Information Security Management System Manual¶
Contents¶
- Version history
- General
- Purpose & Scope
- Organization Overview
- 3.1. About tecciance
- 3.2. tecciance Organizational Structure
- 4.1. Understanding the organization and its context
- 4.2. Understanding the needs and expectations of interested parties.
- 4.3. Determining the scope of the information security management system
- 4.4. Information Security Management System
- Leadership
- 5.1. Leadership and commitment
- 5.2. Organizational Roles, Responsibilities and Authorities
- Planning
- 6.1. Actions to address risks and opportunities.
- 6.2. Information Security Objectives and Planning to achieve them.
- Finance
- Delivery
- Support
- 7.1. Resources
- 7.2. Competence
- 7.3. Awareness
- 7.4. Communication
- 7.5. Documented Information
- Operation
- 8.1. Operational Planning and Control
- 8.2. Information security risk assessment
- 8.3. Information Security risk treatment
- Performance Evaluation
- 9.1. Monitoring, measurement, analysis, and evaluation
- 9.2. Internal Audit
- 9.3. Management Review
- Improvement
- 10.1. Nonconformity and Corrective Action
- 10.2. Continual Improvement
- ISMS Controls
- Organization Controls
- A.5.1. Policy For Information Security
- A.5.2. Information security roles and responsibilities
- A.5.3. Segregation of duties
- A.5.4. Management responsibilities
- A.5.5. Contact with authorities.
- A.5.6. Contact with special interest groups.
- A.5.7. Threat Intelligence
- A.5.8. Information security in project management
- A.5.9. Inventory of assets
- A.5.10. Acceptable use of assets
- A.5.11. Return of assets
- A.5.12. Classification of information
- A.5.13. Labelling information
- A.5.14. Information transfer
- A.5.15. Access control policy
- A.5.16. User registration and de-registration
- A.5.17. Authentication information
- A.5.18. Access Rights
- A.5.19. Information security policy for supplier relationships
- A.5.20. Addressing security within supplier agreements
- A.5.21. Managing information security in the Information and Communication Technology (ICT) supply chain
- A.5.22. Monitoring, review, and change management of supplier services
- A.5.23. Information security for use of cloud services
- A.5.24. Information security incident management planning and preparation
- A.5.25. Assessment and decision on information security events
- A.5.26. Response to information security incidents
- A.5.27. Learning from information security incidents
- A.5.28. Collection of evidence
- A.5.29. Information security during disruption
- A.5.30. ICT readiness for business continuity
- A.5.31. Legal, statutory, regulatory, and contractual requirements
- A.5.32. Intellectual property rights (IPR)
- A.5.33. Protection of records
- A.5.34. Privacy and protection of personally identifiable information
- A.5.35. Independent review of Information Security
- A.5.36. Compliance with policies, rules, and standards for information security
- A.5.37. Documented operating procedures.
- People Controls
- A.6.1. Screening
- A.6.2. Terms and conditions of employment
- A.6.3. Information security awareness, education, and training.
- A.6.4. Disciplinary process
- A.6.5. Responsibilities after termination or change of employment.
- A.6.6. Confidentiality or non-disclosure agreements
- A.6.7. Remote working
- A.6.8. Information security event reporting
- Physical Controls
- A.7.1. Physical security perimeter
- A.7.3. Securing offices, rooms, and facilities
- A.7.4. Physical security monitoring
- A.7.5. Protecting against external and environmental threats
- A.7.6. Working in secure areas
- A.7.7. Clear desk and clear screen policy
- A.7.9. Security of equipment and assets off-premises
- A.7.10. Storage media
- A.7.14. Secure disposal or re-use of equipment
- Technological Controls
- A.8.1. User end point devices
- A.8.2. Privileged access rights
- A.8.3. Information access restriction
- A.8.4 -Access control to source code
- A.8.5. Secure log-on procedures
- A.8.6. Capacity management
- A.8.7. Control against malware
- A.8.8. Management of technical vulnerabilities
- A.8.9. Configuration management
- A.8.10. Information Deletion
- Information deletion
- A.8.11. Data masking
- A.8.12. Data leakage prevention
- A.8.13. Logging
- A.8.14. Monitoring activities
- A.8.15. Clock Synchronization
- A.8.16. Use of privileged utility programs
- A.8.17. Installation of software on operational systems
- A.8.18. Network controls
- A.8.19. Security of network services
- A.8.20. Segregation of Networks
- A.8.21. Use of cryptography
- A.8.25 – Secure Development Life Cycle
- A.8.26. Application Security Requirements
- A.8.27. Secure System Architecture and Engineering Principles
- A.8.28 - Secure Coding
- A.8.29. Security Testing in Development and Acceptance
- A.8.30. Outsourced Development
- A.8.31. Separation of development, test, and production environments
- .8.28 Secure coding
- A.8.32. Change management
- A.8.33. Test Information
- A.8.34. Information systems audit controls
- Document Review
Version history¶
|:---|:---|:---|:---|:---| | 0.1 | 23/Apr/2024 | Initial Copy | [Name] | | | 0.2 | 18/Jun/2024 | Approved | [Name] | [Name] [Name] | | 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
General¶
This ISMS manual specifies the requirements for establishing, implementing, monitoring, reviewing, maintaining, and improving documented Information Security Management System (ISMS) within the context of the overall Business requirements. It specifies the implementation of security controls customized to the needs of tecciance.
The ISMS is designed to ensure adequate and appropriate security controls that maintain Confidentiality, Integrity, and Availability (CIA) of information assets.
Purpose & Scope¶
An information asset is anything that has business value. The purpose of this document is to protect tecciance information assets and the supporting infrastructure. This includes information assets belonging to tecciance, customers, suppliers and business partners used in the operations of tecciance.
It is the policy of tecciance:
-
To Preserve Confidentiality - Protect information assets against unauthorized disclosure.
-
To Maintain Integrity - Protect information assets from unauthorized or accidental modification ensuring. The accuracy and completeness of the organization’s assets.
-
To Ensure Availability - Ensure that Information assets are available as and when required adhering to the organization’s business objectives.
The ISMS framework described in this document is applicable to all the employees of tecciance with access to tecciance Information, Information Assets, and Information processing facilities.
Organization Overview¶
3.1. About tecciance¶
tecciance is the national cyber security agency of Sri Lanka, providing information security services and oversight.
3.2. tecciance Organizational Structure¶
The organizational structure of tecciance, which provides the overall framework for planning, directing, and controlling operations, has segregated personnel and business functions into functional groups according to job responsibilities.
Functions in tecciance
tecciance consist of the following organizational functions.
-
HR
-
Sales and Marketing
-
Admin
-
IT
-
ISMS
-
Delivery
Context of the Organization
4.1. Understanding the organization and its context¶
tecciance shall determine external and internal issues that are relevant for delivering the services and Business Operation that affect its ability to achieve the intended results of ISMS. The internal and external issues that might affect tecciance ability to achieve its “Information Security Objectives” are given below:
Internal Issues
| S No | Internal issues | Management Plan |
|---|---|---|
| 1 | Not complying with client contractual security requirements
|
|
| 2 | Upgrading ISMS in accordance to meet client expectations |
|
| 3 | Effective implementation of business continuity and disaster recovery
|
|
| 4 | Adherence to regulatory requirements and legal laws |
|
| 5 | Resource management |
|
External Issues
| S No | External Issues | Management Plan |
|---|---|---|
| 1 | Disruptions of business due to political or civil unrest/disasters
|
|
| 2 | Cyber Criminals, Nation States, Hacking community targeting tecciance employees through phishing, social engineering.
|
|
| 3 | Disruption in service due to last mile connectivity issues
|
|
| 4 | Pandemic Outbreak |
|
| 5 | Applicable laws and legislations |
|
| 6 | Technological trends |
|
4.2. Understanding the needs and expectations of interested parties.¶
tecciance shall determine:
-
Interested parties that are relevant to the information security management system.
-
The requirements of these interested parties are relevant to information security.
| Parties | Needs | Expectations |
|---|---|---|
| Employees |
|
|
| Clients |
|
|
| Shareholders |
|
|
| Government agencies / Legal and Regulatory bodies |
|
|
Emergency Services (Police, Ambulance, Firefighters, etc.)
|
|
|
Employee families
|
|
|
| Media |
|
|
Suppliers and outsourced companies
|
|
|
| Competitors |
|
|
4.3. Determining the scope of the information security management system¶
This ISMS Framework applies to all systems, people and processes that constitutes the organization’s information systems, including board members, directors, employees, suppliers and other third parties who have access to tecciance systems.
The scope of tecciance ISO 27001 certification is “The Information security management system applies to the entire organization, along with all delivery and support functions”.
4.4. Information Security Management System¶
4.4.1. Policy¶
tecciance has a well-defined and robust information security policy that has been approved and signed off by the leadership. The policy governs tecciance operations to ensure the security of information and is communicated and implemented throughout the organization. The Information Security Policy is made available as a stand-alone document and widely distributed. Please refer to “tecciance Information Security Policy” for further information.
