Information Security Policies
| Title | Information Security Policies |
|---|---|
| Approval Date | 15-12-2025 |
| Version | 1.0 |
Table of Contents
1. Information Security Policy
Purpose
The purpose of this policy is to ensure that the NetPlusDotCom information assets and associated information systems are recognised as valuable assets and managed accordingly to ensure their confidentiality, integrity, and availability.
Scope
This policy applies to all NetPlusDotCom employees, contractors, service providers, and vendors.
Policy Statement
NetPlusDotCom Limited is committed to developing, adopting, and maintaining appropriate information security policies, standards, and procedures to ensure integration of information security with the organisation's mission, business objectives, and in accordance with applicable regulatory, legislative, and contractual requirements.
This will be accomplished by active management oversight and monitoring of information security risks and establishing appropriate organizational processes to ensure that information security risks are appropriately and regularly identified, controlled and monitored.
This policy is required to protect and ensure the security of NetPlusDotCom information assets and ensure NetPlusDotCom's compliance with applicable laws and regulations.
This policy and associated policies shall be reviewed at least annually and revised as necessary, or at a time of major change to the organisation's business processes.
2. Access Control Policy
Purpose
The control of access to NetPlusDotCom's information assets is a fundamental part of the organization’s information security strategy. Accordingly, this policy has been established to forestall the unauthorized or uncontrolled access, misuse of user privileges, or unauthorized disclosure to third parties, that may result in security breaches, damage, misuse, or theft of NetPlusDotCom's information and information systems.
Scope
This policy applies to all NetPlusDotCom's information systems. All NetPlusDotCom's personnel and contractors including vendors shall comply with this policy.
Policy Statement
Multi-factor authentication (MFA) shall be used for access to the Cardholder Data Environment (CDE) and other systems where required by applicable PCI DSS requirements. Static authentication credentials shall not be used as the sole authentication factor where MFA is required.
Default passwords for applications, operating systems, routers, firewalls, wireless devices, and other systems shall be changed or disabled before deploying new systems into the production environment. Where possible, default usernames shall also be disabled
IT systems and applications in the cardholder environment shall be configured to time out after 15 minutes of inactivity. The session shall remain terminated until an authorized user re-establishes connection
Access privileges for business users and any personnel with access to cardholder data environment (such as system administrators and software developers) should follow documented access request process and be approved by an appropriate business manager
Every user will only be granted the minimum access rights required to perform their job functions
A limit of five successive login failures will be enforced and the offending account will be locked out for 30 minutes once this threshold is breached
Normal use of accounts with administrative privileges should be studied, understood and closely monitored by cyber security to increase the chances of rapidly detecting and containing associated malicious activities
Before access privileges come into effect, users should be advised of – and be required to confirm understanding of – their access privileges and conditions of use
Access control arrangements should be supported by documented processes and procedures based on commonly adopted best practices, sensitivity of systems, legal, regulatory and contractual obligations
Access privileges should not be assigned collectively unless special circumstances apply. In exceptional cases where access privileges need to be assigned collectively, this should be documented, approved by an appropriate business manager.
Access requests to NetPlusDotCom's information and information systems shall be authorised and documented.
Access rights of suspended and exiting staff shall be immediately disabled and revoked respectively.
Access rights shall be reviewed periodically, and redundant user accounts removed.
3. Acceptable Use Policy
Purpose
The use of NetPlusDotCom's information systems and resources may expose the organisation to diverse risks such as malware, compromise of information systems, loss of data or confidential information, and legal and/or regulatory actions. This policy provides guidance for the acceptable use of NetPlusDotCom's information systems.
Scope
This policy applies to all personnel and contractors, including vendors who have authorised access to NetPlusDotCom's information and information systems
Policy Statement
All users are responsible for the protection of information in their custody or stored/processed on information systems used.
Anti-malware and other security solutions must be installed in all systems storing NetPlusDotCom's information or connected to NetPlusDotCom's information systems.
The circumvention of deployed security controls or use of unauthorised tools capable of generating, interfering, and/or intercepting network traffic is prohibited.
Email accounts are provided to NetPlusDotCom's personnel primarily for business purposes. The use of these accounts for purposes unrelated to NetPlusDotCom's business requirements is prohibited.
The initiation and/or forwarding of sensitive mails, chain emails or similar material from a NetPlusDotCom mail account or NetPlusDotCom information system is forbidden.
Users shall be responsible for the content of material viewed, downloaded, or sent while using NetPlusDotCom's information resources.
