Whitepaper
Delos Security Whitepaper
Security at Delos
Building Trust Through Security
At Delos, security is not treated as a standalone function or compliance exercise. It is a fundamental business capability that supports the trust placed in us by our customers, partners, and stakeholders.
We recognize that safeguarding information, maintaining operational resilience, and protecting the integrity of our services are essential responsibilities. Security considerations are embedded throughout our governance, operational processes, technology lifecycle, and decision-making practices.
Our objective is to maintain a security program that is proportionate to the risks we manage, aligned with recognized international standards, and continuously evolving to address emerging threats and changing business requirements.
Security Governance
Delos maintains a structured information security program supported by executive leadership and integrated into organizational governance processes.
The program is designed to provide oversight of information security risks, support informed decision-making, promote accountability, and ensure that security objectives remain aligned with business priorities.
Security responsibilities are formally assigned, and governance activities include risk management, policy oversight, control effectiveness reviews, incident management, third-party risk management, and continuous improvement initiatives.
Risk-Based Security Approach
Delos applies a risk-based methodology to the design, implementation, and operation of security controls.
Security, operational, technology, vendor, and business risks are regularly identified, assessed, evaluated, and managed through established governance processes. Risk management activities support the prioritization of security initiatives and the ongoing improvement of the control environment.
This approach enables Delos to maintain a balanced and sustainable security posture while supporting business growth and innovation.
Security Program
The Delos security program incorporates administrative, technical, and organizational measures intended to protect the confidentiality, integrity, and availability of information and services.
The program includes areas such as:
Information security governance
Identity and access management
Vulnerability management
Security monitoring and response
Secure development practices
Third-party risk management
Business continuity and resilience
Security awareness and training
Data protection and privacy controls
Continuous assessment and improvement
Security activities are periodically reviewed to ensure continued effectiveness and alignment with evolving risks and business needs.
Secure Operations
Delos maintains operational processes designed to support the secure and reliable delivery of services.
Security considerations are incorporated into the management of systems, applications, changes, vendors, and operational activities. Processes are established to support the identification, evaluation, escalation, and remediation of security-related issues when appropriate.
Operational resilience and service reliability remain important considerations across all stages of service delivery.
Product and Development Security
Security is considered throughout the lifecycle of products and technology services.
Development, deployment, and change management activities are supported by security practices intended to reduce risk, promote consistency, and strengthen the overall security posture of the organization.
Security requirements are incorporated into relevant stages of planning, implementation, testing, and operational management.
Security Monitoring and Incident Management
Delos maintains capabilities intended to support the identification, assessment, investigation, and management of security events and incidents.
Established processes guide incident handling activities, including assessment, escalation, containment, recovery, communication, and post-incident review where applicable.
Lessons learned from operational events are used to strengthen processes, controls, and organizational resilience.
Business Continuity and Operational Resilience
Maintaining the continuity of critical business operations is an important element of the Delos security program.
Business continuity and recovery capabilities are designed to support operational resilience and help ensure that services can continue to be delivered or restored following disruptive events.
These capabilities are reviewed periodically as part of the organization's ongoing risk management and resilience efforts.
Third-Party Risk Management
Delos recognizes the importance of managing risks associated with external service providers and business partners.
Third-party relationships are evaluated using a risk-based approach that considers factors such as security, operational resilience, regulatory obligations, and business impact.
Appropriate oversight activities are performed throughout the lifecycle of applicable vendor relationships.
Security Awareness and Culture
Security is a shared responsibility across the organization.
Personnel are expected to understand and fulfill their security responsibilities through adherence to established policies, procedures, and standards. Security awareness initiatives support a culture of accountability, risk awareness, and responsible handling of information and technology resources.
Continuous Improvement
Delos views security as an ongoing process rather than a fixed state.
Our security program is regularly reviewed and enhanced through governance activities, risk assessments, operational experience, industry developments, and evolving business requirements.
This commitment to continuous improvement helps ensure that security remains effective, relevant, and aligned with organizational objectives.
Alignment with Recognized Standards
The Delos security program is informed by recognized international security frameworks, standards, and industry best practices.
These include principles and control domains commonly associated with:
ISO/IEC 27001:2022
SOC 2 Trust Services Criteria
NIST Cybersecurity Framework
OWASP Security Practices
Delos continues to invest in the maturity and effectiveness of its security and compliance capabilities as part of its long-term operational strategy.
Contact
For security, compliance, privacy, or third-party risk management inquiries, please contact:
Last updated