4.4.2. Achieving Information Security Objectives¶
To achieve our Information Security objectives, we have established, implemented, maintained, and continually improve our Information Security Management System (ISMS) in line with the International Standard for Information Security, ISO/IEC 27001:2022. tecciance has adopted “Plan-Do-Check-Act” methodology to build, assess, review, and maintain the Information Security Management Systems.
tecciance has established ISMS framework as required by ISO/IEC 27001:2022. ISMS framework addresses the approach to risk management, assets to be protected, control objectives, selected controls and the degree of assurance required. All the relevant domains of ISO/IEC 27001:2022 are addressed in the ISMS Framework.
Leadership¶
5.1. Leadership and commitment¶
The Leadership Team demonstrates leadership and commitment for achieving the objectives of our information security management system by taking accountability for the effectiveness of our information security management system and ensuring that:
-
tecciance has a well-defined Information Security policy that is approved by the Management.
-
Information security roles and responsibilities are defined and established.
-
Clear communication on the importance of effective information security management and of conforming to the management system requirements.
-
tecciance has a well-defined Risk Management Procedure for establishing the risk management process and defining criteria for accepting risks and acceptable level of risks.
-
All personnel are encouraged to contribute to the effectiveness of the information security management system.
-
Continual improvement is actively promoted.
-
Yearly ISMS internal audits are organized by the ISMS Team in collaboration with the internal auditors.
5.2. Organizational Roles, Responsibilities and Authorities¶
Information Security is everyone’s responsibility, although the ultimate responsibility resides with Leadership. tecciance’s Information Security Management System Team (ISMS) has the responsibility of promoting Information Security organization wide. This team shall govern and ensure compliance with the ISMS framework. The relevant support functions shall implement and practice ISMS framework. Information Security roles and responsibilities are clearly defined and established. All personnel with access to tecciance’s information, information assets and information processing facilities shall abide by the security roles and responsibilities.
|
|
|
|---|---|---|
|
|
|
|
|
|
| ISMS Team |
|
|
| HR Team |
|
|
| Employees |
|
|
| Risk Owner |
|
|
Planning¶
6.1. Actions to address risks and opportunities.¶
6.1.1. General¶
When planning for the information security management system, tecciance shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to:
-
Ensure the information security management system can achieve its intended outcome(s)
-
Prevent, or reduce, undesired effects.
-
Achieve continual improvement.
tecciance shall plan:
-
Actions to address these risks and opportunities.
-
How to
-
Integrate and implement the actions into its information security management system processes.
-
Evaluate the effectiveness of these actions.
6.1.2. Information Security Risk Assessment¶
tecciance has a well-defined risk management framework that addresses standard, legal, regulatory, and contractual requirements. The risk management process consists of risk assessment, risk treatment, risk monitoring & review, and Communication & Consultation. Risk assessments are performed every once a year. This establishes processes for reviewing existing risks, performing periodic risk assessments, and proactively responding to risks. The results of risk assessment determine the appropriate management action and priorities for managing information security risks, and for implementing the selected controls to protect against these risks. Please refer to tecciance Risk Management Procedure for further information.
6.1.3. Information Security Risk Treatment¶
Based on the Risk Assessment report, the ISMS team prepares the Risk Treatment Plan, which includes selection of controls. The controls identified during risk assessment shall be implemented to counter risks for information / information assets. The risk owner shall identify what additional controls shall be implemented, who is responsible for them and the target date of closure. The purpose of additional controls selection and implementation is to reduce risk to an acceptable level.
Appropriate control objectives and controls have been determined from Annexure A of ISO/IEC 27001:2022 and implemented to meet the requirements identified by risk assessment process to reduce risks to an acceptable level.
The Statement of Applicability (SoA) document shall be developed based on the applicable controls. Please refer to tecciance’s SoA document.
**
6.2. Information Security Objectives and Planning to achieve them.¶
To achieve our Information Security objectives, we have established, implemented, maintained, and continually improve our Information Security Management System (ISMS) in line with the International Standard for Information Security, ISO/IEC 27001:2022.
HR
| S.NO | Objective | Procedure | Metrics | Threshold | Review frequency |
|---|---|---|---|---|---|
| 1 | Background Check | HR Policies | On time completion of Background check | 95% | Semi Annually |
| 2 | Security Awareness | Information security Policy | Percentage of employees passed the security awareness assessment | 95% | Monthly |
| 3 | Risk Treatment | tecciance -ISMS Risk Management Procedure | Percentage of risk closed | 85% | Quarterly |
| 4 | Access Control Review | Access Control Policy | Monthly Access Reconciliation | 100% | Monthly |
| 5 | Policy/Procedure review | Information security Policy | Annual Review of HR Policy/ Procedures with respect to the ISO 27001 standards/requirements | 100% | Annual |
ISMS
| S. No | Objective | Procedure | Metrics | Threshold | Review frequency |
|---|---|---|---|---|---|
| 1 | Audit Finding Closure (Internal & External Audit) | Internal Audit Process | Percentage of Closed Findings | 85% | Monthly |
| 2 | Incident Reported Metrics | Incident Management Procedure | Time lapse between Incident Happened and Reported Time | Less than 24 hours | Monthly |
| 3 | Incident Resolution Metrics | Incident Management Procedure | Time lapse between Incident Reported to closure | As documented in Incident Management procedure | Monthly |
| 4 | ISMS Documentation Annual Review | ISMS Manual | % of ISMS documentation reviews completed | 100% | Annually |
| 5 | BCP Exercising Review | Business Continuity Exercising Calendar | % of Planned Exercises Completed | 100% | Annually |
| 6 | Reduce Risk exposure within the organization | ISMS-Risk Management Procedure | No of High Risks Open | 10% | Monthly |
| 7 | Number of Risks Accepted | ISMS-Risk Management Procedure | No. of Risks Accepted | \<25% | Monthly |
| 8 | Risk Treatment | tecciance -ISMS Risk Management Procedure | Percentage of risk closed | 75% | Quarterly |
| 9 | Access Control Review | Access Control Policy | Monthly Access Reconciliation | 100% | Monthly |
| 10 | Policy/Procedure review | Information security Policy | Annual Review of ISMS Policy/ Procedures with respect to the ISO 27001 standards/ requirements | 100% | Annual |
IT
| S.NO | Objective | Procedure | Metrics | Threshold | Review frequency |
|---|---|---|---|---|---|
| 1 | Risk Treatment | tecciance -ISMS Risk Management Procedure | Percentage of risk closed | 85% | Quarterly |
| 2 | Access Control Review | Access Control Policy | Monthly Access Reconciliation | 100% | Monthly |
| 3 | Policy/Procedure review | Information security Policy | Annual Review of IT Policy/ Procedures with respect to the ISO 27001 standards/requirements | 100% | Annual |
| 4 | Security Compliance Metrics for Endpoints
|
IT Access Control / IT – Global Asset List | Percentage of Compliant Machines with respect to the compliance entities | 95 % | Monthly |
Finance¶
| S.NO | Objective | Procedure | Metrics | Threshold | Review frequency |
|---|---|---|---|---|---|
| 1 | Risk Treatment | tecciance -ISMS Risk Management Procedure | Percentage of risk closed | 85% | Quarterly |
| 2 | Access Control Review | Access Control Policy | Monthly Access Reconciliation | 100% | Monthly |
| 3 | Policy/Procedure/SOP review | Information security Policy | Annual Review of Department/Function specific Policy/ Procedures/SOPs with respect to the ISO 27001 standards/requirements | 100% | Annual |
Delivery¶
| S.NO | Objective | Procedure | Metrics | Threshold | Review frequency |
|---|---|---|---|---|---|
| 1 | Sourcing Candidates | tecciance HR Manual | Percentage of Candidates placed at client based | 95% | Quarterly |
| 2 | Screening of Candidates for education and experience | tecciance HR Manual | Ration of Candidates sourced vs placed | 95% | Quarterly |
| 3 | Perform BGV | tecciance HR Manual | As per the agreed SLA with the client. | 100% | Quarterly |
| 4 | Candidate replacement for clients (in the event of resignation or termination) | tecciance HR Manual | As per the agreed SLA with the client. | 100% | Monthly |
Support¶
7.1. Resources¶
The management provides resources for the implementation, maintenance, and review of the ISMS. The resources include funds, tools, human resources, and any other resources that may be required for the efficient performance of the ISMS.
Periodically tecciance evaluates resource requirements for improvements in security infrastructure based on RA and audit records. Based on resource requirements, the Management approves/ allocates the required resources.
The Leadership Team ensures that all necessary resources are available to:
-
Implement and maintain this information security management system.
-
Continually improve its effectiveness.
Resources and resource allocation are assessed and monitored during Management review meeting. The Management review meeting shall be conducted on an annual basis.
7.2. Competence¶
Personnel who have experience and expertise in the information security domains are assigned to manage ISMS. Whenever feasible, experienced individuals are available and allocated appropriate responsibilities. When the required levels of skill and expertise are not available, training is provided to ensure skill / knowledge enhancement as per tecciance’s training process. The ISMS training should form an integral part of the training curriculum of the HR Dept. in association with the ISMS Team.
Identifying what training is needed, and how frequently, for specific positions.
-
Conducting online training programs and circulating Awareness template among employees.
-
Organizing the training program.
-
The ISMS team shall conduct security awareness sessions for all the employees and interns as and when required.