Materials that are fraudulent, harassing, embarrassing, sexually explicit, obscene, defamatory, or otherwise unlawful or inappropriate shall not be stored or sent by email or other form of electronic communication (such as bulletin board systems, chat groups, newsgroups, or Instant Messenger) using NetPlusDotCom's resources, nor may it be displayed or stored on NetPlusDotCom's information systems or network.
Information/materials created or resident on NetPlusDotCom's information systems remain the property of the organisation.
NetPlusDotCom's information systems users must not engage in internet activities, e.g. blogging, chat room, etc, that may cause damage to the organisation or expose NetPlusDotCom's confidential information. Such acts include but are not limited to attributing
personal statements or views to the organisation on such platforms, or purporting to represent the organisation on such platforms explicitly or implicitly
NetPlusDotCom's information system users shall not use the organisation’s resources to download, store or transmit materials that infringe any copyright, trademark, licensing agreement, or other proprietary right.
Work areas shall not be cluttered with handwritten or printed notes displaying confidential or sensitive information.
Confidential or sensitive information such as passwords shall not be written down.
All printed information should be stored in secure cabinets or drawers at all times
All printers, scanners, and associated devices should be cleared of papers as soon as they are scanned/copied/printed.
Laptops should be password protected and locked or switched off when unattended.
A clear screen policy shall be adopted on all NetPlusDotCom's information systems.
All technology use must be authenticated with user ID and password or other authentication item (such as a token). A list of all devices and the personnel authorized to use the devices must be maintained and reviewed on a yearly basis.
All devices must be labelled such that they can be properly tracked to a device owner or manager and device purpose.
Approved devices e.g., network devices, laptops, etc must be used in the NetPlusDotCom cloud environment and office premises as approved by management.
Any device that utilizes remote-access technologies must employ automatic disconnect of sessions after a period of inactivity.
4. Mobile Device Policy
Purpose
Mobile devices are particularly at risk of theft or loss due to their portability and size. This policy aims to protect NetPlusDotCom's information stored in mobile devices from loss or unwanted exposure, and to minimise the risk of loss or theft of mobile devices.
Scope
This policy applies to all mobile devices that may be used to store NetPlusDotCom's information. These devices include laptops, smartphone, tablets, external storage devices, memory sticks/flash drives, and all forms of portable devices.
Policy Statement
All NetPlusDotCom's supplied mobile devices and their contents remain the property of NetPlusDotCom and are subject to audit and monitoring.
The creation and use of credentials to access mobile devices shall be in accordance with the password policy and other associated policies.
Laptops and other associated devices shall be encrypted to prevent loss of NetPlusDotCom's information in the event of mobile device loss or theft.
System patches and anti-malware solutions shall be installed on mobile devices where applicable and updated periodically.
Security configurations on mobile devices shall not be changed without reference to the IT department
Mobile devices shall have property/identification tags attached and a log of issued devices shall be kept and maintained.
Mobile device content shall be backed-up on a regular basis.
Where no longer required, mobile device contents shall be removed and made unrecoverable.
The loss or theft of NetPlusDotCom's owned mobile devices shall be reported to IT.
Due care shall be exercised in the use, storage, and transportation of mobile devices.
5. Password Policy
Purpose
Passwords are an important aspect of information systems and are the front line of protection for user and system accounts. This policy sets out the requirements for the creation and usage of passwords for NetPlusDotCom's information systems.
Scope
This policy applies to all personnel, contractors including vendors who have or are responsible for an account on any NetPlusDotCom information system. All NetPlusDotCom personnel and relevant third parties must comply with the requirements of this policy.
Policy Statement
All passwords for users and information systems shall comprise a minimum of twelve characters. Application and service account passwords shall also comprise a minimum of twelve characters and consist of a combination of alphabets, numbers, and special characters. Passwords shall be managed and changed in accordance with applicable PCI DSS requirements and NetPlusDotCom's password-management procedures.
All new accounts shall require and be assigned an initial password comprising a minimum of twelve alpha-numeric characters which shall be communicated securely.
Default passwords shall be changed immediately on all information systems.
All user and administrative credentials shall be changed at least every 90 days.
New passwords shall not be the same as any of the last four passwords used
Passwords shall not be shared, written down, posted, stored or displayed in clear text.
The use of privileged passwords shall be restricted.
New passwords, for users and information systems, shall be transmitted through secure means.
Users shall be held responsible for all activity performed with their usernames.
Failure to comply with this policy may result in disciplinary action, up to and including termination of employment, legal action, and financial penalties.
