Information Security Policy

Table of Contents

Purpose

Protect information entrusted to OutsourcedIn and our clients by maintaining its confidentiality, integrity, and availability; complying with applicable laws; and supporting safe, reliable delivery from the Philippines to Australia.

Scope

This policy applies to all OutsourcedIn employees, contractors, and third-party providers who access client or company information, systems, or devices—whether working from home, coworking hubs, or client environments in AU/PH.

Our security objectives

We will: 
  • Prevent unauthorised access, disclosure, alteration, or loss of information. 
  • Keep systems available to meet business and client requirements.
  • Comply with contractual, regulatory, and statutory requirements. 
  • Set measurable objectives, review them regularly, and continually improve.

Governance & roles

  • Executive sponsor (AU): owns the security posture and resources.
  • Security lead (PH): runs day-to-day security operations, risk, and incident response. 
  • Account leads: ensure client-specific controls are followed and reported. 
  • All staff: follow policies/SOPs, complete training, report incidents.

ISMS approach (lightweight, ISO-aligned)

OutsourcedIn operates a pragmatic security management system inspired by ISO/IEC 27001: risk-based controls, documented procedures, monitoring, and regular reviews (Plan-Do-Check-Act). Formal certification is optional; the framework supports it if required.

Risk Management

  • Maintain an information asset register and risk log.
  • Assess risks at onboarding and at least annually (likelihood × impact).
  • Treat risks via controls, process changes, or acceptance with sign-off. Log exceptions with owner, duration, and compensating controls.

Access & identity

Access & identity

  • Least-privilege access; remove access on role change/exit within 24 hours.
  • MFA where available; unique accounts (no shared logins). 
  • Client SSO honoured

Asset management & acceptable use

  • Company-managed device or approved BYOD with hardening.
  • No unapproved software; removable media restricted to business need.

Data classification & handling

  • Client-confidential, Internal, Public labels used in SOPs. 
  • Store client-confidential data in client systems whenever possible.

Encryption

  •  Encrypt data in transit (TLS) and at rest on managed endpoints/cloud storage.
  • Keys managed via a reputable cloud KMS where applicable.

Endpoint & device security

  • Baseline hardening (disk encryption, screen lock, AV/EDR, patching).
  • Admin rights restricted; USB storage blocked by default.

Network & cloud

  • Prefer working in the client’s tenant (Xero/MYOB/CRM/ticketing). 
  • VDI or secure gateway available for sensitive workflows (on request).

Monitoring & logging

  • System access and administrative actions logged (retain per client need).
  • Optional time-tracking/screen capture available only if the client requests it and staff are informed (off by default).
  • We do not use covert spyware/keystroke logging.

Vulnerability & patch management

  • Critical security patches applied as soon as practical; monthly patch cadence for others.
  • External dependencies monitored; high-severity alerts triaged within 1 business day.

Third parties & suppliers

  • Due diligence for HRIS, payroll, EDR/AV, hosting, background checks.
  • Contracts must include confidentiality, security obligations, and breach notice.

Secure work practices (remote-first)

  •  Private workspace, no shoulder-surfing; clean desk policy. 
  • Prohibit printing client-confidential data unless approved and logged.

Physical security (hubs)

  • Controlled access; visitor logs where applicable; CCTV where the facility provides it.

Business continuity & disaster recovery

  •  Documented contact trees, role coverage, and restoration priorities. 
  • Back-up/restore testing for any systems we operate; continuity for PH power/ISP issues (redundant internet or backup locations).

Privacy & data protection

We work primarily inside client systems under their instructions. We align with the Australian Privacy Act/APPs and the PH Data Privacy Act as applicable; clients may impose stricter controls by contract.

Incident management

  • Report immediately to [[email protected]](mailto:[email protected]) and the account lead. 
  • Classify, contain, eradicate, recover; notify affected clients per contract.
  • Post-incident review within 5 business days; actions tracked to closure.
  • KPIs: time-to-detect, time-to-contain, time-to-notify, recurrence rate.

Training & awareness

  • Security onboarding for every hire; annual refreshers.
  • Targeted modules for high-risk roles (finance ops, access admins). 
  • Phishing awareness and secure data-handling drills.

Policy compliance

  • Breaches may lead to disciplinary action up to termination.
  • Material client-specific requirements form part of the Scope/SOPs.

Continuous improvement

  • Quarterly reviews of risks, incidents, metrics, and audit findings; update SOPs and controls accordingly.
  • Leadership reviews this policy at least annually (or after material changes).