Security Frameworks 

 

ISO 27001

Symplicity is ISO 27001 certified, demonstrating its commitment to maintaining the highest standards of information security. ISO 27001 outlines the requirements for establishing and managing an Information Security Management System (ISMS), which provides a structured approach to identifying, managing, and reducing security risks. This certification is a critical component of our audit and compliance strategy, ensuring that we consistently meet stringent security and regulatory requirements.  Relevance: Symplicity, CareerHub, Orbis, and Contratanet.

 
 

SOC 2 

Symplicity is SSAE 18 SOC 2 Type II certified, underscoring our dedication to robust data security and internal controls. SOC 2, or Service and Organization Controls 2, evaluates a company’s commitment to data availability, security, processing integrity, confidentiality, and privacy. A successful SOC 2 audit provides customers and stakeholders with confidence in the strength and effectiveness of our data management practices, ensuring they meet the trust services criteria. This third-party validation is critical for organizations handling sensitive data, as it demonstrates our ability to safeguard information in environments that require data sharing.  Relevance: Symplicity, CareerHub, Orbis, and Contratanet.

 

NIST 800-53 (moderate)

The NIST 800-53 is a cybersecurity standard and compliance framework developed by the National Institute of Standards in Technology. It’s a continuously updated framework that tries to flexibly define standards, controls, and assessments based on risk, cost-effectiveness, and capabilities.  Symplicity has been successfully audited by the Texas Dept of Information Resources through the Texas Risk and Authorization Management Program (TX-RAMP) for the NIST 800-53 security controls, gaining TX-RAMP compliance on June 15th 2023.  Symplicity is proud to be listed on the TX-RAMP Certified Cloud Products List on the Texas DIR TX-RAMP site.  Relevance: Symplicity & CareerHub,

 

CyberEssentials

Symplicity is CyberEssentials certified, reflecting our proactive approach to safeguarding against common cyber threats. CyberEssentials is a UK government-backed certification that establishes essential security controls to protect organizations from cyber attacks, such as phishing, malware, and ransomware. By achieving this certification, Symplicity demonstrates its commitment to maintaining a strong cybersecurity posture, ensuring the security of both its own systems and those of its clients. This certification not only helps to reduce the risk of data breaches but also reinforces trust with our customers, partners, and stakeholders by showing that we adhere to best practices in cybersecurity.  Click here to see our CyberEssentials Badge. Relevance: Symplicity, CareerHub, Orbis, and Contratanet.

 

PCI-DSS

Symplicity is a PCI-compliant vendor, ensuring the highest level of security for handling payment transactions. Although only a select few of our applications include payment features, we utilize trusted third-party payment processors, ensuring that no credit card information is stored on our servers or within our data infrastructure. To further reinforce our commitment to secure payment handling, we provide a PCI Attestation of Compliance (AOC) to clients upon request, demonstrating our adherence to the stringent requirements of the Payment Card Industry Data Security Standard (PCI DSS).