Information Security Policy Statement¶
Information Security Policy Statement
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Jan/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Scope and Applicability¶
We are committed towards securing the Confidentiality, Integrity, and Availability of tecciance and tecciance’s client data and intellectual property. The security of information assets is therefore regarded as fundamental for successful business operation. tecciance is committed to implementing and maintaining compliance with ISO 27001, and to continual practical improvement of our information security practices. To this effect, the policy is supported by domain level security policies and procedures, which are communicated and made available to relevant stakeholders. This will help maintain our reputation in the industry and meet our legal/regulatory and customers’ requirements.
The objective of tecciance Information Security Management System (ISMS) is to ensure a risk-based approach taken when considering the implementation of the security, privacy, and business continuity controls necessary to support business objectives. This information security policy applies to all tecciance employees, including contractors, vendors, auditors, and visitors who access our data, systems, and facilities.
tecciance commits to¶
-
Working closely with our customers and vendors to deliver services in a security conscious fashion.
-
Ensure Confidentiality, Integrity, and Availability by adequately protecting the critical information assets and systems against unauthorized access, modification or alteration Business continuity plans are developed, maintained, and tested.
-
Establish and implement security policies and processes while considering the protection of critical information assets and systems from internal and external threats.
-
Comply with legal, regulatory, and contractual security obligations as may be applicable.
-
Ensure security awareness and competency amongst all the associates to enable them to meet their security obligations.
-
Provide a framework to manage and handle security breaches, violations, and business disruptions.
-
Ensure continuity of critical operations in line with business and contractual requirements.
-
Ensure continuous improvement of the security posture to consistently meet its security objectives.
It is the responsibility of everyone to adhere to the policy. Information Security Head shall ensure that this policy is communicated, understood, implemented, and maintained at all levels of the organization and regularly reviewed for continual improvement of Information Security Management System.
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.