SimpleRisk Shared Responsibility Model (Hosted Deployment)
When a customer uses SimpleRisk as a hosted service in SimpleRisk’s AWS cloud environment, security responsibilities are shared between SimpleRisk and the customer. SimpleRisk manages and secures the infrastructure, operating system, and application, ensuring that the underlying technology is both robust and compliant with industry standards. This includes implementing regular security updates, monitoring for potential vulnerabilities, and maintaining high levels of data protection through advanced encryption methods. On the other hand, customers remain responsible for user management, which entails establishing and managing user accounts, roles, and permissions to ensure that only authorized personnel have access to sensitive data and features. Additionally, customers must develop and enforce data access policies that govern how data can be accessed, shared, and stored within their organization. This is crucial for maintaining data integrity and confidentiality. Furthermore, compliance with industry regulations is a key area where customers must take an active role. This means staying informed about relevant laws and guidelines that apply to their specific industry, and ensuring that their usage of SimpleRisk aligns with those standards. By clearly understanding these shared responsibilities, both SimpleRisk and the customer can work together to create a secure and compliant environment that protects sensitive information while maximizing the effectiveness of the SimpleRisk platform.
SimpleRisk Responsibilities (Security “OF” the Cloud & Application)
Infrastructure & Hosting Security
- Secure cloud infrastructure (AWS-based hosting, secure networking)
- Server patching and OS hardening
- Firewall and network security controls
- Monitoring and incident response
Application Security
- Patching and updating SimpleRisk software for vulnerabilities
- Secure development practices (code reviews, security testing)
- Addressing security vulnerabilities in the SimpleRisk codebase
- Implementing authentication and session security controls
Data Security within the Application
- Ensuring encryption of sensitive data where applicable
- Providing secure authentication and session management features
Operational & Compliance Support
- Backup and disaster recovery planning
- Uptime and availability management
- Logging and security monitoring
Customer Responsibilities (Security “IN” the Application)
User Access & Identity Management
- Managing user roles and permissions within SimpleRisk
- Enforcing strong authentication policies (e.g., MFA)
Data Security & Privacy
- Controlling who has access to sensitive risk data
- Classifying and securing sensitive information
- Defining data retention policies
Compliance & Governance
- Ensuring compliance with industry regulations (HIPAA, GDPR, etc.)
- Auditing security configurations for regulatory requirements