Security Monitoring Policy
Purpose
The purpose of this document is to outline the NetPlusDotCom policy regarding the monitoring, logging, and retention of network events that traverse its networks. The goal of this policy is to maintain the security of NetPlusDotCom's network infrastructure through logging and monitoring of user and system events.
Scope
This policy is applicable to information assets operating in the NetPlusDotCom network.
Security Monitoring
Security monitoring is a method used to confirm that the security practices and controls in place are being adhered to and are effective. Monitoring consists of activities such as the review of firewall logs, user activities, application logs, and other applicable log files
Logs will be configured to provide real time notification of detected anomalies in user and network activities and reviewed on a daily basis. These tools will be deployed to monitor:
All Actions taken by any individual with root or administrative privileges
Access to audit trails
Event date and time
Identification and authentication mechanisms
Identity or name of affected data, system component, or resource
The following files will be reviewed for exceptions:
Firewall logs
Application logs
Security appliance logs
Where exceptions have been identified, details of the exception will be collected and reviewed from the log source and other information sources, where applicable. If the exception has been determined to be an incident, the security response plan will be activated.
Events from security tools will be configured for the timely detection of failures emanating from logical access controls, controls i.e., file integrity monitoring controls, intrusion detection and prevention, and audit logging mechanisms.
In the event of any security control failing, processes for responding to such failures would include the following:
Immediate restoration of security functions
Documentation of the failure duration of the security failure, root cause of failure, and adopted remediation measures to address the failure root cause.
Remediation of attendant security issues that occurred when the security control failed
Execution of a risk assessment to determine if additional actions are required as a result of the control failure and implementation of identified controls to prevent failure recurrence.
Resumption of security control monitoring
Security Information and Event Management (SIEM)
Security-related logs and events from systems within and supporting the Cardholder Data Environment (CDE) shall be centrally collected, monitored, correlated, reviewed, retained, and protected using approved logging and SIEM capabilities where applicable. Security alerts and identified events shall be investigated, escalated, and addressed in accordance with the incident response process and applicable PCI DSS requirements.
Log Retention Requirements
Audit trails files shall be backed up to a log server and protected from unauthorized modifications via access control mechanisms and physical segregation.
Only those with a job-related need are authorized to view audit files.
Audit trail history shall be retained for one year, with a minimum of three months immediately available for analysis.
Security Reviews
Security reviews shall be conducted on a quarterly basis to confirm applicable personnel are complying to NetPlusDotCom's security policies and operational procedures. These reviews will cover the following security processes:
Daily log reviews
Bi-annual firewall rule-set reviews
Application of configuration standards to new systems
Change management processes
Security alerts response
The outcome of this review process shall be documented and signed off by CTO
Time Synchronisation
All critical system clocks and times shall be synchronised using designated external time sources
Roles & Responsibilities Section
1. Executive Leadership
1.1 Chief Executive Officer (CEO) / President
Ultimate accountability for the organization's PCI DSS compliance program.
Provides executive sponsorship and resources for information security initiatives.
Ensures adequate budget allocation for security controls and compliance activities
Reviews and approves the annual information security policy
Accountable for security incidents and their business impact
1.2 Chief Information Security Officer (CISO) – Olatunbosun Olalegbin
Primary responsibility for developing, implementing, and maintaining the information security program
Ensures information security policy addresses all PCI DSS requirements
Oversees security awareness training programs for all personnel
Manages security incident response and reporting
Coordinates with external assessors and auditors
Reviews and updates security policies annually or as needed
Oversees the security of the organization’s network infrastructure, including network security architecture, security controls, configuration standards, and protection of systems within and supporting the Cardholder Data Environment (CDE).
Provides oversight of system administration security, including privileged access, secure configuration, patching, account management, hardening, and administrative activities affecting systems within and supporting the CDE.
Oversees the protection and encryption of stored account data and related cryptographic controls in accordance with applicable PCI DSS requirements and approved security standards.
Oversees Security Information and Event Management (SIEM) capabilities, including centralized collection, monitoring, correlation, review, retention, and protection of security-related logs and events, and ensures relevant alerts are investigated, escalated, and addressed.
