Security Policy

Omnibond security controls aligned with NIST SP 800-171 and FAR 52.204-21.

Policy review date: 21 February 2021

Omnibond operates and stores production systems in approved cloud services adhering to NIST.SP.800-171r2 infrastructure requirements. Systems containing customer CUI are secured as outlined below and in compliance with FAR 52.204-21.

Access Control

Awareness and Training

Audit and Accountability

Configuration Management

Identification and Authentication

Incident Response

Maintenance, Media Protection, and Personnel Security

Physical Protection and Risk Assessment

Systems and Communications Protection

System and Information Integrity

Asset Management

Employee Acceptable Use

Employees, consultants, and visitors will not: share network access; access another user's account; use resources for unauthorized private profit; impede legitimate use; send junk mail; violate laws; publish threatening or infringing content; or advocate violence.

Technology Disaster Recovery

Production assets reside in the cloud. Images of critical instances are maintained in different regions with configuration options for disaster recovery.

See also our Acceptable Use Policy. Security questions: infosec@omnibond.com