Security Assurance Framework (SAF)

Version 1.0 · Last Updated:

1. Purpose

The Security Assurance Framework (SAF) establishes Murzo Group’s overarching approach to security governance, risk management, and assurance across all operations.

This framework provides a structured method for identifying, assessing, managing, and reviewing security risks relating to information, physical assets, personnel, technology, and infrastructure.

The SAF ensures that security is embedded into Murzo Group’s culture, decision-making, and operational practices.

2. Scope

This framework applies to:

  • All Murzo Group operations, systems, and facilities
  • Digital, physical, and hybrid environments
  • Information assets, intellectual property, and data
  • Employees, contractors, and authorised third parties
  • Client-facing and internal platforms

The SAF applies globally and across all business activities.

3. Governance & Accountability

Overall responsibility for security assurance rests with Murzo Group’s senior management.

Security governance includes:

  • Clear assignment of security responsibilities
  • Defined escalation and decision-making authority
  • Integration of security into business risk management
  • Alignment with legal, regulatory, and contractual obligations

Murzo Group adopts a defence-in-depth and risk-based approach to security assurance.

4. Standards & Framework Alignment

Murzo Group’s SAF is informed by recognised standards and guidance, including:

  • ISO/IEC 27001 – Information Security Management
  • ISO/IEC 27002 – Security Controls
  • ISO/IEC 27005 – Information Security Risk Management
  • ISO/IEC 22301 – Business Continuity
  • UK National Cyber Security Centre (NCSC) guidance
  • UK Data Protection Act 2018 and UK GDPR
  • UK government security principles (where applicable)

Alignment does not imply certification unless explicitly stated.

5. Risk Management Approach

Murzo Group identifies and manages security risks through a structured process:

  • Identification of threats and vulnerabilities
  • Assessment of likelihood and potential impact
  • Implementation of proportionate controls
  • Ongoing monitoring and review

Risk assessments are reviewed periodically and updated when:

  • Systems or operations change
  • New threats emerge
  • Incidents or near-misses occur

6. Information Security Assurance

Information security assurance includes:

  • Protection of confidentiality, integrity, and availability
  • Access control and authentication
  • Secure data handling and retention
  • Monitoring, logging, and auditability

These controls align with Murzo Group’s Cybersecurity & Data Breach Policy and Data Protection Statement.

7. Physical & Environmental Security

Murzo Group applies proportionate physical security controls to protect facilities, infrastructure, and assets.

Measures may include:

  • Controlled access to secure areas
  • Surveillance and monitoring
  • Environmental controls
  • Visitor management procedures

Detailed operational measures are governed by internal policies and not disclosed publicly.

8. Personnel Security

Murzo Group recognises that people are critical to security assurance.

Controls may include:

  • Identity verification and role-based access
  • Security awareness training
  • Clear acceptable-use expectations
  • Prompt removal of access upon role changes

Personnel security measures are applied proportionately and lawfully.

9. Third-Party & Supply Chain Assurance

Murzo Group assesses security risks associated with third parties that access systems, data, or facilities.

Where appropriate:

  • Due diligence is conducted
  • Contractual security requirements are applied
  • Access is limited and monitored

Murzo Group is not responsible for independent security failures of third parties beyond legal obligations.

10. Incident Management & Response

Murzo Group maintains procedures to manage security incidents, including:

  • Detection and reporting mechanisms
  • Incident classification and escalation
  • Containment and remediation actions
  • Post-incident review and improvement

Security incidents are handled in accordance with applicable law and Murzo Group’s internal response plans.

11. Assurance, Audit & Review

Security assurance is supported by:

  • Periodic internal reviews
  • Risk and control assessments
  • Management oversight

Where appropriate, Murzo Group may engage independent assurance activities without disclosing sensitive findings publicly.

12. Continuous Improvement

Murzo Group treats security as an evolving discipline.

The SAF is reviewed to:

  • Address emerging threats
  • Incorporate lessons learned
  • Reflect changes in law, standards, or operations

Updates are implemented proportionately and responsibly.

13. Limitations

This framework:

  • Does not disclose sensitive security configurations
  • Does not guarantee absolute security
  • Does not create contractual obligations

Murzo Group retains discretion over implementation details.

14. Review & Updates

This framework is reviewed periodically and updated where necessary.

Revised versions will be published on Murzo Group platforms.

Murzo Group signature