This portal uses layered security controls in compliance with Public Service Digitalisation Circular No. 1/2025.
Security Controls
- Web Application Firewall (WAF) — OWASP Top 10 protection
- TLS Encryption — GPKI/local CA digital certificate
- Log Monitoring — logs and audit trail continuously enabled
- Security Patching — operating system, CMS, and plugins always current
- Data Backup & DRP — periodic backups and Disaster Recovery Plan testing
- Security Testing — periodic Penetration Test and Security Posture Assessment (SPA)
Incident Reporting
Any cybersecurity incident can be reported to JPPH CSIRT or NACSA NC4.