Security Measures Schedule
Effective and Last Updated: July 15, 2026
1. Security Programme
SMIK-Af maintains proportionate safeguards based on data sensitivity, child risk, available technology, implementation cost, and threats. Measures evolve and are not a guarantee against every incident.
2. Identity and Access
- Firebase-based authentication and supported federated identity providers.
- Role-based and school-scoped authorisation.
- Administrative access limited to authorised duties.
- Account status, permission, and parent-link controls.
- Credential and suspicious-access reporting procedures.
3. Data and Infrastructure
- Managed cloud database and storage services.
- Encryption in transit and provider-supported encryption at rest.
- Environment and project configuration controls.
- Validation and security rules for database and file access.
- Backups or provider resilience appropriate to the service configuration.
4. Application Security
- Firebase App Check or equivalent abuse-reduction controls where supported.
- Dependency updates, code review, testing, and release controls proportionate to risk.
- Input validation and least-data design.
- Separation of user roles and sensitive modules.
- Restricted handling of payment credentials through payment processors.
5. Logging and Monitoring
- Authentication, administrative, security, and audit events where appropriate.
- Crash and reliability diagnostics.
- Incident triage, containment, remediation, and notification procedures.
- Protection of logs against unauthorised access and unnecessary retention.
6. Personnel and Vendors
- Confidentiality obligations and role-appropriate security awareness.
- Access removal when duties end.
- Risk-based service-provider review and contractual safeguards.
- Need-to-know support access.
7. School Responsibilities
Schools must secure devices and networks, assign correct roles, remove departed users, protect downloads, train users, maintain safe recovery contacts, review logs and permissions, and promptly report suspected incidents.
8. Continuity and Review
SMIK-Af maintains reasonable recovery and continuity procedures and periodically reviews controls after significant changes, incidents, or emerging risks.