Introduction
The purpose of this document is to assist in;
- Reducing the risk of IT problems
- Planning for problems and dealing with them when they happen
- Allowing Fly to keep working if something does go wrong
- Protecting company, client and employee data
- Keeping valuable company information secure
- Meeting our legal obligations under the General Data Protection Regulation and other relevant laws
- Meeting our professional obligations towards our clients and customers
Responsibilities
- Tim De La Salle is the Director with overall responsibility for IT security strategy.
- Developers and employees at Fly have day-to-day operational responsibility for implementing this policy.
- A number of partners and suppliers are used to help with our planning and support in IT Security matters.
Review Process
We review this policy annually. In the meantime, if you have any questions, suggestions or feedback, please contact us on hello@talk2fly.com.
Information Classification
- We will only classify information which is necessary for the completion of our duties.
- We will also limit access to personal data to only those that need it for processing.
- With regards to client websites please refer to our WordPress Security Incident Plan for more details.
- We classify information into different categories so that we can ensure that it is properly protected and that we allocate security resources appropriately:
- Unclassified
This is information that can be made public without any implications for the company, such as information that is already in the public domain. - Employee confidential
This includes information such as medical records, pay and so on. - Company confidential
Such as contracts, source code, business plans, passwords for critical IT systems, client contact records, accounts etc. - Client confidential
This includes personally identifiable information such as name or address, passwords to client systems, client business plans, new product information, market-sensitive information etc. and client customer personal information.
- Unclassified
We do not protectively mark documents and systems. Therefore, you should assume information is confidential unless you are sure it is not and act accordingly.
Access Controls
Internally, as far as possible, we operate on a ‘need to share’ rather than a ‘need to know’ basis with respect to company or client confidential information. This means that our bias and intention is to share information to help people do their jobs rather than raise barriers to access needlessly.
As for client information, we operate in compliance with the GDPR ‘Right to Access’. This is the right of data subjects to obtain confirmation as to whether we are processing their data, where we are processing it and for what purpose.
Further, we shall provide, upon request, a copy of their personal data, free of charge in an electronic format. We also allow data subjects to transmit their own personal data to another controller. In general we protect confidential information using access controls including user permissions, 2-step verification and regular audits.
In addition, admin privileges to company systems will be restricted to specific, authorised individuals for the proper performance of their duties.
Security Software
To protect our data, systems, users and customers we use a number of systems including but not limited to;
- Virtual Private Networks Laptop and desktop anti-malware
- Server anti-malware
- Cloud-hosted email spam, malware and content filtering
- Email archiving and continuity
- Website malware and vulnerability scanning
- Intrusion detection and prevention
Employees
General Access
At the client’s discretion, relevant Fly employees are granted access to client websites and/or other relevant systems. Fly will only request and in turn provide access to relevant employees where necessary. All employees with access to client websites and data (confidential or otherwise) are fully trained and qualified in all appropriate security and development practices. Before accessing systems, all employees must sign confidentiality agreements. All access is removed immediately upon termination of employment at Fly.
Training
We will provide training to new staff and support for existing staff to implement this policy. This includes: An initial introduction to IT security, covering the risks, basic security measures, company policies and where to get help
Each employee will complete;
- IT security training courses
- Training on how to use company systems and security software properly
- On request, a security health check on their computer, tablet or phone
When people leave a project or leave the company, we will promptly revoke their access privileges to company systems.
Security
Effective security is a team effort requiring the participation and support of every employee and associate. It is our employees responsibility to know and follow the guidelines provided to them.
These guidelines contain information on, but are not limited to;
- Responsibilities in using devices (computer, phone, tablet etc.) in a secure way.
- Removing software that is not used or needed from your computer
- Updating operating systems and applications regularly
- Keeping computer firewall switched on For Windows OR Mac users, making use of anti-malware software
- Storing files in official company storage locations so that it is backed up properly and available in an emergency.
- Understanding the privacy and security settings on phones and social media accounts
- Keeping work computers and devices separate from any family or shared computers.
Disaster Recovery Plan
A disaster recovery plan has been formulated and shared with relevant employees. It contains confidential information pertaining to specific suppliers and sensitive company information.
It is therefore not shared in detail in this document.
In general it outlines for each system;
- Backup Mechanisms
- Frequency of Backups
- Recovery Time Objectives and
- Contact details for all relevant stakeholders
More Information
Should you require further information you may request it via our website or email security@talk2fly.com