Policy Statement
The Company recognizes the importance of cybersecurity as an integral part of its operations. This Cybersecurity Policy establishes the framework for safeguarding information systems, digital assets, and technology infrastructure from cyber threats in accordance with the Reserve Bank of India (RBI) Cyber Security Framework, CERT-In guidelines, and ISO/IEC 27001 standards.
Objective
- Protect the Company's information assets against unauthorized access, misuse, or disruption.
- Ensure confidentiality, integrity, and availability (CIA) of IT systems and data.
- Establish a framework for cyber incident detection, response, and recovery.
- Comply with national and international cybersecurity standards and regulations.
Scope and Applicability
This policy applies to all employees, contractors, consultants, and third-party vendors with access to the Company's IT systems, networks, applications, or data. It covers all endpoints, cloud services, data centers, and information systems owned or managed by the Company
Turn this template into a living policy
Book a 20-minute demo to see how PolicyCentral.ai distributes, translates, and tracks acknowledgement of policies like this across your entire workforce.
Book a DemoGovernance and Roles
- Board of Directors: Provides oversight and ensures cybersecurity is integrated into business strategy.
- Chief Information Security Officer (CISO): Leads the cybersecurity program and ensures policy implementation.
- IT Department: Responsible for infrastructure security, monitoring, and vulnerability management.
- Employees: Required to adhere to cybersecurity best practices and report suspicious activities immediately.
Cybersecurity Framework
The Company's cybersecurity framework is based on five core functions: Identify, Protect, Detect, Respond, and Recover (as per NIST standards).
- Identify: Maintain an inventory of assets, conduct risk assessments, and define data classifications.
- Protect: Implement access control, encryption, and secure configuration of IT assets.
- Detect: Continuously monitor for abnormal or unauthorized activities.
- Respond: Establish an incident response plan to handle cyber incidents.
- Recover: Ensure timely restoration of services and data following incidents.
Access Control
Access to IT systems and sensitive data shall be provided on a need-to-know and least-privilege basis. Strong authentication measures, including two-factor authentication (2FA), password policies, and account review mechanisms, shall be implemented.
Network Security
- Firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) shall be deployed.
- Network segmentation shall be maintained to isolate critical systems.
- All network traffic shall be monitored and logged for anomalies.
- Remote access shall be secured using VPN and encryption technologies.
Endpoint and Application Security
- All company devices shall have updated antivirus, anti-malware, and endpoint protection software.
- Operating systems and applications must be regularly patched and updated.
- Web applications shall undergo security testing, including vulnerability assessment and penetration testing (VAPT).
- Unapproved or unauthorized software installations are prohibited.
Data Security and Encryption
All sensitive and confidential data must be encrypted at rest and in transit using industry-standard encryption algorithms (e.g., AES-256, TLS 1.2+). Data backups must be regularly performed and securely stored.
Incident Response and Reporting
All employees must immediately report any suspected cybersecurity incident to the IT Security Team or CISO. The Company shall maintain an incident response plan that defines procedures for identifying, containing, eradicating, and recovering from security incidents.
Major incidents shall be reported to CERT-In within the prescribed time frame as per government regulations.
Vendor and Third-Party Security
Third-party vendors with access to Company systems or data must comply with the same cybersecurity standards as the Company Vendor risk assessments shall be conducted before onboarding and periodically thereafter.
Business Continuity and Disaster Recovery
The Company shall maintain a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) to ensure continuity of operations in case of cyber incidents, natural disasters, or system failures.
Awareness and Training
Regular cybersecurity awareness programs shall be conducted to educate employees on phishing, password hygiene, and safe browsing practices. Simulated phishing exercises may be carried out to test and reinforce vigilance.
Policy Review and Compliance
This policy shall be reviewed annually by the CISO and approved by the Board of Directors. Any violations of this policy may result in disciplinary action, including termination or legal action, depending on severity.
Employee Acknowledgment
I acknowledge that I have read and understood the Cybersecurity Policy of the Company I agree to comply with all cybersecurity procedures and report any potential threats immediately.
Employee Name: __________________________
Signature: ______________________________
Date: _________________________________
Browse all policy categories
Frequently asked questions
Who does this policy apply to?
This policy applies to all employees, contractors, consultants, and third-party vendors with access to the Company's IT systems, networks, applications, or data. It covers all endpoints, cloud services, data centers, and information systems owned or managed by the Company
What training is provided to employees?
Regular cybersecurity awareness programs shall be conducted to educate employees on phishing, password hygiene, and safe browsing practices. Simulated phishing exercises may be carried out to test and reinforce vigilance.
Who is responsible for implementing this policy?
Board of Directors: Provides oversight and ensures cybersecurity is integrated into business strategy. Chief Information Security Officer (CISO): Leads the cybersecurity program and ensures policy implementation. IT Department: Responsible for infrastructure security, monitoring, and vulnerability management. Employees: Required to adhere to cybersecurity best practices and report suspicious activities immediately.
How often is this policy reviewed?
This policy shall be reviewed annually by the CISO and approved by the Board of Directors. Any violations of this policy may result in disciplinary action, including termination or legal action, depending on severity. Employee Acknowledgment I acknowledge that I have read and understood the Cybersecurity Policy of the Company I agree.