KPG99 Inc. – Information Security & Risk Management Policy
Effective Date: 01/02/2025
Approved By: President, KPG99 Inc.
1. Purpose
The purpose of this policy is to establish KPG99 Inc.'s framework for identifying, assessing, and managing information security and technology risks. The policy aims to protect the confidentiality, integrity, and availability of company and client information assets while supporting business objectives.
2. Scope
This policy applies to all KPG99 Inc. employees, contractors, subcontractors, vendors, and third parties who access, process, store, or manage company or client information. It covers all information assets regardless of format or location, including systems, networks, cloud services, and physical records.
3. Policy Statement
KPG99 Inc. is committed to managing information security risks through defined controls, governance, and continuous monitoring. The company will apply risk-based practices to protect information assets and comply with applicable legal, contractual, and regulatory requirements.
4. Risk Management Approach
- Conduct periodic risk assessments to identify threats, vulnerabilities, and potential impacts to information assets.
- Maintain an information asset inventory and classify data according to sensitivity and criticality.
- Assess and prioritize risks based on likelihood and business impact, and implement proportionate controls to mitigate identified risks.
- Document risk treatment plans and track remediation activities until closure.
5. Information Security Controls
- Access Control: Enforce role-based access and the principle of least privilege for systems and data access.
- Authentication: Require strong authentication methods, including multi-factor authentication where appropriate.
- Encryption: Use encryption for sensitive data in transit and at rest as per business and client requirements.
- Patch Management: Maintain timely patching of systems and applications based on criticality and vendor guidance.
- Endpoint Security: Ensure devices accessing company systems meet baseline security requirements (antivirus, system updates, secure configuration).
- Network Security: Protect networks through firewalls, secure VPNs, and monitoring of network traffic.
- Change Management: Follow controlled change processes for system modifications to avoid unintended security impacts.
6. Third-Party & Vendor Security
- Evaluate third-party security posture as part of vendor onboarding and periodically thereafter.
- Include security and data protection requirements in third-party contracts and service level agreements.
- Monitor and review third-party compliance with contractual security obligations.
7. Incident Response & Escalation
- Maintain an incident response plan that defines roles, responsibilities, and communication channels for security incidents.
- Report suspected incidents immediately to the Compliance & Operations Team at compliance@kpgtech.com.
- Investigate incidents, contain impact, remediate root causes, and document findings and actions taken.
8. Business Continuity & Resilience
- Coordinate information security planning with business continuity and disaster recovery efforts.
- Ensure critical systems and data have appropriate backup and recovery plans to minimize disruption.
9. Security Awareness & Training
- Provide information security awareness training at onboarding and regular refresher sessions for all personnel.
- Conduct role-specific training for teams with elevated access or security responsibilities.
10. Monitoring & Compliance
- Monitor security controls and system logs to detect anomalous or unauthorized activity.
- Perform regular vulnerability assessments and periodic security reviews or audits.
- Maintain records of security assessments, incidents, and remediation activities to support compliance reviews.
11. Roles & Responsibilities
- Executive Leadership: Provide governance, resources, and oversight for information security and risk management.
- Compliance & Operations Team: Manage policy enforcement, incident response, and risk assessment activities.
- IT Team: Implement technical controls, manage systems, patching, and monitoring.
- Department Heads: Ensure team adherence to policy and report security concerns.
- All Personnel: Follow security practices and report suspicious activity immediately.
12. Policy Exceptions
Exceptions to this policy must be documented, approved by the Compliance & Operations Team, and reviewed by senior management. Exceptions should include a rationale, compensating controls, and a defined expiry.
13. Review
This policy will be reviewed annually and updated as necessary to reflect changes in technology, business processes, and regulatory requirements.
Approved and Authorized by:
Puneet Gulati
President, KPG99 Inc.
Date: 01/02/2025