Departmental Dimension
Sales Department Behavior (SDB)
The SDB dimension defines security expectations for the sales lifecycle, covering prospecting, presentations, negotiations, and the ongoing management of client data within CRM systems.
SDB1Lead Generation
SDB1.1Secure prospecting
- โSDB1.1.1Uses only trusted data sources for obtaining prospect information (e.g., reading online reviews, checking whether these sources adhere to privacy laws, exploring data from industry-specific associations, asking for referrals from trusted contacts who have experience with using data sources for prospect information, etc)
- โSDB1.1.2Communicate with prospects using secure communication channels that use end-to-end encryption (e.g., encrypted emails, secure communication channels like Microsoft Teams, Cisco Webex etc)
- โSDB1.1.3Obtains consent from prospects before collecting data and handles them in a compliant manner
SDB1.2Secure demos and presentations
- โSDB1.2.1Uses mock data or anonymizes information whenever possible during presentation
- โSDB1.2.2Avoids showing sensitive or confidential business data during presentations or demos
- โSDB1.2.3Uses strong protection methods to secure devices used for presentations or demos (e.g., disk encryption, strong passwords, anti-malware software etc)
SDB1.3Secure negotiations
- โSDB1.3.1Ensures that non-disclosure agreements are signed by both parties (organization and prospects) involved in the negotiation before sharing confidential data
- โSDB1.3.2Uses file-sharing platforms that help control who can access, download and modify negotiation-related data (e.g., Intralinks, Onehub, Box etc)
SDB2Customer Relationship Management
SDB2.1Data entry
- โSDB2.1.1Avoids including sensitive or personal data that is not required for the sales or customer relationship management process
- โSDB2.1.2Double checks the accuracy of data entered into the CRM platform
- โSDB2.1.3Always logs out of the CRM platform when data entry tasks have been finished
SDB2.2Reporting and analysis
- โSDB2.2.1Restricts access to reporting and analysis features only to authorized personnel
- โSDB2.2.2Implements data encryption during transit to prevent unauthorized access or interception