2. IT and Technical Leadership
2.1 IT Senior Leadership / IT Director
Operational management of systems within the cardholder data environment
Implements technical security controls as required by PCI DSS
Ensures proper configuration and maintenance of security systems
Manages vulnerability scanning and penetration testing activities
Coordinates system updates and patches that affect PCI DSS compliance
2.2. System Administrator
Maintains server security configurations and access controls
Implements and monitors system-level security controls
Manages user accounts and authentication systems
Ensures secure system configurations and hardening
Performs regular security maintenance and updates
2.3 Database Administrator
Secures databases containing or connected to cardholder data
Implements database access controls and monitoring
Manages database encryption and key management
Performs database security assessments and hardening
Maintains database activity logs and monitoring
3. Compliance and Risk Management
3.1. Compliance Manager / Officer
Ongoing monitoring of PCI DSS compliance status
Coordinates internal compliance assessments and external audits
Maintains compliance documentation and evidence
Tracks remediation of compliance gaps and findings
Reports compliance status to senior management
4. Human Resources
4.1. HR Director / Manager
Personnel security management and background screening
Manages employee onboarding and security awareness training
Implements disciplinary procedures for security violations
Coordinates termination procedures to protect data access
Maintains personnel security records and documentation
5. All Personnel Responsibilities
5.1. Employees and Contractors
Individual accountability for following established security procedures
Protects cardholder data in accordance with company policies
Reports security incidents and suspicious activities immediately
Completes required security awareness training
Uses strong authentication and access controls
Maintains confidentiality of sensitive information
5.2 Personnel Handling Cardholder Data
Enhanced responsibilities for those with direct access to cardholder data
Follows strict data handling and processing procedures
Uses only approved methods for transmitting cardholder data
Implements proper data retention and disposal procedures
Reports any potential data compromise immediately
Complies with additional training and certification requirements
6. Committee Structure
6.1 PCI DSS Compliance Committee
Cross-functional team responsible for overall compliance program coordination
Committee Chair: CISO or designated senior security leader
Members: Representatives from IT, Business Operations, Compliance, HR, and Legal
Responsibilities:
Reviews and updates information security policies
Coordinates compliance activities across business units
Reviews security incidents and lessons learned
Approves major security initiatives and changes
Reports to executive leadership on compliance status
6.2 Project Manager (Dedicated Role)
Centralized coordination of compliance activities and documentation
Manages compliance project timelines and deliverables
Collects and maintains evidence for PCI DSS assessments
Coordinates with external assessors and auditors
Tracks remediation activities and compliance metrics
Facilitates communication between business units and committees
7. Third-Party Management
7.1 Vendor Management Team
Due diligence for third-party service providers handling cardholder data
Ensures third parties maintain appropriate PCI DSS compliance
Reviews and approves vendor security assessments
Manages contractual security requirements with vendors
Monitors ongoing vendor compliance and performance
8. Escalation Structure
8.1 Security Incident Escalation
Immediate Response: Personnel → Supervisor → IT/Security Team
Management Notification: CISO → CEO (for significant incidents)
External Reporting: Legal/Compliance team coordinates with card brands and authorities as required
9. Training and Awareness Responsibilities
9.1 Training Program Management
CISO/Security Team: Develops security awareness curriculum
HR: Coordinates training delivery and tracking
Managers: Ensures staff complete required training
All Personnel: Complete assigned training within specified timeframes
10. Documentation and Record Keeping
10.1 Documentation Responsibilities
Policy Owner (CISO): Maintains master policy documents
Process Owners: Document specific procedures and controls
Compliance Team: Maintains evidence and assessment records
8. Supplier Policy
Purpose
This policy sets out the requirements for the services and products supplied by external parties to NetPlusDotCom.
Scope
This policy applies to all contractors, vendors, and other third parties who supply products and/or services to NetPlusDotCom.
Policy Statement
Proper due diligence must be exercised before engaging with any service providers that may affect or have a relationship or function associated with NetPlusDotCom's information assets. This diligence will involve the execution of risk assessments and other similar information security activities.
Suppliers shall be identified and documented based on the service and/or product supplied, where access to NetPlusDotCom's information assets will be granted.
A current and accurate list of service providers shall be maintained, complete with contact information of applicable personnel
Access granted to NNetPlusDotCom's information assets shall be the minimal access necessary to achieve required purposes.
NetPlusDotCom's information security requirements shall be documented in contractual agreements and suppliers granted access to information assets required to comply with NetPlusDotCom's security policies and requirements.
For any services engaged with service providers that may affect or have a relationship or function associated with NetPlusDotCom's cardholder data environment, a written agreement shall include an acknowledgement by the service providers of their responsibility for securing cardholder data information.
Supplier delivery shall be monitored and reviewed periodically.
Information security awareness training shall be conducted for supplier personnel where applicable.
The compliance status of all PCIDSS service providers to applicable standard requirements shall be monitored on an annual basis.