-
Maintaining attendance records, course outlines of all training conducted.
The HR Team maintains records of Infosec training programs and the evidence of competency records.
7.3. Awareness¶
Personnel doing work under the organization’s control shall be aware of:
-
Information security policy
-
The changes in environment and new threats, vulnerabilities, security incidents/breaches are also considered while developing the training and awareness content.
-
All updates in organization policies & procedure, which are relevant to their job function.
-
All personnel undergo Information Security Awareness Training which covers Information Security essentials as part of induction / joining formalities.
-
Security Awareness assessments shall be conducted for all employees on an annual basis.
7.4. Communication¶
Users shall be made aware of the risk of Information Security while exchanging information through Voice, Email Communication facility.
External Communication
|
|
|
|
|
|---|---|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Internal Communication
ISMS Team and HR manage internal communication specifically. HR are responsible for
- The internal communication of information that has been approved by the Top Management related to policies.
ISMS Manager is responsible for ensuring:
-
That information flows across various part of the organization
-
Ensuring that lessons learnt from non-conformities are communicated to relevant business owners.
-
Reports on information security weakness and improvement are presented to management in Review meetings.
|
|
|
|
|
|
|
|---|---|---|---|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
7.5. Documented Information¶
7.5.1. General¶
The organization’s information security management system shall include:
-
Documented information required by this International Standard; and
-
Documented information determined by the organization as being necessary for the effectiveness of the information security management system.
7.5.2. Creating and Updating¶
tecciance has a well-defined Document Control methodology and all documents that are required for tecciance shall be created and updated as per the defined methodology. Sample control template that applies to every policy/procedure document is provided below.
Version History:
| Version Number | Date | Description | Created By | Reviewed By |
|---|---|---|---|---|
- Department Code:
| Department | Department Code |
|---|---|
| Information Technology | IT |
| Human Resources | HR |
| Information Security | ISMS |
-
Version Number: All documents have a version starting from 1.0. Draft documents are prior to initial release. Every document change will be incremental. Any major changes in the document will go for changes like 1.0 to 2.0. In case of minor changes in the document numbers will change after decimal e.g., 1.0 to 1.1.
-
Date: The approval date of the document to be mentioned
-
Level of Security: The data classification of the document to be mentioned based on the Data classification table.
-
Prepared By: Role or entity that is responsible for the content and who owns the document.
-
Reviewed By: Role responsible for reviewing the policy/process/document.
-
Modification history: Changes performed in the past with related details.
7.5.3. Control of documented information¶
List of all documents and records are maintained on the tecciance SharePoint. Refer tecciance Master List Tracker Document tracker.
Operation¶
8.1. Operational Planning and Control¶
- Selected control objectives and controls are implemented effectively in tecciance and it ensures that processes are established to achieve the ideal of “access to least privilege” and “separation of duties” for creation, use and dissemination of information.
As part of operationalizing the security strategy, the following are performed:
-
Ensuring that the security initiatives and security processes are aligned with the security strategy.
-
Establishing a strong management commitment
-
Ensuring that all personnel and stakeholders are engaged.
-
Detailed risk assessment is carried out to identify potential issues and vulnerabilities in implementation.
-
Assessing current capabilities and gaps
-
Providing adequate resources and budgets
-
Building and maintaining competencies that enable personnel to effectively perform their roles and responsibilities.
-
Ensuring compliance with statutory and regulatory requirements.
The risk owners are responsible for the risks associated with their assets. They must document and implement Information Security processes that ensure the security of their information / information assets is maintained and is in line with the Information security policy and security objectives. Any planned changes to the tecciance environment (that has impact on the CIA) shall be done after reviewing the consequence of the changes and planning for the mitigation of any adverse effects.
Records shall be identified and maintained to provide evidence of conformity to the effective operation of the ISMS taking into consideration relevant legal, regulatory requirements and contractual obligations.
8.2. Information security risk assessment¶
tecciance shall perform information security risk assessments on a yearly basis or as and when needed based on the severity of the internal audit findings and reported incidents or changes in the environment.
Documented information of the results of the information security risk assessments shall be maintained. Please refer tecciance Risk Register for more information.
8.3. Information Security risk treatment¶
The information security risk treatment plan developed shall be implemented and the documentation related to the implementation and the actions taken to mitigate the risks shall be maintained.
Performance Evaluation¶
9.1. Monitoring, measurement, analysis, and evaluation¶
To ensure that the identified security objectives are met, tecciance shall evaluate the information security performance through well-defined metrics. Metrics are established to assess the effectiveness of the implemented information security management system (ISMS). Department-wise metrics shall be derived and tracked based on all departments meeting their objectives and the same will be reviewed monthly.
9.2. Internal Audit¶
tecciance has a well-defined internal audit process that defines an independent internal verification and validation process to ensure that organization conforms to the specified information security policies and procedures and relevant external requirements (client specific, legal, and regulatory requirements). Internal Audit methodology elaborates on the responsibilities of various personnel involved, requirements for planning and conducting audits, reporting results, and maintaining records.
-
ISMS Internal audits shall be performed by selecting audit areas to ensure effectiveness of ISMS implementation by ISMS team as per the audit calendar.
-
Internal Audits will be planned yearly to validate the implementation of ISMS objectives and controls. Results of internal audits are input to management review, especially those for which a management decision is required.
-
The audit criteria, scope and methods shall be defined before the audit.
-
The selection of auditors to conduct the audit shall ensure objectivity and impartiality of the audit process.
Auditor Qualifying Criteria
-
Lead Auditor to be a Certified ISO27001:2022 Lead Auditor.
-
The qualifying lead auditor should not have any governance responsibilities on the scoped audit function.
-
The lead auditor will be independent and remain impartial to the auditee and process throughout the Audit.
-
Internal Auditors to have a fair understanding of ISMS standards, applicable procedures, or other documents.
-
Relevant stakeholders responsible for the area audited shall ensure that actions are taken without undue delay to eliminate detected non-conformances and their causes.
-
Follow up and closure of ISMS audit findings shall be done by ISMS Team.
-
The audit findings, action taken, and verification results shall be documented and recorded.
Procedure
-
The Lead Internal Auditor is an independent auditor who has not implemented or has governance roles for tecciance ISMS program.
-
The Lead Internal Auditor prepares the audit plan covering the frequency and methods of the audit.
-
The audit plan takes into consideration the status and importance of the processes and areas to be audited, the Risk Assessment report, as well as the results of previous audits.
-
Internal Audit plan is reported to the management. After seeking approval on the Audit Plan, respective function owners are communicated with the Audit plan.
-
The Internal Audit Team performs the audit. During the audit, ISMS Audit Team tries to find adequate evidence to ascertain that:
-
The information security policy is still an accurate reflection of the business requirements.
-
An appropriate risk assessment methodology is being used.
-
The documented procedures are being followed (i.e., within the scope of the ISMS) and are meeting their desired objectives.
-
Technical controls are in place, are correctly configured and working as intended.
-
The residual risks have been assessed correctly and are still acceptable to the management of the company.
-
The agreed actions from previous audits and reviews have been implemented.
-
The ISMS is compliant with ISO 27001
1) Non-Conformity (NC)
A NC is raised whenever there is evidence of the non-conformity of the policy or any of its elements, which in the judgment of the auditor can severely compromise the security of the organization and therefore may result in loss of Confidentiality, integrity and/or availability. A NC can be raised in the absence of “intent, implementation and/or effectiveness” as specified in the requirements of the ISO/IEC 27001: 2022 specification.
1. Major Nonconformity
The definition of a MAJOR nonconformity:
-
Total breakdown of system, control, or procedure
-
Absence of a standard (ISO 27001) requirement
-
Several minors related to the same clause.
-
A nonconformity that experiences and judgment indicate will likely result in ISMS failure or materially reduce its ability to assure controlled processes and products.
2. Minor Nonconformity
The definition of a MINOR nonconformity:
-
Failure to conform to a requirement which (based on judgment and experience) is not likely to result in ISMS failure.
-
A single observed lapse or isolated incident
-
Minimal risk of nonconforming product or service or security
2) Observation
- An observation is a situation other than NC where a potential NC may arise in future or can affect the compliance to the policy.
3) Opportunity for Improvement
- Opportunity for improvement is a situation where additional effectiveness on the process already implemented is expected with a modified approach.
Corrective Actions
The auditor shall:
-
Identify nonconformities of the implementation and/or operation of the ISMS.
-
Review the corrective action taken.
-
Ensure that corrective action is implemented.
-
Present the report to the top management team.
Please refer to tecciance - Audit Tracker for more information.
9.3. Management Review¶
The Steering Committee of tecciance shall review an organization’s Information Security Management System once every year to ensure its continuing suitability, adequacy, and effectiveness. The meeting shall be chaired by CISO, and steering committee shall be part of the meeting. MOM shall be maintained as output document of this review.
The agenda shall include but not limited to assessing our information security management system’s continuing alignment to our strategic direction, opportunities for improvement, the need for changes, previous audit results, nonconformity, and corrective action etc.
Improvement¶
10.1. Nonconformity and Corrective Action¶
tecciance should take the necessary action to eliminate the cause of nonconformities with respect to Information Security requirements to prevent recurrence.
-
Nonconformities shall be identified through ISMS internal audits.
