Information Security Policies

TitleInformation Security Policies
Approval Date15-12-2025
Version1.0

Table of Contents

  1. 1. Information Security Policy
  2. 2. Access Control Policy
  3. 3. Acceptable Use Policy
  4. 4. Mobile Device Policy
  5. 5. Password Policy
  6. 6. Security Monitoring Policy
  7. 7. Roles and Responsibilities
  8. 8. Supplier Policy
  9. 9. Anti-Malware Policy
  10. 10. Network Security Policy

1. Information Security Policy

Purpose

The purpose of this policy is to ensure that the NetPlusDotCom information assets and associated information systems are recognised as valuable assets and managed accordingly to ensure their confidentiality, integrity, and availability.

Scope

This policy applies to all NetPlusDotCom employees, contractors, service providers, and vendors.

Policy Statement

NetPlusDotCom Limited is committed to developing, adopting, and maintaining appropriate information security policies, standards, and procedures to ensure integration of information security with the organisation's mission, business objectives, and in accordance with applicable regulatory, legislative, and contractual requirements.

This will be accomplished by active management oversight and monitoring of information security risks and establishing appropriate organizational processes to ensure that information security risks are appropriately and regularly identified, controlled and monitored.

This policy is required to protect and ensure the security of NetPlusDotCom information assets and ensure NetPlusDotCom's compliance with applicable laws and regulations.

This policy and associated policies shall be reviewed at least annually and revised as necessary, or at a time of major change to the organisation's business processes.

2. Access Control Policy

Purpose

The control of access to NetPlusDotCom's information assets is a fundamental part of the organization’s information security strategy. Accordingly, this policy has been established to forestall the unauthorized or uncontrolled access, misuse of user privileges, or unauthorized disclosure to third parties, that may result in security breaches, damage, misuse, or theft of NetPlusDotCom's information and information systems.

Scope

This policy applies to all NetPlusDotCom's information systems. All NetPlusDotCom's personnel and contractors including vendors shall comply with this policy.

Policy Statement

Multi-factor authentication (MFA) shall be used for access to the Cardholder Data Environment (CDE) and other systems where required by applicable PCI DSS requirements. Static authentication credentials shall not be used as the sole authentication factor where MFA is required.

Default passwords for applications, operating systems, routers, firewalls, wireless devices, and other systems shall be changed or disabled before deploying new systems into the production environment. Where possible, default usernames shall also be disabled

IT systems and applications in the cardholder environment shall be configured to time out after 15 minutes of inactivity. The session shall remain terminated until an authorized user re-establishes connection

Access privileges for business users and any personnel with access to cardholder data environment (such as system administrators and software developers) should follow documented access request process and be approved by an appropriate business manager

Every user will only be granted the minimum access rights required to perform their job functions

A limit of five successive login failures will be enforced and the offending account will be locked out for 30 minutes once this threshold is breached

Normal use of accounts with administrative privileges should be studied, understood and closely monitored by cyber security to increase the chances of rapidly detecting and containing associated malicious activities

Before access privileges come into effect, users should be advised of – and be required to confirm understanding of – their access privileges and conditions of use

Access control arrangements should be supported by documented processes and procedures based on commonly adopted best practices, sensitivity of systems, legal, regulatory and contractual obligations

Access privileges should not be assigned collectively unless special circumstances apply. In exceptional cases where access privileges need to be assigned collectively, this should be documented, approved by an appropriate business manager.

Access requests to NetPlusDotCom's information and information systems shall be authorised and documented.

Access rights of suspended and exiting staff shall be immediately disabled and revoked respectively.

Access rights shall be reviewed periodically, and redundant user accounts removed.

3. Acceptable Use Policy

Purpose

The use of NetPlusDotCom's information systems and resources may expose the organisation to diverse risks such as malware, compromise of information systems, loss of data or confidential information, and legal and/or regulatory actions. This policy provides guidance for the acceptable use of NetPlusDotCom's information systems.

Scope

This policy applies to all personnel and contractors, including vendors who have authorised access to NetPlusDotCom's information and information systems

Policy Statement

All users are responsible for the protection of information in their custody or stored/processed on information systems used.

Anti-malware and other security solutions must be installed in all systems storing NetPlusDotCom's information or connected to NetPlusDotCom's information systems.

The circumvention of deployed security controls or use of unauthorised tools capable of generating, interfering, and/or intercepting network traffic is prohibited.

Email accounts are provided to NetPlusDotCom's personnel primarily for business purposes. The use of these accounts for purposes unrelated to NetPlusDotCom's business requirements is prohibited.

