Security & Compliance
Security engineered into every layer.
GITS designs and operates cloud solutions using security controls intended to protect customer information throughout its lifecycle. Our cloud environments leverage Amazon Web Services security capabilities, encryption, identity and access management, audit logging, monitoring, backup, and privacy-by-design practices.
AWS Cloud Security
GITS uses Amazon Web Services infrastructure for applicable cloud-hosted solutions and operates under the AWS Shared Responsibility Model. AWS manages security of the underlying cloud infrastructure, while GITS is responsible for securely configuring and operating the applications, identities, data, permissions, and cloud resources under our control.
Encryption
- Encryption at rest for supported systems
- HTTPS/TLS encryption in transit
- AWS encryption and key-management capabilities where appropriate
Identity & Access
- Multi-factor authentication
- Role-based access controls
- Least-privilege permissions
- Controlled administrative access
Monitoring & Audit
- AWS CloudTrail
- Amazon CloudWatch
- Amazon GuardDuty where enabled
- AWS Security Hub where enabled
- Security alerts and activity monitoring
Infrastructure Protection
- Amazon CloudFront
- AWS WAF where enabled
- S3 Block Public Access
- Secure network configuration
- Backup and recovery controls
Security capabilities may include the items above depending on the services, configuration, and tier used for each production environment. Availability is confirmed on a per-engagement basis rather than assumed across every workload.
Data Protection
GITS applies security and privacy controls throughout the lifecycle of customer information. Depending on the engagement and data classification, safeguards may include encryption, access restrictions, audit logging, secure storage, backup, retention controls, and secure deletion procedures.
Encryption at Rest
Sensitive information should be stored using appropriate encryption controls.
Encryption in Transit
Applications and APIs should use HTTPS/TLS for communications.
Access Management
Access to sensitive systems should be limited according to role and business need.
Backup & Recovery
Production systems should maintain appropriate backup and recovery procedures based on business requirements.
Data Privacy & GDPR
GITS applies privacy-by-design principles to the handling of personal information. Where the General Data Protection Regulation (GDPR) or other applicable privacy laws apply, GITS supports appropriate technical and organizational safeguards and processes for applicable privacy rights, including:
- Access. Requesting the personal information we hold.
- Correction. Requesting that inaccurate information be corrected.
- Deletion. Requesting that personal information be deleted.
- Data portability. Receiving a copy of information in a portable format, where required.
- Restriction of processing. Requesting that processing be limited in certain circumstances.
- Objection to processing. Objecting to certain processing activities.
- Withdrawal of consent. Withdrawing consent at any time where consent is the legal basis for processing.
- Privacy inquiries. Contacting GITS directly with any privacy question or request.
Healthcare Data Security
For healthcare engagements involving Protected Health Information (PHI), GITS establishes appropriate contractual, administrative, and technical safeguards before regulated information is accessed or processed. Applicable healthcare workloads may be designed using HIPAA-eligible AWS services, encryption, restricted access, audit logging, monitoring, and secure data-handling practices.
A Business Associate Agreement or other required agreement must be established before GITS accesses PHI when legally required. Appropriate contractual safeguards, including BAAs where required, are established before regulated healthcare information is processed.
Information Security Management
GITS is developing and maintaining information-security practices informed by recognized security and risk-management principles. Where applicable, our security program may align controls with ISO/IEC 27001 principles.
Security Practices
Cloud Infrastructure
AWS cloud infrastructure for applicable workloads.
Encryption
Encryption in transit and at rest for supported systems.
Access Control
Least-privilege access and MFA.
Logging
Centralized audit and operational logging where implemented.
Threat Detection
Security monitoring and threat-detection capabilities.
Backup & Recovery
Encrypted backup and recovery controls based on workload requirements.
Privacy
Privacy-by-design practices.
Secure Development
Security considerations incorporated into application development and deployment.
Compliance & Assurance
AWS Security
Infrastructure hosted on AWS where applicable and operated according to the AWS Shared Responsibility Model, with customer-managed security controls.
Healthcare
HIPAA-ready architectural and contractual safeguards can be implemented for qualifying healthcare engagements involving regulated information.
ISO/IEC 27001
Information-security controls may be developed in alignment with ISO/IEC 27001 principles.
AWS's own certifications apply to AWS infrastructure and do not, by themselves, certify GITS as an organization.
Have a security or compliance question?
Organizations evaluating GITS may contact our team regarding security practices, cloud architecture, data handling, healthcare technology requirements, and enterprise security considerations.
Contact GITS