-
The cause of nonconformities shall be determined with the knowledge gained through ISMS audits and from the results of root cause analysis. The need for appropriate action (to mitigate the root cause) shall be evaluated to ensure that non-conformities do not recur.
-
Corrective actions shall be implemented based on output from ISMS audit (internal / external), risk assessments, and reported incidents.
-
Corrective action shall be reviewed by calling for evidence and verifying it.
10.2. Continual Improvement¶
tecciance shall determine action to be taken to eliminate the causes for potential nonconformities with respect to Information Security requirements to prevent their occurrence.
-
Potential nonconformities and their causes shall be identified through feedback from relevant stakeholders and through ISMS internal audits and incident occurrences.
-
Appropriate countermeasures shall be implemented to reduce the occurrence of potential problems.
-
The results of the action taken shall be reviewed through follow-ups and ISMS internal audits to ensure their effectiveness.
Effectiveness of ISMS shall be continually improved using information security policy, information security objectives, audit results, analysis of monitored events, corrective and preventive actions and periodic management reviews.
ISMS Controls¶
Organization Controls¶
A.5.1. Policy For Information Security¶
tecciance has a well-defined and robust Information Security policy that has been approved and signed off by the leadership. Refer tecciance Information Security Policy – tecciance-POL-ISMS-ISP
- Policies for information security
Information Security policy of tecciance is developed by ISMS Team. Other Policies for information security are developed by respective teams and are approved by Function Heads. Information Security Policy is communicated to all employees.
- Review of the policies for information security
Information security policies shall be reviewed annually by the Leadership to ensure its continuing suitability, adequacy and effectiveness taking into consideration changes in the organizational environment, business circumstances, legal conditions, or technical environment.
A.5.2. Information security roles and responsibilities¶
- Internal Organization
At the highest level of management, the Senior Directors actively support Information Security within the organization through clear direction setting. Oversight of the ISMS is performed by the Chief Information Security Officer (CISO). The Top Management, chaired by Senior Directors and CISO shall meet half yearly or when required based on the severity of reported security incidents or breaches. tecciance has established an Information Security Management System Team who has the responsibility of promoting Information Security company wide. This team shall govern and ensure compliance with the ISMS framework.
The relevant functions like HR, Delivery and IT shall implement and practice ISMS framework.
Information Security roles and responsibilities are clearly defined and established. All personnel with access to tecciance’ information, information assets and information processing facilities shall abide by the security roles and responsibilities.
A.5.3. Segregation of duties¶
-
Conflicting duties and areas of responsibilities shall be segregated to reduce and opportunities for unauthorized or unintentional modification or misuse of organization’s assets and processes.
-
Roles and responsibilities shall be clearly defined and established to prevent and detect the risk of accidental or deliberate misuse of information and associated systems. Care shall be taken to ensure that no single person can access, modify, or use assets without authorization or detection. Wherever segregation of duties is not feasible due to the nature of work, controls shall be established such as monitoring of activities, audit trails and managerial supervision.
A.5.4. Management responsibilities¶
Management shall set the direction for the security posture of the organization. The tone set at the top shall encourage employees to adhere to tecciance Information security policies and processes.
Management shall brief all employees on the security roles and responsibilities and the information security policies and procedures commensurate to their roles and responsibilities. Management shall take appropriate disciplinary action on any employee found to have violated the information security policies and procedures or found to have caused an information security breach.
Management shall ensure that all employees adhere to applicable information security policies and procedures when accessing tecciance / Client Information or information assets.
A.5.5. Contact with authorities.¶
In tecciance, all the employees are working from their home location in the different geographical regions of India. The HR shall maintain and circulate the list of relevant authorities to be contacted in different situations.
A.5.6. Contact with special interest groups.¶
ISMS team shall ensure that timely and relevant specialist information security advice is obtained from internal and/or external sources to maximize the effectiveness of the tecciance information security framework. Contact with special interest groups is a means to:
-
Share and exchange information about new technologies, products, threats, or vulnerabilities.
-
Ensure understanding of the current security environment.
-
Gain knowledge of the best security practices and being up to date with relevant security landscape.
A.5.7. Threat Intelligence¶
-
The Threat Monitoring Team will ensure that the Information security threats that are related to the confidentiality, integrity and availability of information used in an organization are analyzed and reported. These can cause potential harm to a firm’s information or information system that could lead to unauthorized access, change or destruction of sensitive data or disruption of business processes.
-
Information security threats can be internal or external. Internal threats come from within an organization while external threats originate from outside the organization.
A.5.8. Information security in project management¶
Information security requirements have been integrated with tecciance projects. tecciance ensure that information security risks and issues are identified and addressed as part of each project. This will be assessed by the ISMS team at least once a year during internal audits or a separate assessment for the projects.
Furthermore, the delivery head shall conduct weekly engagement health surveys to assess gaps in projects regarding deliverables or resources. The health survey shall assess the needs of the tecciance resources involved in engagements and keep the leadership informed on the progress. Apart from the weekly health surveys, a quarterly health assessment shall be conducted to ensure the project deliverables are met.
A.5.9. Inventory of assets¶
tecciance are committed to managing the lifecycle of their IT assets and everyone has a duty to take care and protect IT assets whether they are in use, storage, movement or in disposal. IT assets shall be protected against physical or financial loss whether by theft, mis-handling or accidental damage either through primary prevention (e.g., physical security) or remediation (e.g., marking).
All IT assets shall be traceable and auditable throughout the entire lifecycle. Information about all IT assets shall be recorded in an asset register that helps to manage, track and audit throughout the entire lifecycle. Asset register to be reviewed monthly.
|
|
|
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
- Ownership of assets
All information and assets associated with information processing facilities shall be owned by tecciance.
A.5.10. Acceptable use of assets¶
All tecciance and tecciance client assets shall be used for business purposes as defined in the informationsecurity policy.
- All tecciance employees:
Shall acknowledge the need for protecting tecciance information and perform their daily activities in
Compliance with the information security policy.
Shall not participate in illegal activities such as unauthorized access of assets, hacking, introducing any computer contaminant or computer virus, committing acts which may disrupt use of the assets.
The IT Team shall monitor and record the use of any IT systems. Actual or suspected misuse of these systems shall be reported to the management. Refer tecciance Acceptable Usage Policy tecciance-POL-IT-AUP
- Handling of assets
Employees shall adhere to the information classification and handling procedure when dealing with tecciance information. Information shall be handled, processed, stored, communicated, and protected as per its classification level.
A.5.11. Return of assets¶
All employees shall return all information assets issued to them upon notification separation (disengagement from the organization). tecciance Asset Register is updated as and when there are changes.
A.5.12. Classification of information¶
tecciance has established a framework for classifying data based on its sensitivity, value, and criticality to the organization, so that sensitive data can be secured appropriately. Information Owner shall classify information as per the defined information classification Method. Material that is freely available in the public domain, available on the Internet, or other public media, is considered as “Public”. All employees shall protect the information in a manner commensurate with its value as determined by its information classification and ensure that sensitive information handled by them is protected from improper access, disclosure, modification, or loss.
There are four types of Data classification used at tecciance:
-
Public
-
Information is not confidential and can be made public without any implications for tecciance.
-
Impact of Unauthorized Disclosure / Loss: Low
-
Internal
-
Information is restricted to approved internal circulation, which is available for access to all employees for the purpose of performing their day-to-day work and such information is protected from external access.
-
Impact of Unauthorized Disclosure / Loss: Medium
-
Confidential
-
Information collected, processed, and used by tecciance in the conduct of its business to employ people, to log and fulfil client orders, and to manage all aspects of corporate finance.
-
Access to this information is restricted within certain groups based on business need. The high levels of integrity, confidentiality, and restricted availability are vital.
-
Impact of Unauthorized Disclosure / Loss: High
-
Client Confidential
-
Information received from clients in any form for business purposes by tecciance would fall under this category.
-
Impact of Unauthorized Disclosure / Loss: Very High
A.5.13. Labelling information¶
tecciance ensure that information is classified based on its value, sensitivity, and criticality. The classified information is appropriately labelled, protected, handled, and destroyed as per the defined information classification mentioned above. (More elaborate)
A.5.14. Information transfer¶
- Information transfer policies and procedures
Exchange agreements shall be established for the exchange of information and software between the organization and external parties. The agreements shall be in the form of MSA or SoW. All exchange of information and software shall be guided as per the contractual requirements.
IT and Project Leads shall ensure that controls are established over information and software licensing agreements to ensure:
-
Confidentiality of information
-
Safeguarding of Intellectual property (information/software)
-
Integrity of the information
-
Agreements on information transfer
Exchange agreements shall be established for the exchange of information and software between the organization and external parties. The agreements shall be in the form of MSA or SoW. All exchange of information and software shall be guided as per the contractual requirements.
IT and Project Leads shall ensure that controls are established over information and software licensing agreements to ensure:
-
Confidentiality of information
-
Safeguarding of Intellectual property (information/software)
-
Integrity of the information
-
Electronic messaging
Email provided by tecciance is considered as a tecciance information asset and is provided to personnel for business purposes only. Personal use is strictly discouraged.
