1. Commitment
PRO LEVEL aims to protect confidentiality, integrity and availability through a risk-based programme. Publish only controls that are actually implemented and verified.
2. Governance
- Assigned ownership and policies.
- Risk assessment and remediation.
- Staff training and vendor diligence.
- Security requirements in development and change management.
3. Identity and access
Use unique accounts, least privilege, role-based access, strong password controls, session protection, privileged-access review and MFA for privileged users. State public availability only after verification.
4. Application and infrastructure
- Secure development lifecycle and peer review.
- Dependency and vulnerability scanning.
- Environment separation and secret management.
- Input validation, rate limiting and access-control tests.
- Patch and configuration management.
5. Encryption and sensitive data
Use current industry-standard encryption in transit and appropriate protection at rest. Restrict verification documents and sensitive athlete data, minimise collection and shorten retention.
6. Monitoring and incident response
Log and monitor security events. Maintain triage, containment, recovery, evidence, communication and regulatory-notification procedures.
7. Backups and continuity
Maintain tested backups, recovery objectives, rollback, capacity monitoring and business continuity appropriate to the service.
8. Vulnerability reporting
Report vulnerabilities to [INSERT SECURITY CONTACT EMAIL]. Researchers must avoid unnecessary access, disruption, extortion, premature disclosure and third-party testing. Counsel should approve any safe-harbour wording.
9. Customer responsibilities
Customers must manage permissions, devices, exports, integrations and safeguarding. Security is shared.
10. Certifications
Do not claim ISO 27001, SOC 2, PCI DSS, HIPAA compliance or penetration-test status without current evidence.