Information Security Policy

By using our site you accept these terms and conditions

Field Information
Version Number 1,2
Effective Date 1 August 2023
Document Owner Joshua Thornton
Approved By David Larpent
Document Reference Number ISMS-ISP-001
Last reviewed 25 Nov 2024

Purpose

 Please read these Terms and Conditions carefully and ensure that you understand them before using Our Site. These Terms and Conditions, together with any other documents referred to herein, set out the terms of use governing your use of this website, www.getlavanda.com (“Our Site”). It is recommended that you print a copy of these Terms and Conditions for your future reference.

Scope

2.1         Departments

This policy applies to all departments within Lavanda Ventures Ltd, including Operations, Engineering, Product Management, Implementation, Customer Success, Sales & Marketing. All employees, contractors, and third-party users are expected to adhere to the requirements outlined in this policy.

2.2         Types of data

The scope of this policy encompasses the handling of various types of sensitive data, including Customer Personal Identifiable Information (PII), Employee Records, Financial Data, Project Specifications, Source Code, and Testing Data. All individuals within the organization are responsible for ensuring the secure handling and protection of these data types.

2.3         Key information assets

This policy covers the protection of key information assets, such as the Customer Database, Employee Records, Financial System, Delivery Management Software, Source Code Repository, Office Network Infrastructure, Mobile and Web Applications, Company Website, and Internal Documentation. Safeguarding the confidentiality, integrity, and availability of these assets is essential to the overall information security posture of the organisation.

Information Security Objectives

The Information Security Objectives of Lavanda Ventures Ltd are as follows:

  • Ensure the confidentiality and privacy of customer and employee data through appropriate access controls and encryption mechanisms.
  • Protect the integrity of financial systems, source code repositories, and project specifications to prevent unauthorised modifications or tampering.
  • Maintain the availability and reliability of web applications, mobile apps, and enterprise software systems to support business operations and customer service delivery.
  • Comply with the requirements of the General Data Protection Regulation (GDPR) and other relevant legal, regulatory, and contractual obligations pertaining to information security.
  • Foster a culture of security awareness and accountability through regular training, communication, and awareness programs for all employees.
 
Data Classification

The data classification framework of Lavanda Ventures Ltd encompasses the categorization of data into the following levels: Public, Internal Use Only, Confidential, and Highly Restricted. Each category will have specific handling and protection requirements based on the sensitivity and criticality of the data. All employees are responsible for understanding and adhering to the data classification guidelines outlined in this policy.

Roles and Responsibilities

As per the ISO 27001 compliant Information Security Policy, the following roles and responsibilities are defined within Lavanda Ventures Ltd:

1.         Information Security Officer (ISO):
  • Joshua Thornton, Head of Engineering, is designated as the Information Security Officer (ISO) and is responsible for overseeing the development, implementation, and maintenance of the Information Security Management System (ISMS).
  • The ISO is accountable for ensuring that information security objectives are aligned with business goals and for providing guidance on information security matters.

 

2.        Departmental Heads:
  • Each department head, including Operations, Product Management, Implementation, Customer Success, and Sales & Marketing, is responsible for implementing and enforcing information security measures within their respective departments.
  • They are accountable for ensuring that their teams are aware of and comply with information security policies and procedures.
 
3.        Employees:
  • All employees are responsible for adhering to the information security policies, procedures, and guidelines established by the company
  • They are required to report any security incidents, breaches, or vulnerabilities to the designated authorities promptly.
 
Access Control

In accordance with ISO 27001 requirements, the access control measures at Lavanda Ventures Ltd are as follows:

1.         User Access Management:
  • Access to the company’s systems and data is granted based on the principle of least privilege, ensuring that employees have access only to the resources necessary for their roles.
  • User access rights are reviewed and updated regularly to align with employees’ job functions and responsibilities.

 

2.        Authentication:
  • Employees access company systems via company-issued devices only, and two-factor authentication (2FA) is mandatory for all systems and applications.
  • Strong password policies are enforced to ensure that access credentials are robust and secure.
 
3.        Data Encryption:
  • Sensitive data, including Customer Personal Identifiable Information (PII), Employee Records, and Financial Data, is encrypted both at rest and in transit to prevent unauthorized access.
 
4.        Access Monitoring:
  • The company implements logging and monitoring mechanisms to track and review access to sensitive systems and data.
  • Regular audits are conducted to ensure compliance with access control policies and to detect any unauthorised access attempts.
 
These measures are designed to mitigate the risk of unauthorized access and ensure the confidentiality, integrity, and availability of the company’s information assets.
 
Security Measures
7.1         Physical Security Measures

Our office is secured with card-based access control to restrict unauthorized entry.

Security cameras are installed at all entrances and exits to monitor and record activities.

Visitors are required to sign in and are escorted at all times to ensure they are properly authorized.

7.2         Change Management Process

All system changes are tracked through a Change Management System to maintain a record of modifications.

Changes must be approved by the Information Security Officer (Leah McCarthy) before implementation to ensure oversight and accountability.

