Security Best Practices and Shared Responsibility Model for DESTINI Cloud Products
Security is a shared responsibility between Beck Technology and our customers. While Beck Technology is responsible for securing and operating the DESTINI Cloud platform, customers are responsible for securing their users, accounts, devices, and the data they choose to store and manage within the platform.
A strong security posture requires active participation from both parties. This article outlines the security responsibilities of Beck Technology, as well as recommended security practices for administrators and end users of DESTINI Cloud products.
Understanding the Shared Responsibility Model
Cloud security is most effective when responsibilities are clearly defined.
Beck Technology Responsibilities
Beck Technology is responsible for securing the underlying DESTINI Cloud infrastructure and services, including:
- Cloud platform hosting and operations
- Network and infrastructure security
- Application security controls and secure development practices
- Vulnerability assessment and remediation processes
- Service monitoring and incident response
- Data encryption in transit and, where applicable, at rest
- Backup and disaster recovery processes
- Availability and performance of cloud-hosted services
- Security updates and platform maintenance
Customer Responsibilities
Customers are responsible for securing their organization's use of DESTINI Cloud products, including:
- User account management
- Password and authentication practices
- User access reviews
- Device and endpoint security
- Protection of company data uploaded to the platform
- Internal data governance policies
- Compliance with organizational and regulatory requirements
- Employee security awareness training
- Monitoring for unauthorized account activity
Security Guidance for Administrators
Administrators play a critical role in maintaining a secure environment.
Apply the Principle of Least Privilege
Grant users only the access necessary to perform their job functions.
Recommendations:
- Assign administrative privileges only to authorized personnel.
- Regularly review user roles and permissions.
- Remove unnecessary access promptly.
- Limit the number of users with elevated privileges.
Manage User Lifecycle Processes
Establish procedures for onboarding, role changes, and offboarding.
Recommendations:
- Create accounts only for active employees and approved contractors.
- Review user access during role transitions.
- Disable or remove accounts immediately when users leave the organization.
Enforce Strong Authentication
Strong authentication significantly reduces the risk of unauthorized access.
Recommendations:
- Require strong, unique passwords.
- Avoid password reuse across systems.
- Enable Multi-Factor Authentication (MFA) whenever available.
- Prohibit the sharing of user credentials.
Monitor Account Activity
Regular monitoring helps identify potential security incidents early.
Recommendations:
- Review user activity and access logs when available.
- Investigate unexpected login activity.
- Monitor for unusual account behavior.
- Respond promptly to reports of suspicious activity.
Protect Organizational Data
Administrators should establish data-handling policies that align with company and regulatory requirements.
Recommendations:
- Classify sensitive information appropriately.
- Limit access to sensitive projects and data.
- Avoid storing confidential information unnecessarily.
- Establish retention and deletion policies.
Secure Endpoints
The security of cloud applications depends in part on the security of the devices used to access them.
Recommendations:
- Require current antivirus or endpoint protection software.
- Apply operating system and browser updates promptly.
- Use managed devices whenever possible.
- Encrypt company-owned devices.
Security Guidance for End Users
Every user contributes to the overall security of the organization.
Use Strong Passwords
Create passwords that are difficult to guess and unique to DESTINI Cloud services.
Best Practices:
- Use long passphrases or complex passwords.
- Avoid personal information or common words.
- Do not reuse passwords across multiple systems.
- Consider using a password manager.
Protect Your Credentials
Usernames and passwords should never be shared.
Do Not:
- Share credentials with coworkers.
- Store passwords in unsecured documents.
- Send passwords via email or chat.
- Allow others to use your account.
Be Alert for Phishing Attempts
Cybercriminals frequently target users through fraudulent emails, websites, and messages.
Watch for:
- Unexpected login requests
- Urgent requests for credentials
- Suspicious attachments or links
- Messages claiming account problems that require immediate action
If you suspect a phishing attempt, report it to your organization's IT or security team.
Secure Your Devices
Protect the systems used to access DESTINI Cloud products.
Recommendations:
- Keep operating systems updated.
- Use supported web browsers.
- Install security updates promptly.
- Lock your device when unattended.
- Avoid using public or unsecured devices for sensitive work.
Protect Sensitive Information
Users should handle project and business information responsibly.
Recommendations:
- Share data only with authorized individuals.
- Verify recipients before sharing information.
- Follow company policies for data handling.
- Report accidental disclosures immediately.
Reporting Security Concerns
If you believe your account has been compromised or observe suspicious activity:
- Change your password immediately.
- Notify your organization's administrator or IT department.
- Report the issue to Beck Technology support if platform-related assistance is required.
- Document any relevant details, including dates, times, and observed behavior.
Prompt reporting enables faster investigation and mitigation of potential security incidents.
Security Is a Shared Responsibility
The security of DESTINI Cloud products depends on a partnership between Beck Technology and our customers. Beck Technology is committed to maintaining a secure and reliable cloud platform, while customers are responsible for implementing appropriate security controls, managing user access, and promoting secure behavior among their users.
By following the recommendations outlined in this article, administrators and end users can help protect their organizations, data, and projects while maximizing the benefits of DESTINI Cloud services.