1. Purpose
Relevate is committed to protecting the confidentiality, integrity and availability of its information, systems, services and customer data.
This policy establishes the minimum information-security expectations for all Relevate personnel and for third parties handling Relevate information or systems.
2. Scope
This policy applies to all directors, employees, contractors, temporary workers and approved third parties.
It covers Relevate-owned and approved cloud systems, devices, applications, records, customer and supplier information, and information processed on behalf of clients. It applies wherever work is performed, including remote work and travel.
3. Policy principles
Relevate personnel must:
access information only where there is a legitimate business need and approved authority;
use least-privilege access, unique user accounts and multi-factor authentication where available;
protect confidential, personal, commercial and client information from unauthorised access, loss, alteration, disclosure or destruction;
use approved systems and follow secure, documented processes for material changes; and
report suspected security incidents, privacy incidents, phishing attempts, lost devices and unauthorised access immediately.
4. Roles and responsibilities
Managing Director
Approves this policy, assigns accountability and ensures appropriate resources are considered.
Managers
Ensure staff understand and follow this policy, approve access based on role, and promptly remove or amend access when responsibilities change.
System owners
Maintain appropriate access controls, backups, updates, monitoring and documented recovery arrangements for systems they own.
All personnel
Protect credentials and devices, complete required training, use information responsibly and report concerns without delay.
Third parties
Must meet contractual security, privacy and confidentiality obligations proportionate to the service and information involved.
Information must be classified and handled according to its sensitivity.
Public information may be shared only through approved channels. Internal, confidential, personal and client information must be accessed, stored, transmitted and disposed of only through approved methods and only for authorised business purposes.
Personal information must be handled consistently with Relevate privacy obligations and applicable law. Personnel must not store company or client information in personal email, personal cloud storage, unapproved messaging tools or unapproved AI services.
6. Identity, access and authentication
Access must be role-based, approved by the relevant owner and reviewed when roles change.
Shared user accounts are prohibited unless a documented technical exception is approved. Passwords must be unique, kept confidential and protected by an approved password manager where provided.
Multi-factor authentication must be enabled for supported business systems. Access must be removed promptly when employment, engagement or a business need ends.
7. Devices, software and remote work
Company information must be accessed only from approved, supported and appropriately protected devices.
(1/2)
Devices must use current operating-system and security updates, screen locking, malware protection where applicable and encryption where supported.
Unapproved software, browser extensions, storage devices and consumer file-sharing services must not be used for company or client information. Remote workers must use secure networks and approved remote-access methods.
8. Cloud services, suppliers and change management
New cloud services, integrations, AI tools, suppliers and material system changes must be assessed before use for:
business need;
data type and sensitivity;
access model;
hosting and security controls;
privacy implications;
contractual terms; and
exit and backup arrangements.
Production changes must be authorised, documented, tested proportionately to risk and have a rollback or recovery plan where practical.
Secrets, tokens, passwords and private keys must never be placed in email, chat, public repositories or unapproved documents.
9. Data protection, backup and continuity
System owners must maintain appropriate backups and recovery arrangements for material business and client data.
Backup and recovery controls must be tested at a frequency proportionate to risk. Data retention and disposal must follow contractual, legal, operational and privacy requirements.
Information no longer required must be securely deleted or destroyed using approved methods.
10. Monitoring and incident response
Relevate may monitor company systems, access events and security alerts to protect services and information, subject to applicable law.
Suspected incidents must be reported immediately to a manager or the designated IT or security contact. Examples include phishing, malware, unauthorised access, mistaken disclosure, lost devices, suspicious account activity, data loss, or a service outage with a suspected security cause.
Relevate will assess, contain, investigate, recover, document and, where required, notify affected parties and regulators.
11. Training, compliance and exceptions
Personnel must complete assigned security and privacy training and comply with this policy and related procedures.
Breaches may result in access removal, disciplinary action, contract action or other appropriate steps.
Exceptions require documented business justification, risk assessment, compensating controls, a named owner, expiry date and approval by the Managing Director or delegated authority.
This policy should be read with Relevate’s:
- Privacy Policy;
- Acceptable Use Policy;
- Incident Response Procedure;
- Access Control Procedure;
- Backup and Recovery Procedure;
- Supplier Security Assessment; and
- staff onboarding and offboarding procedures.
This policy supports a risk-based security program. It does not claim certification or compliance with ISO 27001, the ASD Essential Eight or any other standard unless independently assessed and approved.
Reference sources