Personnel are made aware of the acceptable use of email through security awareness training. Personnel shall take utmost care and ensure that:
-
The emails are addressed and sent to intended recipients only.
-
All attachments are scanned for viruses and for any objectionable content.
-
Attachments from unknown or unverifiable sources shall not be opened.
-
Junk and spam mails are deleted.
Personnel shall not read other personnel’s emails without their permission or approval. The following shall be treated as unauthorized use of email (this list is not exhaustive):
-
Transmitting or storing offensive material.
-
Sending fraudulent, harassing, or obscene mails.
-
Soliciting for political, personal, religious, or charitable causes or other commercial ventures outside
-
the scope of the employment and the employee’s responsibilities towards the organization.
-
Sending or forwarding chain mail, hoax mails.
-
‘Mail bombing’ (re-sending the same e-mail repeatedly to one or more recipients)
-
Personnel violating the acceptable use of email shall be subjected to appropriate disciplinary action depending on the severity of breach.
A.5.15. Access control policy¶
tecciance have implemented access control to information based on business and security requirements. It ensures that only authorized personnel have access to information, information assets and information processing facilities. Access will be provided on a “need to know” and “need to have” basis. Logical access is essentially controlled through User ID and password.
Every department/engagement shall maintain an access control tracker to record access privileges of employees who have access to the respective environments. The ISMS team shall review the access control sheets on a minimum of a quarterly basis and give a score for each department based on how accurately the ISMS access control process is followed. The scores will include metrics based on timely submission of tracker within the defined target date, proper access provisioning and deprovisioning, overall maintenance. The overall department wise metrics will be calculated as per the tecciance’ department objectives.
- Access to network and network services
Access to the network service (Internet) shall be controlled. Controls are implemented to prevent employees accessing non-business-related websites.
A.5.16. User registration and de-registration¶
tecciance has well defined process for user registration and de-registration. Based on the notification received from HR, IT will create the Google cloud platform
Inactive user IDs are tracked, and necessary actions are taken. IT will also ensure that redundant user IDs are not issued to any other users. Refer tecciance IT Manual tecciance-MAN-IT-ITM.
A.5.17. Authentication information¶
- Management of secret authentication of users
The allocation of passwords shall be controlled through a formal management process. Users shall change their password immediately upon first logon. Employees shall create and maintain passwords as per the Password policies. IT shall ensure default user IDs shall be deactivated or removed and passwords for such default accounts shall be changed.
- Use of secret authentication information
tecciance has a well-defined Password Usage policy that defines good security practices in the selection and use of passwords. The importance of password confidentiality is also emphasized through security awareness training.
-
Employees shall not disclose passwords to anyone. Personnel shall not keep records (e.g., paper, electronic etc.) of passwords.
-
Employees shall adhere to the password usage policy and any non-compliance shall be dealt with appropriate disciplinary actions.
Personnel shall report to contact@tecciance.lk or contact@tecciance.lk f they suspect password compromise.
- Password management system
Systems that manage passwords shall be interactive and shall ensure quality passwords. The passwords management system shall enforce the use of unique user ID and passwords to ensure accountability.
-
Users shall be forced by the system to change their initial password upon first logon to a password that meets the password standards.
-
The system shall enforce the use of quality passwords.
A.5.18. Access Rights¶
- User access provisioning
Employees are provided the required access on a “need to have” basis. Access is provisioned only with the approval of the relevant Project Managers.
For tecciance employees working on client environment, client’s access management process shall be adhered to. Clients shall be notified of employees on-boarding and off-boarding from the account.
- Review of user access rights
Function Head/Project Leads shall review the access rights of personnel at regular intervals. The access rights of all employees and interns to the information and information processing facilities shall be removed upon termination of their employment, contract, or agreement, or reviewed and revised upon any organizational or functional role change.
- Removal or adjustment of user access rights
The process of separation from tecciance may be due to following reasons:
-
Resignation
-
Termination
-
Retirement
-
Absconding
A notification shall be triggered from the HR to the relevant stakeholders (like IT, Project Leads) for separation.
In case of separation from the organization, relevant Project Lead shall ensure that reference to this user is removed from any documentation that identifies him/her as a current member of the organization and emailing lists. Access to client information processing facilities shall be removed upon termination of their employment, contract, or agreement by informing the Clients.
A.5.19. Information security policy for supplier relationships¶
tecciance has described how relationships with third party suppliers will be created and managed ensuring effective Information Security.
A.5.20. Addressing security within supplier agreements¶
Information security requirements are addressed as part of the supplier agreement, and necessary controls are implemented based on the risk category of the supplier. Following Information security requirements will apply to all suppliers/Third Party providers/vendors of tecciance:
-
Service Agreement with Vendor shall define their information security responsibilities in the agreement.
-
Vendors must ensure compliance with the service contractual agreements and the security addendums which are mutually agreed.
-
In case of non-compliance, tecciance will work with Vendors to ensure they implement improvement plans and take corrective actions.
-
Every Vendor resource granted access to tecciance Information Resources must sign the tecciance’ s Third-Party Non-Disclosure Agreement.
-
Vendors should get written approval from tecciance point of contact to work outside of contracts' defined parameters.
-
Vendors must handle tecciance / tecciance’ s Client data with due care and ensure the data is.
-
secured/protected across all the transactions.
-
Upon departure of a 3rd-party employee from a contract, for any reason, the 3rd-party will ensure all the asset & sensitive information is collected and returned to tecciance.
-
Vendor personnel must report any security incidents related to tecciance directly to contact@tecciance.lk or contact@tecciance.lk.
-
Vendors must implement and maintain a process to ensure secure destruction and/or deletion or hand over all tecciance Data as per agreement when exiting from the contract.
-
Vendors have access to Personal information should ensure the compliance with local privacy regulations.
A.5.21. Managing information security in the Information and Communication Technology (ICT) supply chain¶
- Information and communication technology supply chain
tecciance shall ensure that security requirements are included in the agreement with suppliers who provide services to tecciance. The Functional Head shall identify the risks to the information and information processing facilities and shall ensure that appropriate controls are implemented before granting access to external parties.
A.5.22. Monitoring, review, and change management of supplier services¶
- Monitoring and review of supplier services
The respective functions shall monitor and review the records and reports provided by suppliers to ensure that the information security terms and conditions of the agreements are being adhered to. The following shall be monitored and reviewed (including but not limited to):
-
Service performance levels to check adherence to the agreements.
-
Service reports produced by the supplier.
-
Supplier’s capability to maintain service continuity.
-
Managing changes to supplier services
The respective functions along with other relevant stakeholders shall manage the changes to the provision of services, considering the criticality of business systems, processes involved and the reassessment of risks.
A.5.23. Information security for use of cloud services¶
The Cloud Security Team shall ensure that tecciance scrutinize cloud service agreements and ensure that four main operational requirements are met:
-
Confidentiality.
-
Security/data integrity.
-
Service availability.
-
Information handling.
As with other supplier contracts, prior to acceptance, cloud service agreements should undergo a thorough risk assessment that highlights potential problems at source.
A.5.24. Information security incident management planning and preparation¶
- Responsibilities and procedures
Incident management responsibilities and procedures exist to ensure a quick, effective, and orderly response to security incidents. Security events are defined as incidents that could cause unauthorized disclosure, modification, or destruction of, tecciance’ s information assets, or loss or destruction of the physical equipment associated with the computer systems. All users in the, tecciance are responsible to report any observed or suspected security incidents at contact@tecciance.lk or contact@tecciance.lk.
-
Management responsibilities should be established to ensure a quick, effective, and orderly response to Security Incidents and identified weakness.
-
The objectives for Security Incident management should be agreed upon with management, and it should be ensured that those responsible for Security Incident management understand the organization’s priorities for handling Security Incidents.
-
Security Events should be reported to contact@tecciance.lk
-
Personnel using the organization’s information systems and services are required to note and report.
-
any observed or suspected Security Weakness in systems or services.
-
Security Events should be assessed, and they should be classified with respect to the Severity Rating specified.
-
Knowledge gained from analyzing and resolving Security Incidents should be used to reduce the likelihood or impact of future incidents.
-
Process should be defined and applied for the identification, collection, acquisition, and preservation of information, which can serve as evidence.
-
The ISMS team shall provide incident reporting awareness sessions on an annual basis to all employees in the organization. It shall also be a part of the employee induction security awareness training.
-
The incidents shall be resolved by working across different departments and stakeholders within the defined SLA as established in the incident reporting manual.
-
The ISMS team shall establish a risk exception process in the risk management manual with approval from leadership.
A.5.25. Assessment and decision on information security events¶
Information security events reported by the stakeholders are analyzed and determined if these should be classified as an event or an incident. Based on the assessment of the event using the established information
security event and incident scale, it is decided if the reported event should be classified as an information security event or incident. There must be a process followed by the incident response team to differentiate an incident from an event. An event shall be categorized as an incident only if it relevant to the organization’s environment, people, and processes.
A.5.26. Response to information security incidents¶
tecciance has a well-defined and documented incident management procedure that addresses incident reporting, incident analysis and classification and incident resolution. Incident Analysis shall be performed to determine the actions to be taken by tecciance and sufficient controls to be implemented to prevent a similar event from recurring.
