Lan Solver
Cybersecurity Policy
1. Introduction
Lan Solver is committed to protecting the integrity, confidentiality, and availability of the information and information systems used by the company. This cybersecurity policy defines the principles, guidelines, and security measures needed to protect information assets against internal and external threats, in line with ISO/IEC 27001.
2. Objective
The objective of this policy is to protect Lan Solver information against unauthorized access, misuse, disclosure, alteration, and destruction. It also aims to support business continuity, minimize damage, and maximize return on investment and business opportunities.
3. Scope
This policy applies to all employees, contractors, suppliers, and third parties who have access to Lan Solver systems and data. Everyone involved must strictly follow the guidelines set out here.
4. Security Principles
- Confidentiality: Ensure information is accessible only to authorized people.
- Integrity: Ensure the accuracy and completeness of information and processing methods.
- Availability: Ensure information and resources are available when needed.
5. Security Guidelines
5.1. Access Control
- Implement access controls based on least privilege.
- Require multi-factor authentication for access to critical systems.
- Review access permissions regularly so they stay aligned with user roles.
5.2. Data Protection
- Encrypt sensitive data at rest and in transit.
- Implement regular, secure backups to recover data after incidents.
- Ensure personal data is processed in line with applicable laws and regulations.
5.3. Monitoring and Detection
- Continuously monitor information systems to detect suspicious or unauthorized activity.
- Implement intrusion detection and prevention systems (IDPS).
- Retain access logs and security events for a minimum of two years.
5.4. Incident Response
- Establish an incident response plan to handle security breaches effectively.
- Train employees regularly on how to identify and respond to security incidents.
- Notify the cybersecurity team immediately when incidents occur.
5.5. Awareness and Training
- Run periodic cybersecurity training for all employees.
- Promote a cybersecurity culture and good practices in the use of systems and data.
5.6. Vulnerability Management
- Run regular vulnerability assessments and penetration tests to find and fix weaknesses.
- Apply security updates and patches in a timely manner to reduce risk.
5.7. Audits and Compliance
- Conduct regular audits to ensure compliance with this cybersecurity policy.
- Keep adequate documentation of all cybersecurity-related activities.
6. Responsibilities
- Cybersecurity Team: Responsible for implementing and monitoring this policy, running security audits, and responding to incidents.
- Managers: Must ensure their departments comply with this policy.
- Employees: Must follow cybersecurity guidelines and attend the training provided.
7. Policy Review
This policy will be reviewed annually or whenever there are material changes in systems, regulations, or the threat environment. The review is led by the cybersecurity team together with senior management.
8. Normative References
This policy is aligned with ISO/IEC 27001, ISO/IEC 27002, and other relevant information-security standards.
9. Approval
This policy was approved by Lan Solver senior management and takes effect from its publication date.
