Information Security Policy: PD4ML
Version: 2.0
Effective Date: 25.06.2026
Review Cycle: Annual
Table of Contents
1. Information Security Policy
2. Acceptable Use Policy
3. Human Resource Security Policy
4. Information Security Incident Management Policy
5. Third-Party Security Policy
6. Business Continuity & Resilience Policy
7. Remote Working Policy
8. Network Security Policy
9. Password Policy
10. Vulnerability & Patch Management Policy
11. Identity & Access Management Policy
12. Cryptographic Policy
13. Information Classification Policy
14. Clean Desk & Clear Screen Policy
15. Compliance
16. Exceptions
17. Review
1. Information Security Policy
Purpose
The purpose of this policy is to safeguard PD4ML’s information assets and intellectual property against threats. It ensures the confidentiality, integrity, and availability of all data processed, stored, or transmitted. This policy applies to all employees, contractors, and third-party vendors.
Scope
Applies to:
• Employees
• Contractors
• Consultants
• Vendors
• Temporary staff
• All information systems
Objectives
The organization shall:
• Protect information assets
• Meet legal and regulatory obligations
• Reduce cybersecurity risks
• Support business continuity
• Promote security awareness
Information Security Principles
• Confidentiality
• Integrity
• Availability
• Accountability
• Least Privilege
• Need-to-Know
• Defense in Depth
Roles
Management
Responsible for:
• Approving security policies
• Providing resources
• Managing risk
IT Department
Responsible for:
• Security controls
• Monitoring
• Patch management
• Backups
Employees
Responsible for:
• Following policies
• Protecting passwords
• Reporting incidents
2. Acceptable Use Policy
Purpose
To define acceptable use of company technology.
Users Shall
• Use systems for business purposes
• Protect company data
• Lock computers when unattended
• Report suspicious activities
• Follow security procedures
Users Shall Not
• Share passwords
• Install unauthorized software
• Disable security software
• Download pirated software
• Use company devices for illegal activities
Internet Usage
Permitted if:
• Does not interfere with work
• Does not violate law
• Does not introduce malware
Email Usage
Users shall not:
• Open suspicious attachments
• Forward confidential information without authorization
• Send offensive content
Monitoring
The organization reserves the right to monitor:
• Email
• Internet activity
• Device usage
• Network traffic
3. Human Resource Security Policy
Purpose
Ensure personnel understand security responsibilities.
Pre-employment
• Background verification
• Reference checks
• Confidentiality agreements
During Employment
Employees must:
• Complete security awareness training
• Sign Acceptable Use Agreement
• Report security incidents
• Protect confidential information
Termination
Upon termination:
• Disable accounts immediately
• Recover company assets
• Remove physical access
• Revoke VPN access
• Change shared passwords if applicable
4. Information Security Incident Management Policy
Definition
A security incident is any event affecting:
• Confidentiality
• Integrity
• Availability
Examples
• Malware
• Phishing
• Data leakage
• Lost laptop
• Unauthorized access
• Ransomware
Reporting
Incidents must be reported immediately to:
• IT Help Desk
• Information Security Team
Incident Response Process
1. Identification
2. Recording
3. Classification
4. Containment
5. Investigation
6. Eradication
7. Recovery
8. Lessons Learned
Evidence
Evidence shall be preserved for forensic investigation.
5. Third-Party Security Policy
Purpose
Manage supplier security risks.
Requirements
Before onboarding:
• Security assessment
• Risk assessment
• NDA
• Security clauses in contracts
Third Parties Must
• Protect company information
• Notify breaches promptly
• Follow applicable regulations
• Allow security audits where required
Reviews
Third-party security shall be reviewed annually.
6. Business Continuity & Resilience Policy
Objective
Ensure continued operations during disruptions.