A.5.27. Learning from information security incidents¶
Incidents shall be analyzed, and appropriate actions taken to prevent recurrence of these incidents. Actions shall also be taken to prevent the occurrence of such information security incidents in the future.
A.5.28. Collection of evidence¶
Incident response members shall collect evidence from the site of incident. Evidence collected shall be admissible, complete and of good quality (evidential integrity), before responding to the incident. The copies of the evidence shall be used for root cause analysis and as forensic evidence against a person or an organization. The original evidence shall be kept securely.
A.5.29. Information security during disruption¶
- Planning information security continuity
Business Continuity Management process is a process that identifies potential threats to an organization and the impacts to business operations that those threats—if realized—might cause, and which provides a framework for building organizational resilience with the capability for effective response that safeguards the interests of its key stakeholders, reputation, brand, and value-creating activities.
The ISMS Team shall ensure that business continuity or recovery plan covers information security requirements.
- Implementing information security continuity
Information security requirements shall be addressed while developing recovery plans for projects as well as functions to maintain or restore business operations and ensure availability of information at the required level and in the required time scales following an interruption or failure of critical business processes.
ISMS Team shall be responsible for maintenance and testing of the plan, development of execution criteria, and requirements and determination of activation status.
Key contacts:
|
|
|
|
|
|---|---|---|---|---|
- Verify, review, and evaluate information security continuity.
The BCP exercise shall be performed by the ISMS Team on a yearly basis. BCP plans shall be modified by the ISMS Team to address any changes to the following:
-
Changes in infrastructure
-
Changes in business strategy
-
Changes in business environment or risk environment
The results of the tests and action taken to improve the plans shall be recorded.
A.5.30. ICT readiness for business continuity¶
tecciance shall undergo a risk assessment that evaluates their ICT systems and forms the basis of an ICT continuity strategy (or strategies) that bolsters recovery prior to, during and following a period of disruption.
Once a strategy has been agreed, specific processes and plans should be put in place to ensure that ICT services are resilient and adequate to contribute towards recovery of critical processes and systems, before, during and after disruption.
A.5.31. Legal, statutory, regulatory, and contractual requirements¶
-
Identification of applicable legislation and contractual requirements
-
Relevant statutory and regulatory requirements pertaining to tecciance are identified and followed.
-
Function Heads shall review all contracts before being signed.
-
Respective Project Leads shall identify relevant contractual commitments (including laws of the land, as applicable).
-
Regulation of cryptographic controls
IT shall review the requests for purchase and use of cryptographic controls. IT shall consider all applicable laws and regulations of the land before purchasing cryptographic hardware/software.
Personnel who are in the possession of or use cryptographic controls shall adhere to the applicable laws and regulations.
A.5.32. Intellectual property rights (IPR)¶
-
Awareness on Intellectual Property Rights and Copyrights are spread through induction and refresher training sessions and various awareness campaigns.
-
All personnel understand and sign the tecciance Non-Disclosure Agreement (NDA).
-
Periodic reviews of software usage on tecciance laptop shall be performed to ensure all computer resources follow licensing agreements.
-
Personnel found to be violating these controls shall be subjected to appropriate disciplinary action. Illegal copying of licensed software or use of unauthorized versions of software products on tecciance information assets is strictly prohibited.
A.5.33. Protection of records¶
-
All the records (both soft and hard copies) shall be handled as per their level of classification.
-
Suitable physical and logical controls shall be deployed to protect the records to ensure its confidentiality, integrity, and availability.
-
Records shall be legible, readily identifiable, and retrievable, when required. The Information Owner along with the Information Custodian is responsible for ensuring retrieval of their records.
A.5.34. Privacy and protection of personally identifiable information¶
tecciance ensures that Client’s personal information and tecciance’ s personal information are handled properly including the following points:
-
Collection of personal information for business purposes
-
Usage and handling of personal information for business purposes
-
Spreading awareness among employees on data privacy
tecciance also ensure that consent is obtained from employees when collecting their personal information for business purposes. In addition to the controls mentioned in the policy, the following shall also be adhered to it:
-
Personal information shall be classified as per the tecciance Data Classification or as per the information classification requirements of the Client.
-
Client provided personal information shall not be sent through mails, without prior written approval from the Client.
-
Any data privacy breaches that involve Client data should be reported immediately to the Project Leads who shall in turn report the breach to contact@tecciance.lk or contact@tecciance.lk.
Disciplinary action will be taken on anyone who is found intentionally communicating or making available personal to any unauthorized personnel. The disciplinary action will depend on the severity of the breach and can lead to termination and/or taking legal action against the employee.
A.5.35. Independent review of Information Security¶
Review of the implementation of ISMS shall be done by Top Management periodically as per the half yearly audit schedule. Auditors from external certifying agencies shall perform surveillance audits once a year and recertification audit every three years.
A.5.36. Compliance with policies, rules, and standards for information security¶
- Compliance with security policies and standards
All functions of tecciance shall ensure compliance to information security and IT policies and procedures on a regular basis. ISMS Team shall review and audit compliance to information security policies and procedures.
- Technical compliance review
The IT Team shall monitor and review operational systems at periodic intervals for their technical compliance. This includes monitoring and reviewing compliance of all technologies, both hardware and software, to security implementation standards. Only authorized personnel shall be allowed to carry out vulnerability assessments to identify potential vulnerabilities. Prior approval from CISO shall be obtained before carrying out such tests. Another cycle of tests after the mitigation phase shall be conducted to ensure that the vulnerabilities are mitigated, and no new vulnerabilities are introduced in the system. The utmost care shall be taken when tools are used for checking technical compliance to avoid disruption of business processes.
A.5.37. Documented operating procedures.¶
Each function of tecciance shall document and maintain Standard Operating procedures for the activities associated with the respective functions.
-
IT document shall address:
-
Backup
-
Password Management
-
Vulnerability Assessment
-
Asset Management
-
HR document shall address:
-
Onboarding & Offboarding process
-
Recruitment process
People Controls¶
A.6.1. Screening¶
Human Resources team shall perform background verification (BGV) based on tecciance requirement for all employees through authorized /approved BGV Vendors. tecciance has a documented recruitment process which includes background verification of employees, screening, and on-boarding formalities. They shall also receive exceptional approval from leadership in case of BGV exception. Refer tecciance Background Verification Policy – tecciance-POL-HR-BGVP.
A.6.2. Terms and conditions of employment¶
HR shall ensure that all employees understand and agree to abide by the Non-Disclosure Agreement for tecciance by signing it. All employees shall undergo Security Awareness training as part of their induction and undergo the mandatory Security Awareness Self-Assessment Test. Employees shall be made aware of the information security policies and procedures of tecciance in this training.
HR shall include security responsibilities as part of the terms and conditions of employment and the violation of the security responsibilities will lead to disciplinary actions. Employees shall also be made aware of the disciplinary action process that would be initiated during security incidents / breaches.
HR, in conjunction with Legal, shall identify, implement, review, and update various legislative, regulatory, and contractual requirements related to employment, as applicable.
A.6.3. Information security awareness, education, and training.¶
The emphasis on Information security is provided through Security Awareness training conducted as part of the induction process. Employees are made aware of the organization’s Information security framework before being provided access to information, information assets and information processing facilities. Security Awareness training covers the importance of information security, the appropriate use of information and information processing facilities and information security incident reporting process to minimize possible security risks.
The training content is periodically reviewed and updated to ensure consistency with information security policies and procedures commensurate with their roles and responsibilities. Information Security awareness campaigns shall be conducted periodically. The training sessions and awareness campaigns shall cover all tecciance employees who have access to tecciance information and information assets. All the organization’s employees need to complete the mandatory Security Awareness Self-Assessment test. The attendance will be tracked for performance.
A.6.4. Disciplinary process¶
Personnel found to have violated the information security policies and procedures or found to have caused an information security incident, shall be subjected to appropriate disciplinary action after thorough investigation into the incident. HR along with the respective Reporting Manager will discuss and decide on the applicable disciplinary action.
Disciplinary action may include, but is not limited to, loss of access privilege to information and information processing resources, suspension, cancellation of contracts in case of contractors, termination of employment, withholding of any salary payable or other actions deemed appropriate by the organization and in line with the laws of the land. Disciplinary process will be enforced by the HR upon employees who are not conforming with the ISMS requirements. Refer tecciance Disciplinary Action Policy.
A.6.5. Responsibilities after termination or change of employment.¶
- Termination or change of employment responsibilities.
Responsibilities for performing employment termination or change of employment are clearly defined and assigned. Detailed exit form is filled to ensure return of assets, revocation of access rights, full & final settlement, and Job handover by exiting employee and approved by relevant reporting manager and HR. Refer tecciance Separation Policy – tecciance-POL-HR-SP
A.6.6. Confidentiality or non-disclosure agreements¶
Non-Disclosure Agreements (NDAs) shall address the requirement to protect sensitive information using legally enforceable terms. tecciance NDAs are perpetual in nature and shall continue to hold good even beyond the tenure of an employee with the organization.
-
All personnel shall sign Non-Disclosure Agreements prior to accessing tecciance’ information, information assets or information processing facilities. Personnel shall sign these documents as part of the terms and conditions of employment, upon joining.
-
HR along with the Leadership team shall review requirements for the non-disclosure agreements periodically and as and when changes occur that influence these requirements.
