KMGMISSION • CYBERSECURITY

Protect the mission. Strengthen trust.

KMGM Cybersecurity supports the responsible protection of people, identities, information, applications and digital services across the KMGMission ecosystem.

Protect Identity Help keep access connected to the right people and responsibilities.
Protect Information Handle organizational and personal information with care.
Protect Services Support secure and dependable digital operations.
Build Awareness Equip people to recognize and reduce avoidable digital risk.
Prepare & Recover Strengthen resilience when disruption occurs.
SECURITY IS STEWARDSHIP

Protecting digital resources is part of responsible service

Cybersecurity is not only a technical function. It is a shared responsibility involving people, processes, technology, access, information and organizational accountability.

People

Help users understand safe digital practices and their responsibilities when using KMGM systems.

Identity

Support responsible access based on appropriate roles and legitimate organizational need.

Information

Protect personal, ministry and operational information according to its sensitivity and purpose.

Services

Strengthen the reliability and responsible operation of digital platforms and applications.

PROTECT IDENTITY

Access should follow responsibility

Identity security helps ensure that people can use the services they need while reducing unnecessary or inappropriate access.

Account Protection

Encourage secure account practices and appropriate authentication.

Role-Based Access

Align access with responsibilities rather than giving broad permissions by default.

Lifecycle Management

Review access as people join, change responsibilities or leave particular roles.

Shared Accountability

Treat credentials and authorized access as entrusted organizational responsibilities.

PROTECT APPLICATIONS

Build security into digital services

Applications should be designed, maintained and operated with security in mind throughout their useful life.

Secure Design

Consider identity, access, privacy and misuse risks while services are being designed.

Controlled Change

Introduce changes carefully and verify that important protections remain effective.

Responsible Integration

Connect systems only where there is a clear purpose and appropriate authorization.

Ongoing Maintenance

Maintain applications so known weaknesses and unnecessary exposure can be reduced over time.

PROTECT INFORMATION

Handle information according to its purpose and sensitivity

Information stewardship includes appropriate collection, access, use, sharing, retention and protection.

Know What We Hold

Understand the kinds of information being handled and why they are needed.

Limit Access

Give people access to information appropriate to their responsibilities.

Share Carefully

Consider authorization, purpose and sensitivity before information is shared.

Retain Responsibly

Keep information only for legitimate organizational, ministry or legal purposes.

SECURITY AWARENESS

People are an essential part of digital security

Practical awareness helps staff, volunteers, leaders and participants recognize common risks and respond more responsibly.

Suspicious Messages

Encourage careful review of unexpected links, attachments and requests for sensitive information.

Credential Safety

Protect account information and avoid sharing access that belongs to an individual user.

Device Awareness

Use devices responsibly and report loss, compromise or unusual activity promptly.

Information Awareness

Consider whether information is public, internal, personal or otherwise sensitive before sharing it.

RESILIENCE & CONTINUITY

Prepare for disruption before it happens

No digital environment can eliminate every risk. Resilience means preparing to reduce impact, maintain essential functions and restore services responsibly.

Preparedness

Identify important services and consider how teams should continue when normal technology is unavailable.

Recovery

Maintain appropriate recovery capability for important information and digital services.

Communication

Ensure responsible people know how to coordinate when a significant technology disruption occurs.

Learning

Review disruptions and security events so future prevention and recovery can improve.

INCIDENT PREPAREDNESS

Recognize, report and respond responsibly

Potential security incidents should be reported quickly through appropriate organizational channels so they can be assessed and handled by responsible teams.

Recognize

Be alert to unusual account activity, suspicious messages, unexpected system behavior or information exposure.

Report

Escalate suspected security concerns rather than attempting unauthorized investigation.

Contain Responsibly

Allow authorized personnel to take appropriate steps to reduce further impact.

Learn & Improve

Use confirmed incidents to strengthen practices, awareness and future resilience.

EVERYONE HAS A ROLE

Cybersecurity belongs to the whole organization

Users

Follow responsible digital practices and report suspicious activity.

Leaders

Treat cybersecurity, privacy and resilience as organizational responsibilities.

Technology Teams

Design, maintain and operate systems with appropriate safeguards and accountability.

Volunteers & Partners

Work within authorized boundaries and protect access and information entrusted to them.

Protect what has been entrusted to us

KMGM Cybersecurity supports trustworthy digital service by strengthening identity, information protection, awareness, resilience and responsible technology practices.

Scroll to Top