Key Components
• Business Impact Analysis
• Risk Assessment
• Disaster Recovery
• Backup Strategy
• Crisis Communication
Backup
Critical systems:
• Daily backups
• Off-site storage
• Encryption
• Regular restore testing
Recovery Objectives
Management shall define:
• Recovery Time Objective (RTO)
• Recovery Point Objective (RPO)
Testing
Resilience plans shall be tested annually.
7. Remote Working Policy
Approved Devices
Employees shall use:
• Company-managed devices
• Approved mobile devices
Requirements
Remote users must:
• Use VPN
• Enable MFA
• Lock devices
• Encrypt storage
• Maintain updated antivirus
Public Wi-Fi
Employees shall:
• Use VPN
• Avoid accessing sensitive systems without protection
Home Office
Employees should:
• Prevent unauthorized viewing
• Secure documents
• Protect devices from theft
8. Network Security Policy
Objectives
Protect network infrastructure.
Controls
• Firewalls
• IDS/IPS
• Network segmentation
• Secure Wi-Fi
• Secure DNS
• VPN
Wireless Networks
Must:
• Use WPA3 where available
• Require strong authentication
• Separate guest and corporate networks
Logging
Network devices shall:
• Maintain logs
• Synchronize time
• Forward logs to SIEM
9. Password Policy
Password Requirements
Minimum:
• 14 characters
• Uppercase
• Lowercase
• Number
• Special character
Password Rules
Users shall not:
• Reuse passwords
• Share passwords
• Write passwords visibly
MFA
Required for:
• VPN
• Email
• Administrative accounts
• Cloud services
Password Managers
Approved password managers are encouraged.
10. Vulnerability & Patch Management Policy
Purpose
Reduce exposure to known vulnerabilities.
Vulnerability Scanning
Performed:
• Monthly
• After major changes
• Following critical vulnerability announcements
Patch Priorities
Critical:
• Within 7 days
High:
• Within 14 days
Medium:
• Within 30 days
Low:
• Within 90 days
Exceptions
Require documented risk acceptance.
11. Identity & Access Management Policy
Principles
• Least Privilege
• Need-to-Know
• Separation of Duties
User Lifecycle
Joiner
• Create account
• Assign role
Mover
• Modify permissions
Leaver
• Disable accounts immediately
Privileged Accounts
Require:
• MFA
• Separate admin accounts
• Logging
• Regular review
Access Reviews
Conducted quarterly.
12. Cryptographic Policy
Purpose
Protect sensitive information using approved encryption.
Approved Encryption
• AES-256
• TLS 1.2 or higher (TLS 1.3 preferred)
• SSH
• IPsec
Encryption Required
For:
• Laptops
• Mobile devices
• Backups
• Sensitive databases
• Data in transit
Key Management
Keys shall:
• Be protected
• Rotated regularly
• Stored securely
• Have defined ownership
13. Information Classification Policy
Classification Levels
Public
Approved for public release.
Internal
Business information intended for internal use.
Confidential
Sensitive information.
Examples:
• Customer data
• Financial data
• Employee records
Restricted
Highly sensitive information.
Examples:
• Encryption keys
• Trade secrets
• Security credentials
Handling Requirements
Information shall be:
• Labeled
• Stored securely
• Shared only with authorized individuals
• Disposed of securely
14. Clean Desk & Clear Screen Policy
Purpose
Prevent unauthorized access.
Employees Shall
• Lock computers when unattended
• Store confidential documents securely
• Remove papers from desks
• Clear whiteboards after meetings
• Secure portable media
Printing
Users shall:
• Retrieve printouts immediately
• Use secure printing where available
End of Day
Employees shall:
• Lock cabinets
• Remove sensitive documents
• Lock workstations
Compliance
Failure to comply with this policy may result in:
• Disciplinary action
• Revocation of system access
• Legal action where applicable
Exceptions
Policy exceptions require:
• Documented business justification
• Risk assessment
• Management approval
• Defined review period
Review
This policy shall be reviewed:
• Annually
• Following major security incidents
• Following significant regulatory changes
• Following major organizational or technology changes
