Information Security Policy: PD4ML
Version: 2.0
Effective Date: 25.06.2026
Review Cycle: Annual

Table of Contents

1. Information Security Policy
2. Acceptable Use Policy
3. Human Resource Security Policy
4. Information Security Incident Management Policy
5. Third-Party Security Policy
6. Business Continuity & Resilience Policy
7. Remote Working Policy
8. Network Security Policy
9. Password Policy
10. Vulnerability & Patch Management Policy
11. Identity & Access Management Policy
12. Cryptographic Policy
13. Information Classification Policy
14. Clean Desk & Clear Screen Policy
15. Compliance
16. Exceptions
17. Review

1. Information Security Policy

Purpose

The purpose of this policy is to safeguard PD4ML’s information assets and intellectual property against threats. It ensures the confidentiality, integrity, and availability of all data processed, stored, or transmitted. This policy applies to all employees, contractors, and third-party vendors.

Scope

Applies to:
• Employees
• Contractors
• Consultants
• Vendors
• Temporary staff
• All information systems

Objectives

The organization shall:
• Protect information assets
• Meet legal and regulatory obligations
• Reduce cybersecurity risks
• Support business continuity
• Promote security awareness

Information Security Principles

• Confidentiality
• Integrity
• Availability
• Accountability
• Least Privilege
• Need-to-Know
• Defense in Depth

Roles

Management

Responsible for:
• Approving security policies
• Providing resources
• Managing risk

IT Department

Responsible for:
• Security controls
• Monitoring
• Patch management
• Backups

Employees

Responsible for:
• Following policies
• Protecting passwords
• Reporting incidents

2. Acceptable Use Policy

Purpose

To define acceptable use of company technology.

Users Shall

• Use systems for business purposes
• Protect company data
• Lock computers when unattended
• Report suspicious activities
• Follow security procedures

Users Shall Not

• Share passwords
• Install unauthorized software
• Disable security software
• Download pirated software
• Use company devices for illegal activities

Internet Usage

Permitted if:
• Does not interfere with work
• Does not violate law
• Does not introduce malware

Email Usage

Users shall not:
• Open suspicious attachments
• Forward confidential information without authorization
• Send offensive content

Monitoring

The organization reserves the right to monitor:
• Email
• Internet activity
• Device usage
• Network traffic

3. Human Resource Security Policy

Purpose

Ensure personnel understand security responsibilities.

Pre-employment

• Background verification
• Reference checks
• Confidentiality agreements

During Employment

Employees must:
• Complete security awareness training
• Sign Acceptable Use Agreement
• Report security incidents
• Protect confidential information

Termination

Upon termination:
• Disable accounts immediately
• Recover company assets
• Remove physical access
• Revoke VPN access
• Change shared passwords if applicable

4. Information Security Incident Management Policy

Definition

A security incident is any event affecting:
• Confidentiality
• Integrity
• Availability

Examples

• Malware
• Phishing
• Data leakage
• Lost laptop
• Unauthorized access
• Ransomware

Reporting

Incidents must be reported immediately to:
• IT Help Desk
• Information Security Team

Incident Response Process

1. Identification
2. Recording
3. Classification
4. Containment
5. Investigation
6. Eradication
7. Recovery
8. Lessons Learned

Evidence

Evidence shall be preserved for forensic investigation.

5. Third-Party Security Policy

Purpose

Manage supplier security risks.

Requirements

Before onboarding:
• Security assessment
• Risk assessment
• NDA
• Security clauses in contracts

Third Parties Must

• Protect company information
• Notify breaches promptly
• Follow applicable regulations
• Allow security audits where required

Reviews

Third-party security shall be reviewed annually.

6. Business Continuity & Resilience Policy

Objective

Ensure continued operations during disruptions.

