[Company Logo][Company Name]
- Policy No.:
- [Reference Number]
- Version:
- [Version Number]
- Effective Date:
- [Date]
- Policy Owner:
- Information Security Officer
1. Purpose
[Company Name] is committed to protecting the confidentiality, integrity and availability of information belonging to the company, its customers and employees. This policy sets the framework of controls and responsibilities to achieve this.
2. Scope
It covers all information in any form (digital, paper, verbal), all systems that store or process it, and all employees, contractors and vendors with access.
3. Definitions
- Information asset: any data, system, device or document of value to the company.
- Security incident: an event that compromises, or may compromise, information or systems.
- Least privilege: giving users only the access needed for their role.
4. Policy
| Classification | Examples | Handling |
|---|
| Public | Website content, brochures | No restriction |
| Internal | Policies, org charts | Employees only |
| Confidential | Contracts, pricing, employee records | Need-to-know, encrypted in transit |
| Restricted | Customer personal data, source code, financials before release | Named access, encrypted at rest and in transit, logged |
- Governance: the Information Security Officer leads the programme and reports to [Authorised Signatory]; a security committee meets every [Number] months.
- Asset management: all information assets are recorded with an owner and classification.
- Access control: access is granted on least privilege, approved by the asset owner, reviewed every [Number] months and removed within [Number] hours of exit.
- Physical security: offices and server rooms have controlled entry and visitor logs.
- Operations: systems are patched within [Number] days of critical updates; antivirus and logging are enabled.
- Backup: critical data is backed up [daily] and restoration tested every [Number] months.
- Vendors: suppliers handling confidential data sign confidentiality and security terms and are assessed before onboarding.
- Awareness: all staff complete security training on joining and annually.
5. Procedure – Incident Response
- Anyone noticing a suspected incident reports it immediately to [Security Email / Phone].
- The security team assesses severity and contains the incident.
- Where reporting to CERT-In, the Data Protection Board, customers or other authorities is required, the Information Security Officer coordinates it within the applicable timelines with legal advice.
- A post-incident review records root cause and corrective actions.
6. Responsibilities
- Management: approve policy and resources.
- Information Security Officer: run the programme and incident response.
- Asset owners: classify and approve access.
- All users: follow policies, protect credentials and report incidents.
7. Non-compliance
Breaches of this policy may lead to disciplinary action, termination of vendor contracts and, where applicable, legal action. Exceptions require written approval from the Information Security Officer with a documented risk acceptance.
8. Review & Approval
This policy is reviewed annually and after any major incident or change in law.
Prepared by
[Information Security Officer]Approved by
[Authorised Signatory][Designation]Date:
[Date]