Purpose
The purpose of this policy is to direct the design, implementation and management of an effective Information Security Program, which ensures that BufferApps.com's information assets are appropriately identified, recorded, and afforded suitable protection at all times. This document sets forth certain principles regarding the responsible use of information by BufferApps.com and outlines the roles and responsibilities of personnel to protect the confidentiality, integrity, and availability of BufferApps.com's resources and data.
Scope
This policy covers BufferApps.com's information and information systems, including information and information systems used, managed, or operated by a contractor or other vendors, and applies to all BufferApps.com employees, contractors, and other users of BufferApps.com's information and information systems.
Policy Statements
- ✓ Implement and maintain the Information Security Program at BufferApps.com.
- ✓ Continuously improve and align information security practices to global best practices and standards.
- ✓ Review information security policies regularly; employees acknowledge adherence annually.
- ✓ Provide security awareness training regularly.
- ✓ Perform periodic internal assessments or audits; remediate gaps or findings promptly.
- ✓ Define and follow a risk assessment process; reduce risk through continuous improvement.
- ✓ Review and update information asset inventories when assets are added or upgraded.
- ✓ Review and test business continuity plans (BCPs) and backup plans at least annually.
- ✓ Clearly define and communicate roles and responsibilities to relevant individuals.
- ✓ Classify and handle information according to criticality and sensitivity as mandated by relevant requirements.
- ✓ Maintain appropriate contacts with relevant authorities and specialist security forums.
- ✓ Report security incidents outside the organisation via a person nominated by executive management, as needed.
- ✓ Identify, review, and document confidentiality or non-disclosure agreement requirements.
- ✓ Implement prevention, detection, and recovery controls against malware, combined with user awareness.
- ✓ Establish an incident management process to identify, contain, investigate, and remediate threats.
- ✓ Develop and maintain a vendor management process for third-party engagement and assessment.
- ✓ Establish and implement change and vulnerability management controls.
Roles and Responsibilities
4.1Board of Directors
Independent of management, providing oversight and direction for the Information Security Program.
- Ascertaining transparency regarding the significant risks facing BufferApps.com.
- Obtaining assurance that management has established responsibilities, processes and technology for an effective program.
- Using program assessment outputs to inform risk management decisions.
4.2Executive Management
Provides direction and support to employees with information security responsibilities, and reports the program to the Board.
- Defining and aligning program scope with business requirements and best practices.
- Ensuring information security responsibilities are assigned and sufficient, including implementation oversight, training material, periodic assessments, incident analysis, and identifying needed expertise.
- Reviewing implementation status reports and assessments.
- Reporting the overall program to the Board.
- Providing guidance and oversight for BCPs and Disaster Recovery Management, and approving DR action plans.
- Playing an active role in Risk Assessment exercises and defining mitigation strategies.
- Approving information security policies and changes to them.
4.3Chief Information Security Officer (CISO)
An executive-team appointee responsible for the organisation's information and data security.
- Overall responsibility for implementing information security and leading the security organisation.
- Approving information security policies and changes to them.
- Monitoring continuous security improvements and recommending policy/process changes.
- Managing and improving BCP and DR preparedness.
- Reporting periodically to executive management on security risks and effectiveness.
- Advising top management on standards and best practices.
- Ensuring compliance with changing laws and regulations.
- Communicating policies and programs through ongoing training and awareness.
- Partnering with stakeholders to raise risk management awareness.
4.4IT Security
An IT Security Manager oversees the organisation's security operations.
- Managing the Security Operations team and hiring/process policies.
- Monitoring internal, external, and regulatory compliance.
- Ensuring cybersecurity risk policies are understood and implemented by vendors and employees, per ISO, GDPR, SOX, PCI DSS, COPPA, etc.
- Collaborating across departments to ensure controls and policies are implemented org-wide.
4.4.1Security Operations Team
Part of IT Security, responsible for monitoring tools and investigating suspicious activity.
- Maintaining and regularly updating all security tools and technology.
- Monitoring operations and infrastructure via alerts and logs.
- Evaluating new technologies and assisting with risk-reducing controls.
- Continuously reviewing policies and controls for improvement.
- Liaising with Incident Management to test the incident response program org-wide.
4.5IT Operations
Led by the CTO, responsible for delivering technology to customers, vendors, and clients.
- Creating technical requirements aligned with business goals.
- Discovering and implementing technologies that provide competitive advantage.
- Assisting departments in making profitable use of technology.
- Monitoring system infrastructure for functionality and efficiency.
- Using stakeholder feedback to inform technological improvements.
4.6Human Resources (HR)
Ensures employees follow security policies protecting BufferApps.com, customers, and staff.
- Determining skills and requirements for information security positions.
- Ensuring employees and contractors know and carry out their security responsibilities.
- Providing security management direction per business requirements and applicable law.
Information Security Policies
This document, along with the rest of BufferApps.com's information security policies, defines the principles and terms of BufferApps.com's Information Security Program as well as the responsibilities of users and employees in carrying out and adhering to the respective program requirements.
Communication
BufferApps.com maintains dedicated communication channels to ensure that incidents related to personnel security or policy breaches are reported, evaluated, and addressed. Examples of incidents include:
Appendix 1 — Incident Contact
- Contact
- Hrushikesh
- [email protected]
- Address
- Mumbai, India
- Covers
- Health & Safety, HR / Disciplinary