Information Security Policy¶
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 22/Jan/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Objectives¶
The objective of this policy is to protect the Company’s information assets and the supporting infrastructure. This includes all the information assets that belong to the Company, the customers, the suppliers, and business partners used in the company’s operations.
Scope¶
The policy extends to all functions and activities. All Information assets belonging to the Company and/or the Client in possession or custody of the employees, representatives, suppliers, service providers and their personnel are part of the scope.
Requirements¶
Policy Statement¶
tecciance shall commit to:
-
Clearly understanding the requirements and expectations of customers, relevant legal & regulatory authorities.
-
Working closely with customers and vendors to deliver services in a security conscious fashion.
-
Confidentiality of information is protected to prevent disclosure of valuable or sensitive information.
-
The integrity of information is maintained to ensure its accuracy and completeness.
-
The availability of information is maintained to meet business needs and client’s requirements.
-
Deploy appropriate data privacy controls (Systemic, administrative, logical, technical controls) to meet the requirements of Data Controllers & Subjects.
-
Business continuity plans are developed, maintained, and tested.
-
Ensuring every employee shares responsibility for effective information security.
-
Protecting its people, information, intellectual property, assets, activities and facilities against misuse, loss, damage, disruption, interference, espionage, or unauthorized disclosure. It is also critical that we retain the confidence of those who entrust sensitive information to us.
-
Developing and maintaining security policies and controls designed to meet the requirements of ISO 27001. The policy statements contained in our Information Security Policy, procedures, guidelines, and standards, reflect the minimum requirements necessary to maintain an acceptable standard for protecting our information assets and, at the same time, our reputation.
-
Periodically reviewing this policy for its continued suitability and applicability.
-
By conducting periodic Risk Assessment and Internal Compliance Audit to identify the risk and to mitigate the identified risk.
-
Implement an Information Security Management System (ISMS) in line with ISO 27001 and ensure it is maintained, continually improved, and supported with adequate resources to achieve the objectives set in this Policy Statement.
Security objectives¶
tecciance’s management has set the following security objectives – which are fulfilled by ISMS.
-
Protection of Customer Information (100% Compliance).
-
Compliance with the law of the land (100% Compliance).
-
Awareness of People (95% Completion of Information Security Assessment).
-
Incident Response and Resolution (Issue reported within 24 hours. Preventive and Corrective actions taken in the shortest period).
Goals¶
To identify through appropriate risk assessment, the degree of protection of information assets, the preparedness against threats, the vulnerabilities and the threats that may expose the assets to risk.
To manage and minimize the risks to an acceptable level through the design, implementation, and maintenance of a formal Information Security Management System (ISMS).
To comply with Legislation including (but not limited to):
-
Applicable legislation, regulatory and customer requirements.
-
Commitment to comply with ISO 27001: 2022.
-
Commitment to achieve continual improvement by adherence to security and governing best practices, wherever applicable.
Methodology¶
A systematic “Plan - Do - Check - Act” approach is followed to build, assess, review and maintain the Information Security Management Systems.
Specific policies / practices exist to support the mandatory requirements to satisfy the ISO 27001 standards.
-
ISMS Roles and responsibilities.
-
Acceptable Usage Policy for all end users.
-
Incident Management and Reporting.
-
Non-Disclosure Agreement with all employees & business partners.
Responsibilities¶
The ISMS operate through a management forum which combines representatives from all units of the organization and consists of:
-
A Steering Committee
-
CISO / ISMS Manager
-
Head of Departments
-
Internal Auditors (internal and external)
The CISO / ISMS Manager is a role that facilitates the implementation & maintenance of the Company’s Information Security program through appropriate policies and procedures. The constitution of the Steering Committee, Implementation team and Audit team is represented by leadership teams. Each department head/team leader promotes information security within their teams, ensuring that all personnel are responsible for following the policies and practices to maintain the ISMS.
Disciplinary action¶
Any deliberate attempt to jeopardize the information assets or the supporting infrastructure will be subject to relevant disciplinary action, according to the Misconduct Disciplinary Action policy and process.
Review¶
This Policy and Procedure shall be reviewed and approved by IS Head once a year or at the time of any major change in existing environment affecting policy, whichever is earlier.
Exceptions¶
Any exceptions to this Policy and Procedure shall be reviewed and approved by IS Head before acceptance.
Definitions¶
| S. No | Term/Acronyms | Definition |
|---|---|---|
| 1 | ISP | Information Security Policy |
| 2 | ISMS | Information Security Management System |
| 3 | CISO | Chief Information Security Officer |
Control Mapping¶
Mapping To ISO 27001 Control (s)¶
| ISO 27001:2022 Control | Control Objective |
|---|---|
| Clause 5.1 | Leadership and commitment |
| Clause 5.2 | Policy |
| Clause 5.3 | Organizational roles, responsibilities, and authorities |
| Clause 6.2 | Information Security objectives and planning to achieve them |
| A.6.4 | Disciplinary process |
¶
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.