How We Protect Your Data
A summary of our information-security approach for clients and prospective clients
Our clients trust us with sensitive well-completion data, schematics and the people we place on their projects. We take that seriously. Security is owned by our management and built into how we work every day — not treated as an afterthought. The points below summarise the safeguards we maintain:
Governance. Information security is led and resourced by management, with a named security lead coordinating it. Our policies are structured around ISO/IEC 27001 and aligned with Norway’s NSM ICTsecurity principles, so our approach maps to standards you already recognise.
Access control. Access to systems and your data follows least-privilege and need-to-know principles. Multifactor authentication is required for all remote, administrative and client-data access, and access is reviewed regularly and removed promptly when no longer needed.
Data protection. Client data is treated as confidential by default, kept logically separated between clients, and encrypted both in transit and at rest. It is used only to deliver the agreed service and is returned or securely deleted at the end of an engagement.
Privacy and GDPR. We process personal data in line with the GDPR and the Norwegian Personal Data Act, collecting only what is needed and putting data-processing agreements in place with the suppliers who support us.
Secure development. The software we build, including CSD and Cdim, follows secure-development practices — code review, separation of test and production environments, and testing for common vulnerabilities before release.
Resilience and backup. Critical data and client services are backed up, and our backups are tested so we can recover from disruption. We keep current systems and apply security updates promptly.
Incident response. We have a defined incident-response plan to contain, recover from and learn from security events, including timely notification to affected clients and, where required, to the relevant authorities.
Our people. Everyone we employ or engage agrees to our acceptable-use rules and receives securityawareness guidance. Consultants placed on your sites follow your security requirements alongside our own.
Want more details? We are happy to share our information-security policies, complete a supplier-security questionnaire, or discuss specific contractual requirements — under a confidentiality agreement where appropriate.
Please contact us at info@csd.as or +47 91 30 10 06.