0% found this document useful (0 votes)
8 views2 pages

Company Security Policy Overview

E

Uploaded by

mmeerut31
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views2 pages

Company Security Policy Overview

E

Uploaded by

mmeerut31
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Company Security Policy

1. Introduction
This Security Policy outlines the security measures and protocols to safeguard the
company's information, systems, and physical assets. It is designed to protect against
unauthorized access, breaches, and other security threats.

2. Purpose
The purpose of this policy is to:
• Protect the confidentiality, integrity, and availability of the company's information
and systems.
• Establish responsibilities for security management.
• Ensure compliance with relevant laws and regulations.

3. Scope
This policy applies to all employees, contractors, consultants, temporary and other
workers at the company, including all personnel affiliated with third parties. It covers all
company-owned or leased equipment, software, and facilities.

4. Responsibilities
Management: Ensure the security policy is enforced and updated.
Employees: Comply with the security policy and report security incidents.
IT Department: Implement and manage security measures, conduct regular audits, and
respond to incidents.

5. Policy Statements
5.1. Access Control
• User Accounts: Only authorized personnel are allowed to create, modify, or delete
user accounts.
• Authentication: All users must use strong passwords and multi-factor authentication
where applicable.
• Least Privilege: Access rights are granted based on the minimum necessary to
perform job functions.
5.2. Data Protection
• Encryption: Sensitive data must be encrypted both at rest and in transit.
• Backup: Regular backups of critical data must be performed and stored securely.
• Data Retention: Data retention policies must comply with legal and business
requirements.
5.3. Physical Security
• Facilities: Access to company facilities must be controlled and monitored.
• Equipment: Company equipment must be secured against theft and damage.
5.4. Network Security
• Firewalls: Firewalls must be used to protect the company network.
• Monitoring: Network traffic must be monitored for suspicious activities.
• Wireless Networks: Wireless networks must be secured using strong encryption
and authentication mechanisms.
5.5. Incident Response
• Reporting: All security incidents must be reported immediately to the IT
department.
• Investigation: The IT department will investigate all incidents and take appropriate
actions to mitigate them.
• Recovery: Plans must be in place to recover from security incidents and resume
normal operations.
5.6. Training and Awareness
• Education: All employees must receive regular training on security policies and
best practices.
• Awareness: Regular awareness programs must be conducted to keep security top
of mind.

6. Compliance
Audits: Regular security audits must be conducted to ensure compliance with this policy.
Legal Requirements: The company must comply with all relevant legal and regulatory
requirements.

7. Policy Review
This policy must be reviewed and updated at least annually or when significant changes
occur in the company’s operations or threat landscape.

8. Enforcement
Violations of this policy may result in disciplinary action, up to and including termination of
employment and legal action where applicable.

9. Approval
This policy is approved by the executive management team and is effective as of
1/April/2020

For JASSDAK FACILITIES PVT LTD

Authorized Signatory.

You might also like