All changes are tested in a separate environment before deployment to mitigate the risk of disruptions to operational systems.

7.3         Information Transmission Security

We encrypt all data in transit using SSL/TLS protocols to safeguard information during transmission.

Our email system uses secure email gateways for outbound and inbound traffic to prevent unauthorized access to sensitive data.

7.4      Incident Management Process

We follow a predefined Incident Response Plan for any security incidents to ensure a structured and efficient response.

All incidents are logged, investigated, and lessons learned are incorporated into our security procedures to continuously improve our incident response capabilities.

7.5      Business Continuity Plan

We have a Business Continuity Plan that includes regular data backups to prevent data loss and ensure operational resilience.

Disaster recovery sites are established to facilitate rapid recovery in the event of a catastrophic failure.

Predefined roles and responsibilities for the management team are outlined in the Business Continuity Plan to ensure a coordinated response during disruptive events.

These security measures are designed to align with ISO 27001 requirements and support our company’s compliance with legal, regulatory, and contractual obligations, including the General Data Protection Regulation (GDPR) due to the handling of EU citizens’ data.

Training and Awareness

Lavanda Ventures Ltd recognises the importance of fostering a culture of security awareness and continuous training among its employees. All employees, contractors, and third-party users with access to the company’s information systems and data are required to undergo regular security awareness training. This training will cover topics such as data protection, secure handling of customer PII, recognising social engineering attempts, and the proper use of company-issued devices.

Employees will also receive specific training related to their roles and responsibilities concerning information security. This tailored training will ensure that employees understand the security measures and best practices relevant to their day-to-day tasks. Additionally, employees will be informed about the potential risks associated with their specific job functions and how to mitigate those risks effectively.

The training program will be conducted annually, or more frequently if significant changes occur in the company’s security posture, the regulatory landscape, or the technology environment. The training materials will be regularly reviewed and updated to reflect the latest security threats, trends, and best practices. All employees are required to complete the training satisfactorily and demonstrate their understanding of the security policies and procedures.

Policy Compliance

Policy compliance is a critical aspect of Lavanda Ventures Ltd’s information security management system (ISMS). All employees, contractors, and third-party users are expected to comply with the company’s information security policies, standards, and procedures. Non-compliance with these policies may result in disciplinary action, including but not limited to warnings, suspension, or termination of employment or contract.

To ensure policy compliance, the company will conduct regular internal audits and assessments of its information security controls. These audits will verify that employees are adhering to the established policies and procedures and identify any areas of non-compliance or potential weaknesses in the ISMS. The results of these audits will be used to drive continuous improvement and corrective actions within the organization.

Employees are encouraged to report any suspected violations of the information security policies through the established reporting channels. Reports will be thoroughly investigated, and appropriate actions will be taken to address any confirmed breaches or non-compliance issues. The company is committed to creating a work environment where employees feel empowered to raise security concerns without fear of retaliation.

Review and Updates

Lavanda Ventures Ltd understands the dynamic nature of information security threats and the evolving business environment. As such, the company is committed to regularly reviewing and updating its information security policies, standards, and procedures to ensure their effectiveness and relevance.

The ISMS will undergo formal reviews at planned intervals, or in response to significant changes in the business operations, technology landscape, or regulatory requirements. These reviews will be conducted to assess the continued suitability, adequacy, and effectiveness of the ISMS in meeting its objectives and securing the company’s information assets.

Updates to the information security policies and related documentation will be communicated to all relevant employees, contractors, and third-party users. Employees will be required to acknowledge their understanding of the updates and adhere to the revised policies and procedures. Additionally, the company will maintain a documented history of changes made to the ISMS, including the reasons for the changes and the individuals involved in the review and approval process.

Definitions

Confidentiality: The principle of preventing unauthorized access to information. It ensures that information is accessible only to those authorized to have access.

Integrity: The assurance that information is trustworthy and accurate. It refers to protecting data from being altered or tampered with by unauthorized individuals.

Availability: The guarantee that authorized users have access to information and associated assets when required.

Personal Identifiable Information (PII): Any data that can be used to identify a specific individual, including names, addresses, phone numbers, and social security numbers.

Protected Health Information (PHI): Any information about health status, provision of health care, or payment for health care that can be linked to an individual.

Risk Assessment: The process of identifying, evaluating, and analyzing risks associated with organizational operations, particularly in terms of information security.

Change Management: The systematic approach to dealing with changes, both from the perspective of an organization and on the individual level.

Incident Management: The process of identifying, managing, and analyzing security breaches or attacks to prevent future occurrences.

Business Continuity Plan (BCP): A plan that outlines procedures and instructions an organization must follow in the face of disaster, in order to continue its daily operations.

Two-Factor Authentication (2FA): A security process in which users provide two different authentication factors to verify themselves.

Virtual Private Network (VPN): A technology that creates a safe and encrypted connection over a less secure network, such as the internet.

SSL/TLS (Secure Sockets Layer/Transport Layer Security): Protocols for establishing authenticated and encrypted links between networked computers.