The organization maintains an information security program intended to support the confidentiality, integrity, availability, and appropriate use of information and technology resources relevant to its business operations.
This policy establishes a general framework for identifying, assessing, managing, and monitoring information security risks. Security measures are intended to be proportionate to the nature of the organization’s operations, the information and systems involved, and the risks reasonably identified.
This policy applies, as appropriate, to information, systems, applications, technology resources, business processes, personnel, contractors, and third-party services used in connection with the organization’s operations.
The applicability and extent of specific security measures may vary based on business requirements, technical considerations, information sensitivity, operational needs, and identified risks.
Information security responsibilities are assigned to appropriate personnel or functions within the organization.
Management provides oversight of information security matters as appropriate and may establish supporting procedures, standards, guidance, or controls to address specific operational or technical requirements.
Information security considerations may be incorporated into relevant business, technology, and operational decision-making processes.
The organization seeks to identify and evaluate information security risks relevant to its operations.
Risk assessments may consider factors such as:
Identified risks may be addressed through mitigation, monitoring, acceptance, transfer, avoidance, or other measures considered appropriate under the circumstances.
Risk management activities are performed at a level and frequency considered appropriate to the organization’s operating environment and risk profile.
The organization seeks to maintain reasonable awareness of information, systems, and technology resources relevant to its operations.
Information and assets may be managed based on their business importance, sensitivity, intended use, and associated risk.
Reasonable measures may be implemented to protect information throughout its lifecycle, including creation, access, use, storage, transmission, retention, and disposal.
Access to information and systems is generally provided based on legitimate business needs and appropriate authorization.
The organization may implement access controls intended to:
Access control practices may vary based on the nature and sensitivity of the system or information involved.
The organization maintains account and authentication practices appropriate to the systems and services it uses.
Such practices may include password requirements, multi-factor authentication, account lifecycle management, session controls, or other authentication safeguards where appropriate.
Authentication requirements may differ depending on technical capabilities, risk, and business needs.
Information is protected using reasonable administrative, technical, and organizational measures appropriate to its sensitivity and intended use.
Depending on the circumstances, such measures may include:
The organization may apply different protections to different categories of information based on risk and operational requirements.
The organization maintains reasonable safeguards intended to protect systems, networks, applications, and technology infrastructure from unauthorized access, misuse, disruption, or other security risks.
Such safeguards may include, where applicable:
Specific controls may vary according to technical architecture, available capabilities, and identified risks.
The organization seeks to identify and address relevant vulnerabilities within systems and technology resources.
Security updates, patches, configuration changes, and remediation activities may be prioritized based on factors such as severity, exploitability, business impact, operational constraints, and available mitigations.
Changes to important systems may be evaluated and managed using processes appropriate to the nature and potential impact of the change.
The organization conducts security monitoring activities as considered appropriate for its systems, operations, and risk profile.
Monitoring may include the review of system activity, alerts, logs, vulnerabilities, unusual behavior, service availability, or other indicators relevant to information security.
The scope, frequency, and methods of monitoring may vary based on available technology, business needs, and assessed risk.
Potential or confirmed information security events are evaluated and addressed according to their nature, severity, and potential impact.
Incident management activities may include:
Escalation and notification activities are performed where appropriate based on the circumstances and applicable requirements.
Lessons identified through security events may be considered when evaluating future improvements to security practices.
Personnel are expected to use information and technology resources responsibly and to follow security practices applicable to their roles.
The organization may provide information security awareness, guidance, or training as appropriate to support personnel understanding of relevant security responsibilities.
Personnel-related security measures may include access management, confidentiality expectations, acceptable-use practices, and procedures associated with changes in employment or responsibilities.
Technology resources and information made available by the organization are generally intended for legitimate and authorized business purposes.
Users are expected to exercise reasonable care when accessing, handling, storing, transmitting, or otherwise using organizational information and technology resources.
Activities that could reasonably create unnecessary security, operational, legal, or reputational risk may be restricted.
The organization may rely on third parties, vendors, contractors, cloud providers, and other service providers in connection with its operations.
Information security considerations may be incorporated into the evaluation, selection, contracting, management, or review of relevant third parties based on the nature of the relationship and associated risk.
The organization may consider factors such as:
The level of review may vary according to the nature and significance of the relationship.
The organization considers information security and technology availability as part of its broader operational resilience practices.
Reasonable measures may be maintained to support recovery from disruptions, system failures, security incidents, or other events affecting important business operations.
Such measures may include backups, recovery procedures, alternate processes, service redundancy, or other safeguards considered appropriate to business needs.
Reasonable physical safeguards may be used to protect facilities, equipment, information, and technology resources from unauthorized access, damage, theft, or disruption.
Physical security measures may vary depending on the location, type of resource, operating model, and associated risk.
Where remote work, mobile devices, or externally accessible systems are used, the organization may implement security measures appropriate to the associated risks.
Such measures may include authentication requirements, device protections, secure connectivity, access restrictions, and guidelines for handling organizational information outside controlled environments.
Information security considerations may be incorporated into the acquisition, development, configuration, implementation, maintenance, and retirement of technology systems where appropriate.
Security practices may be adjusted based on the purpose, complexity, importance, and risk associated with a particular system or service.
The organization seeks to maintain information security practices consistent with applicable business, contractual, legal, and regulatory requirements relevant to its operations.
Where appropriate, specific requirements may be addressed through supporting policies, contractual terms, operational procedures, technical safeguards, or other measures.
Exceptions to established information security practices may be permitted where justified by business, operational, or technical circumstances.
Exceptions may be evaluated based on associated risks and may be subject to appropriate approval, compensating measures, limitations, or periodic review.
This policy and related information security practices are reviewed periodically and may be updated as considered appropriate.
Reviews may take into account:
The organization seeks to improve its information security practices over time in a manner proportionate to its operational requirements and risk profile.
Improvements may be informed by risk assessments, monitoring activities, security events, technology changes, business developments, internal reviews, third-party observations, or other relevant information.
This policy provides a general information security framework. It may be supported by additional procedures, standards, guidelines, technical controls, or operating practices where appropriate.
The formality, scope, and level of documentation associated with supporting practices may vary depending on business needs, applicable requirements, and the nature of the risks being addressed.