A.6.7. Remote working¶
-
Teleworking
-
Work from Home Guidelines
-
Secure your home office.
-
Secure your home router/Wi-Fi Devices.
-
Separate work and personal devices.
-
Encrypt your devices.
-
Use a supported operating system.
-
Keep your operating system up to date.
-
Keep your software up to date.
-
Enable automatic system locking.
-
Use a strong PIN/password on your device.
-
Use an antivirus.
-
Enable two-factor authentication.
-
Avoid public Wi-Fi; if necessary, use personal hotspots or some way to encrypt your web connection.
-
Keep Work Data on Work on Computers.
-
Encrypt Sensitive Data in Emails and on Your Device.
-
Physical Security while working from home.
-
Never Leave Your Devices or Laptop unattended.
-
Do not Use Random Thumb Drives.
A.6.8. Information security event reporting¶
- Reporting information security events
All personnel are made aware of their responsibility to report security events or incidents as quickly as possible. As soon as personnel encounter an information security event or incident, he/she shall report it. Personnel shall note all the relevant details (like breach, occurring malfunction, messages on screen, strange/ suspicious behavior) and send the incident details to contact@tecciance.lk or contact@tecciance.lk.
- Reporting security weaknesses
Employees shall report any weakness / vulnerability identified to contact@tecciance.lk or contact@tecciance.lk employees shall not attempt to test or prove suspected information security weaknesses. Testing or proving weakness will be interpreted as a potential misuse of the system and anyone involved in this activity will be subjected to appropriate disciplinary action.
Physical Controls¶
A.7.1. Physical security perimeter¶
Security perimeters shall be defined and established to protect tecciance information and information processing facilities. Physical security of tecciance office is maintained as below:
-
Segregated perimeter with entry / exit points that are manned by security guards 24x7.
-
Security guards ensure that only authorized persons are provided entry to the premises.
-
Visitors are allowed entry into the tecciance office upon confirmation from the authorized person whom the visitor has requested to visit. The visitor register is maintained at the front desk.
A.7.3. Securing offices, rooms, and facilities¶
Security Offices, rooms, and facilities for tecciance office is maintained as below:
-
The physical perimeter of the facility and secure areas shall be monitored 24x7.
-
The Building Management Team shall ensure that offices are protected with physical security.
-
The information processing facilities shall comply with any applicable local health and safety regulations and laws of the land.
A.7.4. Physical security monitoring¶
The Physical Security requirements fall into two broad categories: secure areas and equipment security. Secure areas provisions – secure areas being sites where organizations handle sensitive information or shelter valuable IT equipment and personnel to achieve important business objectives – deal with protecting the physical environment in which assets are housed, in other words: building, offices, etc.
Secure Areas
| Type | Control |
|---|---|
| Physical Security Perimeter | Security perimeters (barriers such as walls, card-controlled entry gates or manned reception desks) shall be used to protect areas that contain information and information processing facilities. |
| Physical Entry Controls | Secure areas shall be protected by appropriate entry controls to ensure that only authorized personnel are allowed access. |
| Securing Offices, Rooms, and Facilities | Physical security for offices, rooms, and facilities shall be designed and applied. |
| Protecting Against External and Environmental Threats | Physical protection against damage from fire, flood, earthquake, explosion, civil unrest, and other forms of natural or man-made disaster shall be designed and applied. |
| Working in Secure Areas | Physical protection and guidelines for working in secure areas shall be designed and applied. |
| Public Access, Delivery, and Loading Areas | Access points such as delivery and loading areas and other points where unauthorized persons may enter the premises shall be controlled and, if possible, isolated from information processing facilities to avoid unauthorized access. |
Equipment Security
| Type | Control |
|---|---|
| Equipment Siting and Protection | Equipment shall be sited or protected to reduce the risks from environmental threats and hazards, and opportunities for unauthorized access. |
| Supporting Utilities | Equipment shall be protected from power failures and other disruptions caused by failures in supporting utilities. |
| Cabling Security | Power and telecommunications cabling carrying data or supporting information services shall be protected from interception or damage. |
| Equipment Maintenance | Equipment shall be correctly maintained to ensure its continued availability and integrity. |
| Removal of Assets | Equipment, information, or software shall not be taken off-site without prior authorization. |
| Security or Equipment Off-Premises | Security shall be applied to off-site equipment considering the different risks of working outside the organization’s premises. |
| Secure Disposal or Re-Use of Equipment | All items of equipment containing storage media shall be checked to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or wiped off completely, prior to re-use. |
| Unattended User Equipment | Users shall ensure that unattended equipment has appropriate protection. |
| Clear Desk and Clear Screen Policy | A clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities shall be adopted. |
A.7.5. Protecting against external and environmental threats¶
Controls to ensure physical protection of the information processing facility against damage from flood, fire, earthquake, explosion, civil unrest, and other forms of natural or manmade disasters shall be implemented by Building management Team.
It also ensures that:
-
Any hazardous or combustible materials shall be stored at a safe distance from any secure area according to local safety regulations and manufacturer specifications.
-
Adequate fire detection and firefighting equipment are provided and suitably placed across the facility, in compliance with local safety regulations.
A.7.6. Working in secure areas¶
Access to office areas shall be provided upon appropriate authorization from office room owners, based on business requirements. Housekeeping personnel working in secure areas shall be supervised by authorized personnel.
A.7.7. Clear desk and clear screen policy¶
-
All personnel are required to lock their screen (Pressing Windows + L or Control+ALT+DEL) when they are no longer working on their PC.
-
Laptops must be shut completely down at the end of the workday.
-
Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
A.7.9. Security of equipment and assets off-premises¶
Authorized equipment taken off premises or used outside tecciance premises, shall be controlled, secured, and protected. A tracking mechanism shall be in place for all organizational equipment sent off premises. Security risks like damage, theft or eavesdropping shall be considered in determining the most appropriate security controls for off-premises equipment and their usage. Manufacturer’s instructions should be considered when developing and implementing controls.
A.7.10. Storage media¶
- Management of removable media
Employees are made aware of not using removable media in their corporate laptop. When it comes to insider threat, Employees should be able to recognize and report social engineering attacks promptly which would mitigate or minimize the impact of an attack. Employees must be regularly trained and assessed for the effectiveness of the training. If any employee falls victim to a social engineering attack, the tecciance’ security team shall act quickly to contain it. tecciance’s corporate culture must therefore encourage victims to report incidents as soon as possible.
- Disposal of media
In tecciance, all damaged and discarded assets are low level formatted and stored under lock and key.
- Physical Media Transfer
Transfer of any tecciance Assets from one location to another shall be done with the appropriate approval from IT Team. The IT Team shall compile and maintain a list of authorized delivery service companies.
- Removal of assets
Equipment shall not be taken offsite without prior authorization from the IT Team. Movement of any assets shall be done only after approval from the IT Team.
A.7.14. Secure disposal or re-use of equipment¶
All equipment including storage media shall be checked to ensure that any sensitive information or licensed software has been removed or securely overwritten prior to reuse or disposal or wiped off completely, prior to re-use. IT team shall ensure that no sensitive information and licensing software are left on the equipment before releasing the equipment or providing approval for physical destruction.
Technological Controls¶
A.8.1. User end point devices¶
- Mobile device policy
Mobile devices are among the most vulnerable tech items we own because they are easily exploited and can be quickly compromised by hackers. tecciance do not restrict employees accessing corporate emails on their mobile devices. However, we recommend our employees follow the list of best practices for securing their mobile devices below:
-
Use a secure PIN.
-
Never store tecciance or their client’s confidential information on your personal phone.
-
Keep the software up to date.
-
Do not connect to public Wi-Fi networks.
-
Backup & encrypt your device.
-
Block Potentially Dangerous Apps
-
Unattended user equipment
Users shall ensure that unattended equipment is appropriately protected.
Personnel shall lock the system (using Win key + L) or log off when stepping out of the work area to prevent misuse. Users shall adequately protect laptops while travelling by taking appropriate measures.
All laptops are protected by password protected screensavers that get activated after a defined period of inactivity.
A.8.2. Privileged access rights¶
- Management of privileged access rights
The allocation and use of privileges shall be restricted and controlled. The access privileges associated with account and the users require the privileges need to be identified. Privileges access rights shall be allocated to personnel on a “need to have” basis and based on business requirements. Personnel shall be provided with minimum privilege as per their functional role. Privileged access rights will be allocated only after receiving appropriate approvals from Reporting Managers or Project Leads.
A.8.3. Information access restriction¶
Access to information, information assets and information processing facilities shall be provided based on the defined Access Control policy. Access shall be controlled based on business requirements and the classification level of the information. All employees shall only be provided with the minimum level of access required to perform their duties.
A.8.4 -Access control to source code¶
Access control to source code shall be provided based on the defined Access Control policy. Process of managing and restricting access to the underlying source code of a software application or system. It involves implementing security measures to ensure that only authorized individuals or entities can view, modify, or distribute the source code.
A.8.5. Secure log-on procedures¶
The procedure for logging into an operating system shall be designed to minimize the opportunity for unauthorized access. IT shall ensure passwords are not displayed in clear text on screen while entering and not transmitted in clear text over network.