The initiation and/or forwarding of sensitive mails, chain emails or similar material from a NetPlusDotCom mail account or NetPlusDotCom information system is forbidden.

Users shall be responsible for the content of material viewed, downloaded, or sent while using NetPlusDotCom's information resources.

Materials that are fraudulent, harassing, embarrassing, sexually explicit, obscene, defamatory, or otherwise unlawful or inappropriate shall not be stored or sent by email or other form of electronic communication (such as bulletin board systems, chat groups, newsgroups, or Instant Messenger) using NetPlusDotCom's resources, nor may it be displayed or stored on NetPlusDotCom's information systems or network.

Information/materials created or resident on NetPlusDotCom's information systems remain the property of the organisation.

NetPlusDotCom's information systems users must not engage in internet activities, e.g. blogging, chat room, etc, that may cause damage to the organisation or expose NetPlusDotCom's confidential information. Such acts include but are not limited to attributing

personal statements or views to the organisation on such platforms, or purporting to represent the organisation on such platforms explicitly or implicitly

NetPlusDotCom's information system users shall not use the organisation’s resources to download, store or transmit materials that infringe any copyright, trademark, licensing agreement, or other proprietary right.

Work areas shall not be cluttered with handwritten or printed notes displaying confidential or sensitive information.

Confidential or sensitive information such as passwords shall not be written down.

All printed information should be stored in secure cabinets or drawers at all times

All printers, scanners, and associated devices should be cleared of papers as soon as they are scanned/copied/printed.

Laptops should be password protected and locked or switched off when unattended.

A clear screen policy shall be adopted on all NetPlusDotCom's information systems.

All technology use must be authenticated with user ID and password or other authentication item (such as a token). A list of all devices and the personnel authorized to use the devices must be maintained and reviewed on a yearly basis.

All devices must be labelled such that they can be properly tracked to a device owner or manager and device purpose.

Approved devices e.g., network devices, laptops, etc must be used in the NetPlusDotCom cloud environment and office premises as approved by management.

Any device that utilizes remote-access technologies must employ automatic disconnect of sessions after a period of inactivity.

4. Mobile Device Policy

Purpose

Mobile devices are particularly at risk of theft or loss due to their portability and size. This policy aims to protect NetPlusDotCom's information stored in mobile devices from loss or unwanted exposure, and to minimise the risk of loss or theft of mobile devices.

Scope

This policy applies to all mobile devices that may be used to store NetPlusDotCom's information. These devices include laptops, smartphone, tablets, external storage devices, memory sticks/flash drives, and all forms of portable devices.

Policy Statement

All NetPlusDotCom's supplied mobile devices and their contents remain the property of NetPlusDotCom and are subject to audit and monitoring.

The creation and use of credentials to access mobile devices shall be in accordance with the password policy and other associated policies.

Laptops and other associated devices shall be encrypted to prevent loss of NetPlusDotCom's information in the event of mobile device loss or theft.

System patches and anti-malware solutions shall be installed on mobile devices where applicable and updated periodically.

Security configurations on mobile devices shall not be changed without reference to the IT department

Mobile devices shall have property/identification tags attached and a log of issued devices shall be kept and maintained.

Mobile device content shall be backed-up on a regular basis.

Where no longer required, mobile device contents shall be removed and made unrecoverable.

The loss or theft of NetPlusDotCom's owned mobile devices shall be reported to IT.

Due care shall be exercised in the use, storage, and transportation of mobile devices.

5. Password Policy

Purpose

Passwords are an important aspect of information systems and are the front line of protection for user and system accounts. This policy sets out the requirements for the creation and usage of passwords for NetPlusDotCom's information systems.

Scope

This policy applies to all personnel, contractors including vendors who have or are responsible for an account on any NetPlusDotCom information system. All NetPlusDotCom personnel and relevant third parties must comply with the requirements of this policy.

Policy Statement

All passwords for users and information systems shall comprise a minimum of twelve characters. Application and service account passwords shall also comprise a minimum of twelve characters and consist of a combination of alphabets, numbers, and special characters. Passwords shall be managed and changed in accordance with applicable PCI DSS requirements and NetPlusDotCom's password-management procedures.

All new accounts shall require and be assigned an initial password comprising a minimum of twelve alpha-numeric characters which shall be communicated securely.

Default passwords shall be changed immediately on all information systems.

All user and administrative credentials shall be changed at least every 90 days.

New passwords shall not be the same as any of the last four passwords used

Passwords shall not be shared, written down, posted, stored or displayed in clear text.

The use of privileged passwords shall be restricted.