9. Anti-Malware Policy
Purpose
This policy establishes mandatory requirements for the deployment, configuration, and monitoring of anti-malware controls to protect against known and unknown malicious software threats across all systems handling cardholder data, in compliance with PCI DSS v4.0 Requirement 5.
Scope
This policy applies to all information systems, endpoints, servers, and users within the Cardholder Data Environment (CDE), and all systems that connect to or support the CDE, whether on-premises or cloud-hosted.
Policy Requirements
Centrally Managed Anti-Malware Protection
All applicable systems must have BitDefender Endpoint Protection installed, configured, and managed centrally.
BitDefender must:
Be capable of detecting, removing, and protecting against all forms of malware, including viruses, trojans, spyware, rootkits, ransomware, etc.
Automatically update its malware signature database at least daily.
Be configured to perform real-time scanning of files and programs on access or execution.
Malware Scans and Alerts
Full system scans must be conducted at least weekly or as determined by risk assessment.
Alerts and logs for detected malware events must be:
Sent in real time to the centralized management console.
Retained for a minimum of 12 months in a secure log management system.
Reviewed at least weekly by the Information Security Team.
Handling Malware Detections
Detected malware must be automatically quarantined or deleted as per BitDefender configuration.
Incidents must be documented, escalated, and investigated in accordance with the Incident Response Policy.
Systems showing persistent or high-severity infections must be isolated from the network until they are clean.
Configuration Management
BitDefender policies must prevent users from disabling, altering, or uninstalling anti-malware protection without authorization.
Systems that do not support BitDefender must be segmented from the CDE and reviewed for compensating controls.
Coverage Monitoring and Gap Closure
A monthly audit must be performed to:
Ensure 100% anti-malware coverage on in-scope systems.
Identify and remediate any non-compliant systems.
Any new system must be onboarded to the BitDefender console before being allowed access to the network.
Roles and Responsibilities
IT/Technical Leadership: Ensures anti-malware controls are deployed, maintained, monitored, and updated on applicable systems.
System Administrators: Maintain anti-malware configurations, investigate alerts, apply updates, and escalate identified security events.
Users: Must not disable, bypass, or interfere with approved anti-malware controls and must promptly report suspicious activity.
CISO: Provides oversight of anti-malware governance, monitoring, exceptions, and compliance with applicable PCI DSS requirements.
Compliance and Exceptions
This policy is enforced as part of the organization’s overall PCI DSS compliance.
Exceptions must be approved by the CISO or Compliance Officer and must include documented compensating controls.
Review and Maintenance
This policy must be reviewed annually or upon any significant change to:
PCI DSS requirements
Malware threats
BitDefender platform or infrastructure
10. Network Security Policy
Purpose
This policy sets out the requirements for the management and support of NetPlusDotCom's information systems.
Scope
This policy applies to NetPlusDotCom's information systems and networks.
Policy Statement
Anti-malware solutions and firewalls shall be enabled on all applicable information systems and regularly updated.
All information systems shall be configured in accordance with applicable NetPlusDotCom's information security policies and procedures, and information security best practices.
Changes to applications, information systems, and network devices shall be subject to the NetPlusDotCom change management process.
Firewall rulesets shall be reviewed at least quarterly.
Wireless networks shall use strong, industry-accepted encryption and authentication. WEP and WPA shall not be used.
Security assessments shall be conducted to identify existing vulnerabilities in information systems and identified vulnerabilities remediated in line with NetPlusDotCom's information security procedures.
Internal and external network vulnerability assessments shall be conducted quarterly and when there are significant changes to the network infrastructure.
Penetration tests shall be conducted on a bi-annual basis and in the event of significant changes to the network infrastructure. These tests shall be based on recognized best-practice penetration test methodologies.
For access to the network environment, multifactor authentication mechanisms shall be implemented.
Logs of network and associated devices shall be configured in accordance with the security monitoring, and records retention and protection policy and monitored in line with ISMS and PCIDSS compliance requirements.
Events which are deemed to be network security incidents shall be recorded and managed according to the incident management process.
Access to network management tools shall be controlled and the use of insecure protocols such as Telnet are forbidden.
When disposing of network equipment, all configuration information shall be cleared in accordance with NetPlusDotCom's information security policies and procedures to prevent disclosure of confidential information.
Network equipment will be housed securely to which only authorised support staff shall have access. Wireless access points located in public areas should be hidden from view where possible and should be placed in positions where access by the public is difficult e.g., in or near the ceiling.