Cybersecurity Policy

Information Security & Data
Experience PolicyCentral.ai platform features right here

Policy Statement

The Company recognizes the importance of cybersecurity as an integral part of its operations. This Cybersecurity Policy establishes the framework for safeguarding information systems, digital assets, and technology infrastructure from cyber threats in accordance with the Reserve Bank of India (RBI) Cyber Security Framework, CERT-In guidelines, and ISO/IEC 27001 standards.

Objective

  • Protect the Company's information assets against unauthorized access, misuse, or disruption.
  • Ensure confidentiality, integrity, and availability (CIA) of IT systems and data.
  • Establish a framework for cyber incident detection, response, and recovery.
  • Comply with national and international cybersecurity standards and regulations.

Scope and Applicability

This policy applies to all employees, contractors, consultants, and third-party vendors with access to the Company's IT systems, networks, applications, or data. It covers all endpoints, cloud services, data centers, and information systems owned or managed by the Company

Governance and Roles

  • Board of Directors: Provides oversight and ensures cybersecurity is integrated into business strategy.
  • Chief Information Security Officer (CISO): Leads the cybersecurity program and ensures policy implementation.
  • IT Department: Responsible for infrastructure security, monitoring, and vulnerability management.
  • Employees: Required to adhere to cybersecurity best practices and report suspicious activities immediately.

Cybersecurity Framework

The Company's cybersecurity framework is based on five core functions: Identify, Protect, Detect, Respond, and Recover (as per NIST standards).

  • Identify: Maintain an inventory of assets, conduct risk assessments, and define data classifications.
  • Protect: Implement access control, encryption, and secure configuration of IT assets.
  • Detect: Continuously monitor for abnormal or unauthorized activities.
  • Respond: Establish an incident response plan to handle cyber incidents.
  • Recover: Ensure timely restoration of services and data following incidents.

Access Control

Access to IT systems and sensitive data shall be provided on a need-to-know and least-privilege basis. Strong authentication measures, including two-factor authentication (2FA), password policies, and account review mechanisms, shall be implemented.

Network Security

  • Firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) shall be deployed.
  • Network segmentation shall be maintained to isolate critical systems.
  • All network traffic shall be monitored and logged for anomalies.
  • Remote access shall be secured using VPN and encryption technologies.

Endpoint and Application Security

  • All company devices shall have updated antivirus, anti-malware, and endpoint protection software.
  • Operating systems and applications must be regularly patched and updated.
  • Web applications shall undergo security testing, including vulnerability assessment and penetration testing (VAPT).
  • Unapproved or unauthorized software installations are prohibited.

Data Security and Encryption

All sensitive and confidential data must be encrypted at rest and in transit using industry-standard encryption algorithms (e.g., AES-256, TLS 1.2+). Data backups must be regularly performed and securely stored.

Incident Response and Reporting

All employees must immediately report any suspected cybersecurity incident to the IT Security Team or CISO. The Company shall maintain an incident response plan that defines procedures for identifying, containing, eradicating, and recovering from security incidents.

Major incidents shall be reported to CERT-In within the prescribed time frame as per government regulations.

Vendor and Third-Party Security

Third-party vendors with access to Company systems or data must comply with the same cybersecurity standards as the Company Vendor risk assessments shall be conducted before onboarding and periodically thereafter.

Business Continuity and Disaster Recovery

The Company shall maintain a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) to ensure continuity of operations in case of cyber incidents, natural disasters, or system failures.

Awareness and Training

Regular cybersecurity awareness programs shall be conducted to educate employees on phishing, password hygiene, and safe browsing practices. Simulated phishing exercises may be carried out to test and reinforce vigilance.

Policy Review and Compliance

This policy shall be reviewed annually by the CISO and approved by the Board of Directors. Any violations of this policy may result in disciplinary action, including termination or legal action, depending on severity.

Employee Acknowledgment

I acknowledge that I have read and understood the Cybersecurity Policy of the Company I agree to comply with all cybersecurity procedures and report any potential threats immediately.

Employee Name: __________________________

Signature: ______________________________

Date: _________________________________

Browse all policy categories

Frequently asked questions

Who does this policy apply to?

This policy applies to all employees, contractors, consultants, and third-party vendors with access to the Company's IT systems, networks, applications, or data. It covers all endpoints, cloud services, data centers, and information systems owned or managed by the Company

What training is provided to employees?

Regular cybersecurity awareness programs shall be conducted to educate employees on phishing, password hygiene, and safe browsing practices. Simulated phishing exercises may be carried out to test and reinforce vigilance.

Who is responsible for implementing this policy?

Board of Directors: Provides oversight and ensures cybersecurity is integrated into business strategy. Chief Information Security Officer (CISO): Leads the cybersecurity program and ensures policy implementation. IT Department: Responsible for infrastructure security, monitoring, and vulnerability management. Employees: Required to adhere to cybersecurity best practices and report suspicious activities immediately.

How often is this policy reviewed?

This policy shall be reviewed annually by the CISO and approved by the Board of Directors. Any violations of this policy may result in disciplinary action, including termination or legal action, depending on severity. Employee Acknowledgment I acknowledge that I have read and understood the Cybersecurity Policy of the Company I agree.

Stop emailing policy PDFs nobody reads

PolicyCentral.ai turns templates like this into living policies, versioned, translated, acknowledged, and answerable by AI.

PolicyGPT
AI-powered policy assistant

Hi! I'm PolicyGPT. Ask me anything about PolicyCentral.ai — features, security, compliance, pricing, or hosting.