Security assurance plan: what it should contain
In a tender or a contract with a large French organisation, you will often be asked for a security assurance plan, known in French as a plan d’assurance sécurité or PAS. It is a contractual document: it describes the measures you commit to applying to protect the customer’s data and service.
Assurance plan and security policy are different
Your security policy is an internal, general document. The assurance plan is specific to one customer and one service. It binds you: what you write in it can be held against you.
What an assurance plan usually contains
- the scope of the service and the data involved;
- organisation: security contacts on both sides;
- access control and authentication;
- encryption of data at rest and in transit;
- backups, with target recovery times;
- incident management and the notification delay;
- subcontracting and data location;
- reversibility and deletion of data at the end of the contract;
- the customer’s audit rights.
Three traps
- Copying the customer’s template without adapting it. You then commit to measures you do not apply.
- Promising an impossible delay. An incident notification delay that is too short becomes a breach of contract on the day it matters.
- Writing in the future tense. An assurance plan describes what is in place. What is planned belongs in a separate, dated action plan.
The right method
Start from what is really in place and provable, measure by measure. Hadovia draws these elements from your systems: the plan then describes reality, and each commitment rests on evidence.
Tell us what your customer is asking for. We get back to you within one business day with the next steps.
Get a demo →