New passwords, for users and information systems, shall be transmitted through secure means.

Users shall be held responsible for all activity performed with their usernames.

Failure to comply with this policy may result in disciplinary action, up to and including termination of employment, legal action, and financial penalties.

Security Monitoring Policy

Purpose

The purpose of this document is to outline the NetPlusDotCom policy regarding the monitoring, logging, and retention of network events that traverse its networks. The goal of this policy is to maintain the security of NetPlusDotCom's network infrastructure through logging and monitoring of user and system events.

Scope

This policy is applicable to information assets operating in the NetPlusDotCom network.

Security Monitoring

Security monitoring is a method used to confirm that the security practices and controls in place are being adhered to and are effective. Monitoring consists of activities such as the review of firewall logs, user activities, application logs, and other applicable log files

Logs will be configured to provide real time notification of detected anomalies in user and network activities and reviewed on a daily basis. These tools will be deployed to monitor:

All Actions taken by any individual with root or administrative privileges

Access to audit trails

Event date and time

Identification and authentication mechanisms

Identity or name of affected data, system component, or resource

The following files will be reviewed for exceptions:

Firewall logs

Application logs

Security appliance logs

Where exceptions have been identified, details of the exception will be collected and reviewed from the log source and other information sources, where applicable. If the exception has been determined to be an incident, the security response plan will be activated.

Events from security tools will be configured for the timely detection of failures emanating from logical access controls, controls i.e., file integrity monitoring controls, intrusion detection and prevention, and audit logging mechanisms.

In the event of any security control failing, processes for responding to such failures would include the following:

Immediate restoration of security functions

Documentation of the failure duration of the security failure, root cause of failure, and adopted remediation measures to address the failure root cause.

Remediation of attendant security issues that occurred when the security control failed

Execution of a risk assessment to determine if additional actions are required as a result of the control failure and implementation of identified controls to prevent failure recurrence.

Resumption of security control monitoring

Security Information and Event Management (SIEM)

Security-related logs and events from systems within and supporting the Cardholder Data Environment (CDE) shall be centrally collected, monitored, correlated, reviewed, retained, and protected using approved logging and SIEM capabilities where applicable. Security alerts and identified events shall be investigated, escalated, and addressed in accordance with the incident response process and applicable PCI DSS requirements.

Log Retention Requirements

Audit trails files shall be backed up to a log server and protected from unauthorized modifications via access control mechanisms and physical segregation.

Only those with a job-related need are authorized to view audit files.

Audit trail history shall be retained for one year, with a minimum of three months immediately available for analysis.

Security Reviews

Security reviews shall be conducted on a quarterly basis to confirm applicable personnel are complying to NetPlusDotCom's security policies and operational procedures. These reviews will cover the following security processes:

Daily log reviews

Bi-annual firewall rule-set reviews

Application of configuration standards to new systems

Change management processes

Security alerts response

The outcome of this review process shall be documented and signed off by CTO

Time Synchronisation

All critical system clocks and times shall be synchronised using designated external time sources

Roles & Responsibilities Section

1. Executive Leadership

1.1 Chief Executive Officer (CEO) / President

Ultimate accountability for the organization's PCI DSS compliance program.

Provides executive sponsorship and resources for information security initiatives.

Ensures adequate budget allocation for security controls and compliance activities

Reviews and approves the annual information security policy

Accountable for security incidents and their business impact

1.2 Chief Information Security Officer (CISO) – Olatunbosun Olalegbin

Primary responsibility for developing, implementing, and maintaining the information security program

Ensures information security policy addresses all PCI DSS requirements

Oversees security awareness training programs for all personnel

Manages security incident response and reporting

Coordinates with external assessors and auditors

Reviews and updates security policies annually or as needed

Oversees the security of the organization’s network infrastructure, including network security architecture, security controls, configuration standards, and protection of systems within and supporting the Cardholder Data Environment (CDE).

Provides oversight of system administration security, including privileged access, secure configuration, patching, account management, hardening, and administrative activities affecting systems within and supporting the CDE.

Oversees the protection and encryption of stored account data and related cryptographic controls in accordance with applicable PCI DSS requirements and approved security standards.

Oversees Security Information and Event Management (SIEM) capabilities, including centralized collection, monitoring, correlation, review, retention, and protection of security-related logs and events, and ensures relevant alerts are investigated, escalated, and addressed.