A.8.6. Capacity management¶
Capacity demands on information processing systems shall be monitored to meet anticipated capacity requirements, minimize the risk of failures, and ensure continual availability of the critical resources. IT shall plan to determine anticipated capacity requirements and prepare to ensure the availability of adequate capacity and resources. Capacity plan should include current loads, future demands, continuity needs, cost and timelines for upgrades if required.
A.8.7. Control against malware¶
IT shall implement detective and preventive controls to protect the information processing system against malicious software. Immediate action and follow up shall be taken to minimize the impact and restore services during and after a malicious code attack.
Personnel should inform IT and report to contact@tecciance.lk or contact@tecciance.lk immediately if their laptop is suspected to be infected with virus or other malicious code. Periodic reviews shall be carried out by IT to ensure that malicious codes are not present in the systems.
IT shall implement the following controls:
-
All tecciance laptops should have Antivirus solution installed in them.
-
The Antivirus should be active in all the laptops.
A.8.8. Management of technical vulnerabilities¶
IT shall maintain the inventory of IT assets including the software vendor, version numbers, current state of deployment (e.g., what software is installed on what systems), and the personnel using the software. IT shall be responsible for technical vulnerability management including vulnerability monitoring, vulnerability risk assessment, patching, asset tracking, and any coordination responsibilities. The IT officer shall find appropriate mechanisms of handling patch updates relevant for the size of the organization, subject to leadership approval.
- Technical compliance review
The IT Team shall monitor and review operational systems at periodic intervals for their technical compliance. This includes monitoring and reviewing compliance of all technologies, both hardware and software, to security implementation standards. Only authorized personnel shall be allowed to carry out vulnerability assessments to identify potential vulnerabilities. Prior approval from CISO shall be obtained before carrying out such tests. Another cycle of tests after the mitigation phase shall be conducted to ensure that the vulnerabilities are mitigated, and no new vulnerabilities are introduced in the system. The utmost care shall be taken when tools are used for checking technical compliance to avoid disruption of business processes.
A.8.9. Configuration management¶
The IT team shall ensure that the Configuration management is an integral part of tecciance broader asset management operation. Configurations are key in ensuring that a network is not only operating as it should be, but also in securing devices against unauthorized changes or incorrect amendments on the part of maintenance staff and/or vendors.
A.8.10. Information Deletion¶
A fundamental principle of information security is that information that is not necessary for the business should not be kept. This process is known as data deletion, and it is meant to protect against unnecessary and disproportionate harm in the event of a security breach.
Information deletion¶
A.8.11. Data masking¶
Data masking is a complex technical process that involves altering sensitive information and preventing users from identifying data subjects through a variety of measures.
The nature of data masking is directly related to tecciance’s ability to remain compliant with laws, regulations, and statutory guidelines concerning the storage, access, and processing of data. As such, ownership should reside with the Chief Information Security Officer.
A.8.12. Data leakage prevention¶
Data Leakage prevention has been added to ensure tecciance has measures to detect and prevent the unauthorized disclosure and extraction of information by both individuals and systems. Data leakage can broadly be described as any information that is accessed, transferred, or extracted by unauthorized internal and external personnel and systems, or malicious sources that target a tecciance information operation.
A.8.13. Logging¶
- Event logging
IT shall ensure that all events and activities are logged. The events include, but are not limited to:
- User IDs, Date and time, Login failures.
IT shall ensure that monitoring tools are installed to log activity and security violations against critical resources / information.
Access to security logs shall be restricted to authorized personnel only. Logs shall be retained on read-only media as far as possible.
- Protection of log information
Access to security logs shall be restricted to authorized personnel only. Logs shall be retained on read-only media as far as possible.
A.8.14. Monitoring activities¶
The IT Team ensures that Monitoring Activities is a dual-purpose detective and corrective control that modifies risk by optimizing monitoring activities to identify anomalous behaviour and assists in the prompt analysis of information security events and incidents.
A.8.15. Clock Synchronization¶
The clocks of all systems shall be synchronized regularly as per the Standard time.
A.8.16. Use of privileged utility programs¶
Every user needs to have a unique user account to access their systems. Password policy is defined as below:
-
Minimum password length should be 8 characters.
-
Password should contain at least 1 upper case, 1 lower case, 1 numeric, 1 special character and 1 character.
-
User must change his/her login password after first login.
-
Users must keep their laptop password protected with the help of a 6-digit PIN.
-
Awareness is given to employees to change their passwords regularly.
A.8.17. Installation of software on operational systems¶
- Installation of software on operational systems
IT maintains the list of software installed on each employee's laptop. Any non-business-related software installation is strictly prohibited. Employees need to raise a change request to the IT Team for installing any software on their corporate laptop. IT on a monthly basis performs the reconciliation between the system and Asset register.
- Restrictions on software installation
IT maintains the list of software installed on each employee's laptop. Any non-business-related software installation is strictly prohibited. Employees need to raise a change request to the IT Team for installing any software on their corporate laptop. IT monthly performs the reconciliation between the system and Asset register.
A.8.18. Network controls¶
Employees should use only protected networks for office purposes.
A.8.19. Security of network services¶
People when they are accessing WIFI at home, WEP, WPA basic security controls can be enabled. Accessing Public and Open Wi-Fi networks present in Restaurants, Hotels, Airports, Railway Stations must be avoided on corporate devices.
A.8.20. Segregation of Networks¶
Ensure the protection of information in networks and their supporting information processing facilities. Communications encompass the breadth of digital data flows both within a tecciance and between external entities across network infrastructures.
A.8.21. Use of cryptography¶
- Policy on the use of cryptographic controls
Sensitive information when stored, shared, transmitted, or used in any manner that increases the risk of data exposure, leakage and loss shall be protected using controls like encryption. The use of encryption technologies shall be in accordance with applicable licensing, regulatory norms (where applicable) and contractual requirements. These procedures shall address the selection and use of industry recognized encryption algorithms, key lengths, key management protocols, hashing algorithms, digital signature standards etc. Bit Locker is used to encrypt all the laptop HDDs in the organization.
- Key Management
Key management processes shall be in place to support organizational use of cryptographic controls. Wherever encryption is employed, the IT Team shall ensure that the encryption keys are selected, changed, stored, exchanged, backed up and retired in a secure and timely manner. Access to keys shall be restricted to only a few authorized personnel. Keys are maintained with authorized user only.
A.8.25 – Secure Development Life Cycle¶
tecciance designs information security standards and applies these standards across the entire secure development life cycle for software products and systems.
A.8.26. Application Security Requirements¶
tecciance shall defend their data assets stored on or processed by applications through the recognition and application of appropriate information security specifications. Application security is the practice of using security software, hardware, techniques, best practices, and procedures to protect computer applications from external security threats.
A.8.27. Secure System Architecture and Engineering Principles¶
tecciance implements secure system architecture and engineering principles to ensure that the design, implementation, and management of the information system are appropriate to the tecciance security requirements. This includes the establishment of secure system architectures, engineering principles, and secure design practices.
A.8.28 - Secure Coding¶
tecciance works to prevent security risks and vulnerabilities that may arise because of poor software coding practices by designing, implementing, and reviewing appropriate secure software coding principles.
A.8.29. Security Testing in Development and Acceptance¶
Security testing in development and acceptance is a process that helps identify and mitigate security vulnerabilities in software applications before they are deployed. This type of testing is typically done during the development and acceptance phases of the software development life cycle (SDLC).
A.8.30. Outsourced Development¶
tecciance ensures that the established information security requirements are adhered to when the system and software development is outsourced to external suppliers.
A.8.31. Separation of development, test, and production environments¶
Separation of development, test, and production environments is important to achieve segregation of the functions involved. It is appropriate that the rules for development to transfer to production environments are well defined and documented. Failure to properly segregate development, test, and production environments may result in a loss of availability, confidentiality, and integrity of information assets.
.8.28 Secure coding¶
A.8.32. Change management¶
tecciance follows a well define methodology by which changes to the information processing facilities are controlled.
The roles and responsibilities for personnel involved in the change control process shall be clearly defined and properly segregated. Change management process shall ensure segregation of duties so that change is not proposed and approved by the same individual.
Any user can initiate a change request. IT is authorized to approve the operational and process changes request after discussing with Functional Head.
A.8.33. Test Information¶
Development and testing environments should not contain sensitive information, including personal data. Organisations should follow these steps to protect test information against loss of confidentiality and integrity:
-
Test environments should also implement access controls that are used in real-world environments.
-
The copying of real information into test environments requires a separate authorization procedure.
-
In order to maintain an audit trail, all activities relating to the copying, using, and storing of sensitive information in test environments should be recorded.
-
Test environments should protect sensitive information with appropriate controls, such as data masking or data removal if sensitive information is to be used.
A.8.34. Information systems audit controls¶
Audit requirements and activities involving checks on operational systems shall be planned and agreed upon by relevant Function Heads to minimize the risk of disruptions to business processes. Audit scope and plan shall be agreed upon by relevant stakeholders before execution. All audit activities shall be logged to provide a record of tasks performed, audit procedures, findings, and recommendations.
Document Review¶
This manual will be updated annually or as and when significant change happens to the relevant areas covered by ISMS Team.