1. Purpose
The Security Assurance Framework (SAF) establishes Murzo Group’s overarching approach to security governance, risk management, and assurance across all operations.
This framework provides a structured method for identifying, assessing, managing, and reviewing security risks relating to information, physical assets, personnel, technology, and infrastructure.
The SAF ensures that security is embedded into Murzo Group’s culture, decision-making, and operational practices.
2. Scope
This framework applies to:
- All Murzo Group operations, systems, and facilities
- Digital, physical, and hybrid environments
- Information assets, intellectual property, and data
- Employees, contractors, and authorised third parties
- Client-facing and internal platforms
The SAF applies globally and across all business activities.
3. Governance & Accountability
Overall responsibility for security assurance rests with Murzo Group’s senior management.
Security governance includes:
- Clear assignment of security responsibilities
- Defined escalation and decision-making authority
- Integration of security into business risk management
- Alignment with legal, regulatory, and contractual obligations
Murzo Group adopts a defence-in-depth and risk-based approach to security assurance.
4. Standards & Framework Alignment
Murzo Group’s SAF is informed by recognised standards and guidance, including:
- ISO/IEC 27001 – Information Security Management
- ISO/IEC 27002 – Security Controls
- ISO/IEC 27005 – Information Security Risk Management
- ISO/IEC 22301 – Business Continuity
- UK National Cyber Security Centre (NCSC) guidance
- UK Data Protection Act 2018 and UK GDPR
- UK government security principles (where applicable)
Alignment does not imply certification unless explicitly stated.
5. Risk Management Approach
Murzo Group identifies and manages security risks through a structured process:
- Identification of threats and vulnerabilities
- Assessment of likelihood and potential impact
- Implementation of proportionate controls
- Ongoing monitoring and review
Risk assessments are reviewed periodically and updated when:
- Systems or operations change
- New threats emerge
- Incidents or near-misses occur
6. Information Security Assurance
Information security assurance includes:
- Protection of confidentiality, integrity, and availability
- Access control and authentication
- Secure data handling and retention
- Monitoring, logging, and auditability
These controls align with Murzo Group’s Cybersecurity & Data Breach Policy and Data Protection Statement.
7. Physical & Environmental Security
Murzo Group applies proportionate physical security controls to protect facilities, infrastructure, and assets.
Measures may include:
- Controlled access to secure areas
- Surveillance and monitoring
- Environmental controls
- Visitor management procedures
Detailed operational measures are governed by internal policies and not disclosed publicly.
8. Personnel Security
Murzo Group recognises that people are critical to security assurance.
Controls may include:
- Identity verification and role-based access
- Security awareness training
- Clear acceptable-use expectations
- Prompt removal of access upon role changes
Personnel security measures are applied proportionately and lawfully.
9. Third-Party & Supply Chain Assurance
Murzo Group assesses security risks associated with third parties that access systems, data, or facilities.
Where appropriate:
- Due diligence is conducted
- Contractual security requirements are applied
- Access is limited and monitored
Murzo Group is not responsible for independent security failures of third parties beyond legal obligations.
10. Incident Management & Response
Murzo Group maintains procedures to manage security incidents, including:
- Detection and reporting mechanisms
- Incident classification and escalation
- Containment and remediation actions
- Post-incident review and improvement
Security incidents are handled in accordance with applicable law and Murzo Group’s internal response plans.
11. Assurance, Audit & Review
Security assurance is supported by:
- Periodic internal reviews
- Risk and control assessments
- Management oversight
Where appropriate, Murzo Group may engage independent assurance activities without disclosing sensitive findings publicly.
12. Continuous Improvement
Murzo Group treats security as an evolving discipline.
The SAF is reviewed to:
- Address emerging threats
- Incorporate lessons learned
- Reflect changes in law, standards, or operations
Updates are implemented proportionately and responsibly.
13. Limitations
This framework:
- Does not disclose sensitive security configurations
- Does not guarantee absolute security
- Does not create contractual obligations
Murzo Group retains discretion over implementation details.
14. Review & Updates
This framework is reviewed periodically and updated where necessary.
Revised versions will be published on Murzo Group platforms.