2. IT and Technical Leadership

2.1 IT Senior Leadership / IT Director

Operational management of systems within the cardholder data environment

Implements technical security controls as required by PCI DSS

Ensures proper configuration and maintenance of security systems

Manages vulnerability scanning and penetration testing activities

Coordinates system updates and patches that affect PCI DSS compliance

2.2. System Administrator

Maintains server security configurations and access controls

Implements and monitors system-level security controls

Manages user accounts and authentication systems

Ensures secure system configurations and hardening

Performs regular security maintenance and updates

2.3 Database Administrator

Secures databases containing or connected to cardholder data

Implements database access controls and monitoring

Manages database encryption and key management

Performs database security assessments and hardening

Maintains database activity logs and monitoring

3. Compliance and Risk Management

3.1. Compliance Manager / Officer

Ongoing monitoring of PCI DSS compliance status

Coordinates internal compliance assessments and external audits

Maintains compliance documentation and evidence

Tracks remediation of compliance gaps and findings

Reports compliance status to senior management

4. Human Resources

4.1. HR Director / Manager

Personnel security management and background screening

Manages employee onboarding and security awareness training

Implements disciplinary procedures for security violations

Coordinates termination procedures to protect data access

Maintains personnel security records and documentation

5. All Personnel Responsibilities

5.1. Employees and Contractors

Individual accountability for following established security procedures

Protects cardholder data in accordance with company policies

Reports security incidents and suspicious activities immediately

Completes required security awareness training

Uses strong authentication and access controls

Maintains confidentiality of sensitive information

5.2 Personnel Handling Cardholder Data

Enhanced responsibilities for those with direct access to cardholder data

Follows strict data handling and processing procedures

Uses only approved methods for transmitting cardholder data

Implements proper data retention and disposal procedures

Reports any potential data compromise immediately

Complies with additional training and certification requirements

6. Committee Structure

6.1 PCI DSS Compliance Committee

Cross-functional team responsible for overall compliance program coordination

Committee Chair: CISO or designated senior security leader

Members: Representatives from IT, Business Operations, Compliance, HR, and Legal

Responsibilities:

Reviews and updates information security policies

Coordinates compliance activities across business units

Reviews security incidents and lessons learned

Approves major security initiatives and changes

Reports to executive leadership on compliance status

6.2 Project Manager (Dedicated Role)

Centralized coordination of compliance activities and documentation

Manages compliance project timelines and deliverables

Collects and maintains evidence for PCI DSS assessments

Coordinates with external assessors and auditors

Tracks remediation activities and compliance metrics

Facilitates communication between business units and committees

7. Third-Party Management

7.1 Vendor Management Team

Due diligence for third-party service providers handling cardholder data

Ensures third parties maintain appropriate PCI DSS compliance

Reviews and approves vendor security assessments

Manages contractual security requirements with vendors

Monitors ongoing vendor compliance and performance

8. Escalation Structure

8.1 Security Incident Escalation

Immediate Response: Personnel → Supervisor → IT/Security Team

Management Notification: CISO → CEO (for significant incidents)

External Reporting: Legal/Compliance team coordinates with card brands and authorities as required

9. Training and Awareness Responsibilities

9.1 Training Program Management

CISO/Security Team: Develops security awareness curriculum

HR: Coordinates training delivery and tracking

Managers: Ensures staff complete required training

All Personnel: Complete assigned training within specified timeframes

10. Documentation and Record Keeping

10.1 Documentation Responsibilities

Policy Owner (CISO): Maintains master policy documents

Process Owners: Document specific procedures and controls

Compliance Team: Maintains evidence and assessment records

8. Supplier Policy

Purpose

This policy sets out the requirements for the services and products supplied by external parties to NetPlusDotCom.

Scope

This policy applies to all contractors, vendors, and other third parties who supply products and/or services to NetPlusDotCom.

Policy Statement

Proper due diligence must be exercised before engaging with any service providers that may affect or have a relationship or function associated with NetPlusDotCom's information assets. This diligence will involve the execution of risk assessments and other similar information security activities.

Suppliers shall be identified and documented based on the service and/or product supplied, where access to NetPlusDotCom's information assets will be granted.

A current and accurate list of service providers shall be maintained, complete with contact information of applicable personnel

Access granted to NNetPlusDotCom's information assets shall be the minimal access necessary to achieve required purposes.

NetPlusDotCom's information security requirements shall be documented in contractual agreements and suppliers granted access to information assets required to comply with NetPlusDotCom's security policies and requirements.

For any services engaged with service providers that may affect or have a relationship or function associated with NetPlusDotCom's cardholder data environment, a written agreement shall include an acknowledgement by the service providers of their responsibility for securing cardholder data information.

Supplier delivery shall be monitored and reviewed periodically.

Information security awareness training shall be conducted for supplier personnel where applicable.

