Skip to content

Information Technology Manual

Information Technology Manual

IT Exception Policy …………………………………………………………………………………………………………………………………. 7

Version history

Version Number Date Description Created By Approved By
0.1 23/Apr/2024 Initial Copy [Name]
0.2 18/Jun/2024 Approved [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Purpose

The purpose of this IT manual, to achieve their objectives, shall entail certain salient features and shall comply with industry-established standards.

The IT manual shall

  • Comply with regulatory, Government of Sri Lanka and statutory guidelines.

  • Be based on well-established industry practices.

  • tecciance’s IT infrastructure and operations shall be in line with IT policy.

  • Be technology and properly agonistic.

Scope

IT manual covers all applications / business processes that rely on IT for its processing and delivery. It applies to all employees and others who directly or indirectly use or support tecciance’s computing services or information.

IT manual applies to

  • All Departments and functions

  • All branches and geographical locations

  • All information system technology used; and

  • Third parties with whom tecciance have a long-term relationship for regular operations as well as independent service providers engaged to provide infrequent or on-off services.

Objective

IT manual aims at achieving a streamlined process flow implementation for all IT related functions supporting existing tecciance’s core business. It strives to ensure that all IT aspects upon which the business depends to pursue its activities are optimally utilized.

IT manual forms the foundation of the IT program of tecciance. All initiatives on the IT front shall draw support from this policy and shall extend its support. The IT procedures shall be integrated with the existing and/or future procedures managing IT infrastructure. tecciance shall issue guidelines, wherever necessary, add to the technology specifics to the procedure.

The key objectives of the IT manual are to provide guidelines to:

  • IT Governance

  • Aligning IT to business strategy

  • Improve quality of IT delivered.

  • Reduce the long-term cost of service provision.

IT Policy

The IT policy covers below mentioned process/policy related to IT projects, Infrastructure, applications, and Operations.

  • IT Governance

  • IT Infrastructure

  • IT Operations

  • Access Control

  • Asset Management

  • Capacity Management

  • Configuration Management

  • Network Security

  • Incident & Problem Management

  • Change Management

  • Anti-Virus

  • Logging & Monitoring

IT Governance

  • IT Governance of tecciance shall be in - line with the corporate governance norms of tecciance.

  • tecciance shall ensure that an effective strategic planning process is in place.

  • tecciance shall Align IT services to meet the needs of the business and customers.

  • tecciance shall ensure adherence to IT Security as per tecciance Information Security Policy.

  • tecciance shall ensure adherence to Business Continuity as per the tecciance’s BCP Policy.

  • tecciance shall follow outsourcing guidelines while outsourcing some of the functions/ operations as per tecciance Outsourcing Policy.

  • tecciance shall review the process of IT Roadmap and the utilization of IT budgets at Board Level on yearly basis.

IT Infrastructure

Policy statement

  • A robust, secured, reliable and available network is the primary requirement for the Information Technology plan. All offices and branches of tecciance will have permanent network connectivity with the WAN.

  • tecciance shall ensure quality network and computing infrastructure implementation through periodical review of existing systems and technology.

  • All forms of connectivity media, which includes terrestrial, wireless and satellite shall be used for network connectivity with appropriate security controls, following tecciance’s Information Security Policy.

  • Direct connectivity of external networks including Internet on tecciance’s nodes bypassing security controls shall not be implemented.

  • Temporary connectivity for accessing tecciance resources from internal and external network should have security controls like Firewall, VPN, etc. in place.

  • Types of applications viz. Centralized, Client Server Based, Local or Web based will not be a limiting factor and will solely be governed by the business objectives of tecciance.

  • The Procurement Policy shall be adhered to for all IT procurements.

IT Operations

  • tecciance shall ensure a service environment that keeps pace with the business needs, free of unplanned disruptions, and responds quickly to unforeseeable incidents that may affect the operational integrity of the service platforms.

  • tecciance shall manage IT infrastructure components for an environment which falls under IT operations.

  • IT infrastructure shall be configured, maintained, and managed by tecciance as per the IS policy.

  • tecciance shall ensure that the technical knowledge and expertise required to design, develop, test, manage and improve IT services are identified, developed, and refined.

  • tecciance shall ensure appropriate resources are effectively trained and deployed to deliver, build transit, operate, and improve the technology required to deliver and support IT Infrastructure.

  • tecciance shall ensure the availability of skill sets needed for infrastructure management.

Please refer to tecciance – policy and procedure documents for more information on the IT operational processes below:

  • Access Control

  • Asset Management

  • Capacity Management

  • Configuration Management

  • Network Security

  • Incident & Problem Management

  • Change Management

  • Anti-Virus

  • Logging & Monitoring

IT exception Policy

  • This policy outlines the process for handling deviations from organizational rules and standards. All exception requests must be submitted in writing, detailing the policy in question, the reason for the exception, and any supporting documentation.

  • Each request will be reviewed and approved or denied by the relevant authority, with specific conditions or controls applied as necessary. Exceptions are granted for a defined period and are subject to regular review and monitoring to ensure compliance and mitigate risks.

  • The organization reserves the right to revoke exceptions if they pose undue risk or fail to meet established conditions.

  • USB devices may be used only with prior mail approval from the head of IT department. Approved devices comply with security protocols. Usage is subject to logging, monitoring, and periodic audits.

  • Any unusual activity must be reported immediately. Temporary (24 hours) and permanent (1year) approval can be given based on the requirement and designation of the employee. Once the approval timeline is met the USB access must be revoked in a timely fashion.