Information Security Policy
Table of Contents
Purpose
Protect information entrusted to OutsourcedIn and our clients by maintaining its confidentiality, integrity, and availability; complying with applicable laws; and supporting safe, reliable delivery from the Philippines to Australia.
Scope
This policy applies to all OutsourcedIn employees, contractors, and third-party providers who access client or company information, systems, or devices—whether working from home, coworking hubs, or client environments in AU/PH.
Our security objectives
We will:
- Prevent unauthorised access, disclosure, alteration, or loss of information.
- Keep systems available to meet business and client requirements.
- Comply with contractual, regulatory, and statutory requirements.
- Set measurable objectives, review them regularly, and continually improve.
Governance & roles
- Executive sponsor (AU): owns the security posture and resources.
- Security lead (PH): runs day-to-day security operations, risk, and incident response.
- Account leads: ensure client-specific controls are followed and reported.
- All staff: follow policies/SOPs, complete training, report incidents.
ISMS approach (lightweight, ISO-aligned)
OutsourcedIn operates a pragmatic security management system inspired by ISO/IEC 27001: risk-based controls, documented procedures, monitoring, and regular reviews (Plan-Do-Check-Act). Formal certification is optional; the framework supports it if required.
Risk Management
- Maintain an information asset register and risk log.
- Assess risks at onboarding and at least annually (likelihood × impact).
- Treat risks via controls, process changes, or acceptance with sign-off. Log exceptions with owner, duration, and compensating controls.
Access & identity
Access & identity
- Least-privilege access; remove access on role change/exit within 24 hours.
- MFA where available; unique accounts (no shared logins).
- Client SSO honoured
Asset management & acceptable use
- Company-managed device or approved BYOD with hardening.
- No unapproved software; removable media restricted to business need.
Data classification & handling
- Client-confidential, Internal, Public labels used in SOPs.
- Store client-confidential data in client systems whenever possible.
Encryption
- Encrypt data in transit (TLS) and at rest on managed endpoints/cloud storage.
- Keys managed via a reputable cloud KMS where applicable.
Endpoint & device security
- Baseline hardening (disk encryption, screen lock, AV/EDR, patching).
- Admin rights restricted; USB storage blocked by default.
Network & cloud
- Prefer working in the client’s tenant (Xero/MYOB/CRM/ticketing).
- VDI or secure gateway available for sensitive workflows (on request).
Monitoring & logging
- System access and administrative actions logged (retain per client need).
- Optional time-tracking/screen capture available only if the client requests it and staff are informed (off by default).
- We do not use covert spyware/keystroke logging.
Vulnerability & patch management
- Critical security patches applied as soon as practical; monthly patch cadence for others.
- External dependencies monitored; high-severity alerts triaged within 1 business day.
Third parties & suppliers
- Due diligence for HRIS, payroll, EDR/AV, hosting, background checks.
- Contracts must include confidentiality, security obligations, and breach notice.
Secure work practices (remote-first)
- Private workspace, no shoulder-surfing; clean desk policy.
- Prohibit printing client-confidential data unless approved and logged.
Physical security (hubs)
- Controlled access; visitor logs where applicable; CCTV where the facility provides it.
Business continuity & disaster recovery
- Documented contact trees, role coverage, and restoration priorities.
- Back-up/restore testing for any systems we operate; continuity for PH power/ISP issues (redundant internet or backup locations).
Privacy & data protection
We work primarily inside client systems under their instructions. We align with the Australian Privacy Act/APPs and the PH Data Privacy Act as applicable; clients may impose stricter controls by contract.
Incident management
- Report immediately to [[email protected]](mailto:[email protected]) and the account lead.
- Classify, contain, eradicate, recover; notify affected clients per contract.
- Post-incident review within 5 business days; actions tracked to closure.
- KPIs: time-to-detect, time-to-contain, time-to-notify, recurrence rate.
Training & awareness
- Security onboarding for every hire; annual refreshers.
- Targeted modules for high-risk roles (finance ops, access admins).
- Phishing awareness and secure data-handling drills.
Policy compliance
- Breaches may lead to disciplinary action up to termination.
- Material client-specific requirements form part of the Scope/SOPs.
Continuous improvement
- Quarterly reviews of risks, incidents, metrics, and audit findings; update SOPs and controls accordingly.
- Leadership reviews this policy at least annually (or after material changes).
Contact
Questions or suspected incidents: [email protected]