Security, Infrastructure & OperationsHuman Resources & Security
Human Resources Security
Pre-employment screening, access management at hiring and departure, confidentiality obligations
Security controls applied to SSM.ro (Consultia Digital S.R.L.) staff and collaborators with access to systems reduce the risk of unauthorized access and information leaks.
Applicability
This page covers SSM.ro / Consultia Digital S.R.L. staff. Users within each client's commercial account are managed by the Client's Super User — see Periodic Access Review.
Before employment
- Screening proportional to the role and level of data access
- Confidentiality obligations assumed contractually; ethical principles from the Code of Conduct
At hiring (access provisioning)
- Access granted on the least privilege principle — strictly what is necessary for the role
- Mandatory 2FA on all administrative accounts: GitHub, Heroku, AWS, and other consoles
- Access to secrets delimited per environment (see Secret Management)
- Security training at onboarding (see Awareness and Training)
During employment
- Restriction of access to data strictly to staff who need it, in accordance with the Privacy Policy
- Periodic review of administrative access to consoles and services
- Compliance with security policies and the code of conduct
At departure (access deprovisioning)
- Prompt revocation of all access: administrative accounts, provider consoles, keys, and tokens
- Rotation of secrets the person had access to (config vars, AWS keys, tokens)
- Return/deactivation of equipment and credentials
- Continuation of confidentiality obligations after the relationship ends
Sanctions
Violations of security policies and the code of conduct result in disciplinary measures, in accordance with the Code of Conduct and applicable labor legislation.