Our commitment to information security
Akuerò ensures proper Information Security Management, applying IT Security best practices to protect its infrastructure and mitigate cyber risk.
We have prepared a detailed document to describe, for the benefit of anyone who may be interested, the criteria used to manage the IT risk associated with Akuerò Platforms, which provide digital services to automate information processes in the loyalty marketing sector.
The content of this document is organized to provide a detailed understanding of the methods used and the security controls implemented to protect the information processed through the Akuerò Platforms' software applications, with particular regard to personal data subject to the provisions of EU Regulation 2016/679 (hereinafter "GDPR").
© Methodology and Framework for Cybersecurity and Data Protection
Akuerò has its own Information Security Management System to operate consciously and obtain objective parameters to measure and mitigate IT risk.
To best address awareness-raising efforts, the original Cyberction © , designed to provide an operational method for creating and deploying information security management systems that leverage the taxonomy of the National Framework for Cybersecurity and Data Protection (Framework 2.0). This methodology is therefore natively designed to bridge the gap between cybersecurity and data protection.
ISO/IEC 27001
The information reference is ISO/IEC 27001; the individual activities envisaged by the Akuerò System are typically mapped to the ISO/IEC 27001 Security Control of the information reference associated with the Framework 2.0 subcategory. The Cybersecurity activities performed on the Akuerò Platforms to manage cyber risk are thus mapped to the ISO/IEC 27001 standard and therefore compliant.
DPO
We have appointed a Data Protection Officer (DPO).