This document describes Virtus Group’s standard for this area and how it is applied in practice. It is derived from our internal policies and standards and is intended for both reviewers and operations.
| Profile | Highlights |
|---|---|
| Default | FDE, MFA, EDR, screen lock ≤5min, OS/app updates ≤14d |
| Elevated (Admins) | Admin workstation hardening, PAM, no internet on privileged sessions |
| Exception | Documented risk acceptance with expiry; compensating controls |
Records are maintained per the VGL Document & Record Control guidelines, including logs, approvals, test outputs, meeting minutes, and reports.