SAFERWATCH INFORMATION SECURITY POLICY
Effective Date: May 1, 2018
Last Updated: Dec 7, 2024
Information Security Principles
1. Confidentiality: Ensuring data is accessible only to authorized individuals.
2. Integrity: Preventing unauthorized modification or corruption of data.
3. Availability: Ensuring data and systems are available when needed.
Access Control
1. All users must use unique credentials for system access.
2. Multi-Factor Authentication (MFA) is required for all critical systems.
3. Access is granted based on the principle of least privilege.
4. Periodic access reviews will be conducted to ensure compliance.
Data Protection
1. Sensitive data must be encrypted in transit and at rest.
2. Data classification is required to categorize information based on sensitivity.
3. Secure data disposal policies must be followed for decommissioned systems and storage devices.
Secure Software Development
1. SaferWatch follows a secure SDLC integrating security at every stage.
2. SAST (Static Analysis) and DAST (Dynamic Analysis) are mandatory before deployment.
3. Security coding practices, aligned with OWASP, must be followed.
Endpoint & Network Security
1. All corporate devices must have AV/EDR (Antivirus & Endpoint Detection Response).
2. Web Application Firewall (WAF) and Runtime Application Self-Protection (RASP) must be deployed.
3. Network segmentation and firewall rules must be enforced.
Incident Response
1. A Security Incident Response Plan (SIRP) must be in place.
2. Employees must report security incidents immediately to the IT Security team.
3. Regular tabletop exercises must be conducted to test incident response readiness.
Security Awareness & Training
1. All employees must complete mandatory security awareness training annually.
2. Phishing simulations will be conducted periodically.
3. Developers must undergo secure coding training.
Compliance & Auditing
1. Compliance with SOC 2, GDPR, CCPA, HIPAA, and other relevant regulations must be maintained.
2. Security audits and penetration testing must be conducted regularly.
3. A risk assessment program must be in place to evaluate emerging threats.
Vendor & Third-Party Security
1. All vendors must undergo a security risk assessment before engagement.
2. Third-party access must be monitored and restricted based on need.
3. Data shared with third parties must be encrypted and contractually protected.
This policy will be reviewed annually or whenever significant changes occur in the business or threat landscape.
Approved By: SaferWatch LLC Security Team
Let's Make Information Security Policy SAFER Today!
Reach out to a safety specialist now.
"*" indicates required fields