The compliance status of all PCIDSS service providers to applicable standard requirements shall be monitored on an annual basis.

9. Anti-Malware Policy

Purpose

This policy establishes mandatory requirements for the deployment, configuration, and monitoring of anti-malware controls to protect against known and unknown malicious software threats across all systems handling cardholder data, in compliance with PCI DSS v4.0 Requirement 5.

Scope

This policy applies to all information systems, endpoints, servers, and users within the Cardholder Data Environment (CDE), and all systems that connect to or support the CDE, whether on-premises or cloud-hosted.

Policy Requirements

Centrally Managed Anti-Malware Protection

All applicable systems must have BitDefender Endpoint Protection installed, configured, and managed centrally.

BitDefender must:

Be capable of detecting, removing, and protecting against all forms of malware, including viruses, trojans, spyware, rootkits, ransomware, etc.

Automatically update its malware signature database at least daily.

Be configured to perform real-time scanning of files and programs on access or execution.

Malware Scans and Alerts

Full system scans must be conducted at least weekly or as determined by risk assessment.

Alerts and logs for detected malware events must be:

Sent in real time to the centralized management console.

Retained for a minimum of 12 months in a secure log management system.

Reviewed at least weekly by the Information Security Team.

Handling Malware Detections

Detected malware must be automatically quarantined or deleted as per BitDefender configuration.

Incidents must be documented, escalated, and investigated in accordance with the Incident Response Policy.

Systems showing persistent or high-severity infections must be isolated from the network until they are clean.

Configuration Management

BitDefender policies must prevent users from disabling, altering, or uninstalling anti-malware protection without authorization.

Systems that do not support BitDefender must be segmented from the CDE and reviewed for compensating controls.

Coverage Monitoring and Gap Closure

A monthly audit must be performed to:

Ensure 100% anti-malware coverage on in-scope systems.

Identify and remediate any non-compliant systems.

Any new system must be onboarded to the BitDefender console before being allowed access to the network.

Roles and Responsibilities

IT/Technical Leadership: Ensures anti-malware controls are deployed, maintained, monitored, and updated on applicable systems.

System Administrators: Maintain anti-malware configurations, investigate alerts, apply updates, and escalate identified security events.

Users: Must not disable, bypass, or interfere with approved anti-malware controls and must promptly report suspicious activity.

CISO: Provides oversight of anti-malware governance, monitoring, exceptions, and compliance with applicable PCI DSS requirements.

Compliance and Exceptions

This policy is enforced as part of the organization’s overall PCI DSS compliance.

Exceptions must be approved by the CISO or Compliance Officer and must include documented compensating controls.

Review and Maintenance

This policy must be reviewed annually or upon any significant change to:

PCI DSS requirements

Malware threats

BitDefender platform or infrastructure

10. Network Security Policy

Purpose

This policy sets out the requirements for the management and support of NetPlusDotCom's information systems.

Scope

This policy applies to NetPlusDotCom's information systems and networks.

Policy Statement

Anti-malware solutions and firewalls shall be enabled on all applicable information systems and regularly updated.

All information systems shall be configured in accordance with applicable NetPlusDotCom's information security policies and procedures, and information security best practices.

Changes to applications, information systems, and network devices shall be subject to the NetPlusDotCom change management process.

Firewall rulesets shall be reviewed at least quarterly.

Wireless networks shall use strong, industry-accepted encryption and authentication. WEP and WPA shall not be used.

Security assessments shall be conducted to identify existing vulnerabilities in information systems and identified vulnerabilities remediated in line with NetPlusDotCom's information security procedures.

Internal and external network vulnerability assessments shall be conducted quarterly and when there are significant changes to the network infrastructure.

Penetration tests shall be conducted on a bi-annual basis and in the event of significant changes to the network infrastructure. These tests shall be based on recognized best-practice penetration test methodologies.

For access to the network environment, multifactor authentication mechanisms shall be implemented.

Logs of network and associated devices shall be configured in accordance with the security monitoring, and records retention and protection policy and monitored in line with ISMS and PCIDSS compliance requirements.

Events which are deemed to be network security incidents shall be recorded and managed according to the incident management process.

Access to network management tools shall be controlled and the use of insecure protocols such as Telnet are forbidden.

When disposing of network equipment, all configuration information shall be cleared in accordance with NetPlusDotCom's information security policies and procedures to prevent disclosure of confidential information.

Network equipment will be housed securely to which only authorised support staff shall have access. Wireless access points located in public areas should be hidden from view where possible and should be placed in positions where access by the public is difficult e.g., in or near the ceiling.