ISO 27001 is a globally recognised security standard. Following a week of having auditors in our offices putting our security systems through their paces, I'm really delighted that we have passed our audit with flying colours and Beacon is now ISO 27001 certified.
The first part of an ISO 27001 audit involves explaining to your auditors why you've decided to become certified. For me, there were three really clear reasons:
We're certified to the modern (2022) version of the standard (watch out for the older 2013 version which has been withdrawn). Our auditors are UKAS accredited, which is how you can have confidence that they have carried out their audit to the standard required by the UK government.
Keeping your data secure is the most important thing that we do at Beacon. I recently wrote about a data breach at another organisation in which "details of how to gain entry into the homes of 890 people who were receiving care at home" were stolen. It's situations like this that demonstrate the importance of security, and following good security practices.
We've also recently written about 8 things you can do today to improve the security position at your charity. It's well worth a read!
A lack of 2 factor authentication (2FA) was found to have played a part in the Advanced data breach I mentioned above (you can read the full report from the ICO here). 2FA has been available since day one at Beacon, but we've now made the decision to enforce 2 factor authentication for all Beacon admins. As a Beacon admin, you can also choose to require everyone in your organisation to set up 2FA - and I highly recommend that you do!
Beacon's address autocomplete feature now includes Eircode data for Irish addresses with 98% coverage. There is no additional cost for this data beyond the standard 2p per lookup. You can find out more about pricing for address lookups here.
We've completely redesigned the Beacon roles and permissions interface. And even better, for those with the new Advanced Permissions element, we have introduced a new rules-based system that allows for more granular control at the record-level. You can now control which users have access to specific records.
For example, with advanced permissions you can now do these sorts of things:
You can find out more about roles and permissions here, and you can read a summary of the changes in this blog post.
We've improved how point to another record fields display on record pages. When you allow for multiple values, and those values are of multiple types, it's now much easier to see which records are of which type, and to remove all records of a type if you need to.
We've built some new standard import templates for you. If you need to bring GiveWheel, GoDonate, or Paypal Giving Fund data into Beacon then it's never been simpler!
Connect with fellow Beacon customers, share ideas, get tips, and discover best practices.
You can find the group here and we'd love to welcome you in.
Please note that this group is exclusively for Beacon customers.
Right now, we're working on a lot of infrastructure improvements to make Beacon faster and to keep our reliability and availability at the high standards that we set ourselves. Remember, you can view our historic uptime and subscribe to system alerts from our status page. We're also working on a brand new system for tracking and managing consent for all of your People records. We're expecting to have this ready for you as an early Christmas present in December!