Cyber Security at Toucan

At Toucan, we're committed to the highest quality of security for our customers, our product, and our employees. We maintain a comprehensive set of certifications to ensure that data is safe at every level. We selected the industry-leading framework, the National Institute of Standards and Technology (NIST), for our platform. 

The National Institute of Standards and Technology (NIST)

 

The National Institute of Standards and Technology (NIST) promotes and maintains measurement standards and guidance to help organizations assess risk. The main priorities of NIST were to establish a set of standards and practices to help organizations manage cybersecurity risk all while enabling business efficiency. 
  • The NIST Cybersecurity Framework is a voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity-related risks.
  • The NIST Cybersecurity Framework is divided into five main parts or functions. Continue reading to learn how we  apply these functions in the Toucan product.
NIST-CybersecurityFrameworkMain-20

NIST Cyber Security Framework

At Toucan, all data provided by our customers is viewed as strictly confidential information. We work with companies of all sizes and industries around the globe and are committed to protecting and defending our customers on all security needs.
Implementing the industry-leading NIST practices, we follow a cyber security framework allowing us to meet security needs and present quality insurance around all our data security controls. 

Identify

We manage cybersecurity risk by inventorying our:

 

- Assets

- Business environment

- Governance

- Supply chain

Detect

We identify cybersecurity events by:

- Detecting anomalies and events


- Applying
 continuous monitoring


- Applying
cybersecurity detection processes

Respond

We take action regarding a detected cybersecurity incident with:

- Response planning  communications 

- Analysis after every event 

- Mitigation of cybersecurity events

 

Recover

We maintain plans for resilience to:

 

- Restore any capabilities to services

- Continuously improve