Skip to main content

PRVIEW Awards & Events Platform – Never Miss a Deadline

IT SECURITY POLICY

    1. PURPOSE

      The purpose of this IT Security Policy is to provide comprehensive guidance on safeguarding PRVIEW, Inc.’s (the “Company”) information technology resources and data against unauthorized access, disclosure, alteration, or destruction. By adhering to this Policy, the Company aims to minimize security risks, protect sensitive information, maintain operational continuity, and comply with regulatory requirements in the field of IT security.

    2. SCOPE

      This Policy applies to all employees, contractors, vendors, and authorized users who access, utilize, or oversee IT systems, data, and assets within the Company. It encompasses all aspects of IT security within the organization, including but not limited to:

      1. Employee workstations and laptops 
      2. Servers and data centers 
      3. Network infrastructure 
      4. Mobile devices 
      5. Cloud-based systems 
      6. Application software 
      7. Data storage devices and media 
      8. Electronic communication systems (email, messaging) 
      9. Security controls and mechanisms

    3. POLICY STATEMENTS

      1. Information Classification and Handling

        1. Information Classification: To ensure appropriate protection, the Company shall classify all information assets based on their sensitivity and criticality. Classification levels are as follows:

          1. Public
          2. Internal Use
          3. Confidential

        2. Handling Procedures: Employees and authorized users must strictly adhere to information handling procedures, including encryption, access controls, and secure disposal, as specified in this IT Security Policy.

      2. Access Control

        1. Authentication Mechanisms: Access to IT systems and data will be controlled through strong authentication mechanisms, including but not limited to passwords, biometrics, and multi-factor authentication (MFA).

        2. Least Privilege: Access privileges will be assigned based on the principle of least privilege (PoLP). Users will only have access to the resources necessary to perform their job responsibilities.

        3. Access Reviews: the Company will conduct regular access reviews and audits to ensure adherence to access control policies and to promptly revoke access for employees and users who no longer require it.

      3. Data Protection

        1. Data Encryption: Sensitive data, both in transit and at rest, must be protected through encryption. Encryption will be applied during data transmission over networks and when storing data on electronic media.

        2. Backup and Recovery: Robust backup and disaster recovery procedures will be established and regularly tested to ensure data availability in case of system failures, data corruption, or data breaches.

      4. Malware Protection

        1. Anti-Malware Software: All devices connected to the corporate network will be equipped with up-to-date anti-malware software that actively scans for and defends against malicious software, including viruses, spyware, and ransomware.

        2. Security Awareness: Employees and users will be educated and trained to recognize and report suspicious activities, phishing attempts, and malware incidents.

      5. Incident Response and Reporting

        1. Incident Response Plan: The Company will maintain a documented incident response plan designed to detect, assess, and respond to security incidents promptly. This plan will outline roles and responsibilities for handling incidents.

        2. Reporting: All employees and users must promptly report any security incidents, breaches, or suspected breaches to the IT Department and the designated security officer, following the incident reporting procedures outlined in the incident response plan.

      6. Acceptable Use of IT Resources

        1. Acceptable Use Policy: The Company will maintain an Acceptable Use Policy that defines acceptable and prohibited behaviors when using company IT resources, including guidelines for internet usage, email communications, and social media usage.


      7. Remote Access

        1. Secure Remote Access: Remote access to company systems will be secured through Virtual Private Networks (VPNs) or equivalent secure remote access technologies. Remote users will be held to the same security standards and controls as on-site users.

      8. Security Awareness and Training

        1. Regular Training: The Company will conduct regular security awareness and training programs for employees and users to promote understanding of security best practices, policies, and emerging threats.

      9. Security Monitoring and Auditing

        1. Continuous Monitoring: Continuous monitoring of IT systems, networks, and data will be conducted to proactively detect and respond to security events, vulnerabilities, and unauthorized activities.

        2. Audits and Assessments: Periodic audits and assessments will evaluate the effectiveness of security controls, compliance with policies, and alignment with industry best practices.

  • RESPONSIBILITIES

  • IT Department: The IT Department is responsible for implementing and maintaining IT security measures, developing security procedures, and ensuring compliance with this Policy.

  • All Employees and Authorized Users: All employees, contractors, vendors, and authorized users are responsible for complying with this Policy, reporting security incidents, and participating in security training programs.

  • POLICY REVIEW

    This IT Security Policy will be reviewed annually or more frequently if necessary. The purpose of these reviews is to assess its effectiveness, relevance to current threats, and compliance with relevant laws and regulations. Any updates or changes to this Policy will be communicated to all relevant individuals as necessary.



PRVIEW, INC.



____________________________

By: Lisa Ann Pinkerton

Title: Founder 

Join the PRVIEW Waitlist

Connect with us and see how PRVIEW can streamline your PR programs.

Contact Information