal readiness evidence from independent examination or certification conclusions and do not claim an assurance outcome before the applicable review.
Requests and questions
For a question about this policy, security controls, or information handling at NextGen Assure, contact the team through our [company page](/company/about). Engagement-specific requests should identify the relevant service, information category, and authorized contact so they can be routed safely.