Key Components

• Business Impact Analysis
• Risk Assessment
• Disaster Recovery
• Backup Strategy
• Crisis Communication

Backup

Critical systems:
• Daily backups
• Off-site storage
• Encryption
• Regular restore testing

Recovery Objectives

Management shall define:
• Recovery Time Objective (RTO)
• Recovery Point Objective (RPO)

Testing

Resilience plans shall be tested annually.

7. Remote Working Policy

Approved Devices

Employees shall use:
• Company-managed devices
• Approved mobile devices

Requirements

Remote users must:
• Use VPN
• Enable MFA
• Lock devices
• Encrypt storage
• Maintain updated antivirus

Public Wi-Fi

Employees shall:
• Use VPN
• Avoid accessing sensitive systems without protection

Home Office

Employees should:
• Prevent unauthorized viewing
• Secure documents
• Protect devices from theft

8. Network Security Policy

Objectives

Protect network infrastructure.

Controls

• Firewalls
• IDS/IPS
• Network segmentation
• Secure Wi-Fi
• Secure DNS
• VPN

Wireless Networks

Must:
• Use WPA3 where available
• Require strong authentication
• Separate guest and corporate networks

Logging

Network devices shall:
• Maintain logs
• Synchronize time
• Forward logs to SIEM

9. Password Policy

Password Requirements

Minimum:
• 14 characters
• Uppercase
• Lowercase
• Number
• Special character

Password Rules

Users shall not:
• Reuse passwords
• Share passwords
• Write passwords visibly

MFA

Required for:
• VPN
• Email
• Administrative accounts
• Cloud services

Password Managers

Approved password managers are encouraged.

10. Vulnerability & Patch Management Policy

Purpose

Reduce exposure to known vulnerabilities.

Vulnerability Scanning

Performed:
• Monthly
• After major changes
• Following critical vulnerability announcements

Patch Priorities

Critical:
• Within 7 days
High:
• Within 14 days
Medium:
• Within 30 days
Low:
• Within 90 days

Exceptions

Require documented risk acceptance.

11. Identity & Access Management Policy

Principles

• Least Privilege
• Need-to-Know
• Separation of Duties

User Lifecycle

Joiner
• Create account
• Assign role
Mover
• Modify permissions
Leaver
• Disable accounts immediately

Privileged Accounts

Require:
• MFA
• Separate admin accounts
• Logging
• Regular review

Access Reviews

Conducted quarterly.

12. Cryptographic Policy

Purpose

Protect sensitive information using approved encryption.

Approved Encryption

• AES-256
• TLS 1.2 or higher (TLS 1.3 preferred)
• SSH
• IPsec

Encryption Required

For:
• Laptops
• Mobile devices
• Backups
• Sensitive databases
• Data in transit

Key Management

Keys shall:
• Be protected
• Rotated regularly
• Stored securely
• Have defined ownership

13. Information Classification Policy

Classification Levels

Public

Approved for public release.

Internal

Business information intended for internal use.

Confidential

Sensitive information.
Examples:
• Customer data
• Financial data
• Employee records

Restricted

Highly sensitive information.
Examples:
• Encryption keys
• Trade secrets
• Security credentials

Handling Requirements

Information shall be:
• Labeled
• Stored securely
• Shared only with authorized individuals
• Disposed of securely

14. Clean Desk & Clear Screen Policy

Purpose

Prevent unauthorized access.

Employees Shall
• Lock computers when unattended
• Store confidential documents securely
• Remove papers from desks
• Clear whiteboards after meetings
• Secure portable media

Printing

Users shall:
• Retrieve printouts immediately
• Use secure printing where available

End of Day

Employees shall:
• Lock cabinets
• Remove sensitive documents
• Lock workstations

Compliance

Failure to comply with this policy may result in:
• Disciplinary action
• Revocation of system access
• Legal action where applicable

Exceptions

Policy exceptions require:
• Documented business justification
• Risk assessment
• Management approval
• Defined review period

Review

This policy shall be reviewed:
• Annually
• Following major security incidents
• Following significant regulatory changes
• Following major organizational or technology changes