You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/handbook/company/security/information-security.md
+14-6Lines changed: 14 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,12 +6,12 @@ navTitle: Information Security Policy and Acceptable Use Policy
6
6
7
7
| Policy owner | Effective date |
8
8
| -------------- | -------------- |
9
-
|@ZJvandeWeg| 2023-05-01|
9
+
|@knolleary| 2025-04-16|
10
10
11
11
12
12
## Overview
13
13
14
-
This Information Security Policy is intended to protect FlowFuse’s employees,
14
+
This Information Security Policy is intended to protect FlowFuse's employees,
15
15
partners and the company from illegal or damaging actions by individuals, either
16
16
knowingly or unknowingly.
17
17
@@ -26,7 +26,7 @@ understand this policy, and to conduct their activities accordingly.
26
26
## Purpose
27
27
28
28
The purpose of this policy is to communicate our information security policies
29
-
and outline the acceptable use and protection of FlowFuse’s information and
29
+
and outline the acceptable use and protection of FlowFuse's information and
30
30
assets. These rules are in place to protect customers, employees, and FlowFuse.
31
31
Inappropriate use exposes FlowFuse to risks including virus attacks, compromise
32
32
of network systems and services, financial and reputational risk, and legal and
@@ -126,6 +126,14 @@ to ensure compliance with this policy.
126
126
Employees must ensure the software they use is properly licensed and used as
127
127
intended.
128
128
129
+
### AI Tools Usage
130
+
131
+
When using AI tools:
132
+
1. Do not input sensitive or confidential information unless explicitly approved
133
+
2. Be aware of data retention and privacy policies of AI tools
134
+
3. Follow our security policies and guidelines
135
+
4. Report any security concerns related to AI tool usage immediately
136
+
129
137
## Unacceptable Use
130
138
131
139
Under no circumstances is an employee of FlowFuse authorized to engage in any
@@ -152,8 +160,8 @@ Role | Purpose
152
160
[Human Resources Policy](./human-resources.md) | To ensure that employees and contractors meet security requirements, understand their responsibilities, and are suitable for their roles.
153
161
[Incident Response Plan](./incident-response.md) | Policy and procedures for suspected or confirmed information security incidents.
154
162
[Operations Security Policy](./operations-security.md) | To ensure the correct and secure operation of information processing systems and facilities.
155
-
Physical Security Policy | To prevent unauthorized physical access or damage to the organization’s information and information processing facilities.
156
-
[Risk Management Policy](./risk-management.md) | To define the process for assessing and managing FlowFuse's information security risks in order to achieve the company’s business and information security objectives.
163
+
Physical Security Policy | To prevent unauthorized physical access or damage to the organization's information and information processing facilities.
164
+
[Risk Management Policy](./risk-management.md) | To define the process for assessing and managing FlowFuse's information security risks in order to achieve the company's business and information security objectives.
157
165
[Secure Development Policy](./secure-development.md) | To ensure that information security is designed and implemented within the development lifecycle for applications and information systems.
158
166
[Third Party Risk Management Policy](./third-party-risk-management.md) | To ensure protection of the organization's data and assets that are shared with, accessible to, or managed by suppliers, including external parties or third-party organizations such as service providers, vendors, and customers, and to maintain an agreed level of information security and service delivery in line with supplier agreements.
159
167
@@ -179,7 +187,7 @@ company procedures up to and including termination of employment.
179
187
180
188
## Whistleblower Policy
181
189
182
-
Our Whistleblower Policy is intended to encourage and enable employees and others to raise serious concerns internally so that we can address and correct inappropriate conduct and actions. It is the responsibility of all employees to report concerns about violations of our code of ethics or suspected violations of law or regulations that govern our operations. It is contrary to our values for anyone to retaliate against any employee or who in good faith reports an ethics violation, or a suspected violation of law, such as a complaint of discrimination, or suspected fraud, or suspected violation of any regulation. An employee who retaliates against someone who has reported a violation in good faith is subject to discipline up to and including termination of employment. Anonymous reports may be submitted via FlowFuse’s [Whistleblower Channel](https://forms.gle/mttPj8NXd9yhb31H7).
190
+
Our Whistleblower Policy is intended to encourage and enable employees and others to raise serious concerns internally so that we can address and correct inappropriate conduct and actions. It is the responsibility of all employees to report concerns about violations of our code of ethics or suspected violations of law or regulations that govern our operations. It is contrary to our values for anyone to retaliate against any employee or who in good faith reports an ethics violation, or a suspected violation of law, such as a complaint of discrimination, or suspected fraud, or suspected violation of any regulation. An employee who retaliates against someone who has reported a violation in good faith is subject to discipline up to and including termination of employment. Anonymous reports may be submitted via FlowFuse's [Whistleblower Channel](https://forms.gle/mttPj8NXd9yhb31H7).
183
191
184
192
---
185
193
Policy derived from [JupiterOne/security-policy-templates](https://github.com/JupiterOne/security-policy-templates) ([CC BY-SA 4 license](https://creativecommons.org/licenses/by-sa/4.0/)) and [Vanta](https://vanta.com)
0 commit comments