| Policy Name | Description | Owner | Latest Version | View Policy | |
| ACCESS CONTROL & SECRET AUTHENTICATION POLICY | Governs who can access what resources and how their identity is verified. | CISO | V2.7 | View | |
| BACKUP & RECOVERY POLICY | Outlines procedures for data backup and restoration to ensure business continuity. | CISO | V2.5 | View | |
| CHANGE MANAGEMENT POLICY | Establishes a systematic approach to managing and approving changes to IT systems. | CISO | V2.6 | View | |
| CLOUD SECURITY POLICY | Sets guidelines for securing data and applications hosted in cloud environments. | CISO | V1.5 | View | |
| CRYPTOGRAPHIC CONTROLS AND KEY MANAGEMENT POLICY | Dictates the use of encryption and the secure management of cryptographic keys. | CISO | V2.6 | View | |
| DATA DISPOSAL POLICY | Specifies secure methods for permanently removing data from storage media. | CISO | V2.5 | View | |
| DATA RETENTION & DESTRUCTION POLICY | Defines how long data should be kept and how it should be securely disposed of. | CISO | V2.6 | View | |
| FORENSIC READINESS POLICY | Ensures the organization is prepared to collect and preserve digital evidence for investigations. | CISO | V2.5 | View | |
| INCIDENT RESPONSE PLAN | Details the step-by-step actions to be taken during a security incident. | CISO | V2.6 | View | |
| IT APPLICATION SECURITY POLICY | Addresses security requirements for the development, acquisition, and deployment of IT applications. | CISO | V2.5 | View | |
| IT ASSET MANAGEMENT POLICY | Defines procedures for tracking and managing IT assets throughout their lifecycle. | CISO | V2.5 | View | |
| IT SECURITY STRATEGY POLICY | Outlines the long-term goals and approach for information security within the organization. | CISO | V2.5 | View | |
| NETWORK SECURITY POLICY | Establishes controls to protect the organization’s network infrastructure from threats. | CISO | V2.6 | View | |
| OFFSITE STORAGE POLICY | Governs the secure storage of data and physical media at external locations. | CISO | V2.5 | View | |
| OPEN SOURCE SOFTWARE POLICY | Provides guidelines for the secure and compliant use of open-source software. | CISO | V2.5 | View | |
| PHYSICAL SECURITY POLICY | Sets standards for protecting physical assets and facilities from unauthorized access. | CISO | V2.5 | View | |
| STANDARD PRACTICES – LOG MANAGEMENT | Specifies guidelines for the collection, retention, and analysis of system and security logs. | CISO | V2.6 | View | |
| STANDARD PRACTICE – SECURITY INCIDENT MANAGEMENT PROCESS | Details the specific steps for handling security incidents, from detection to post-incident review. | CISO | V2.5 | View | |
| DORMANT ACCOUNT VERIFICATION & DEACTIVATION SOP | Formal process for identifying and securing user accounts that have been inactive for a specified period to prevent fraud and maintain system security. | CISO | | View | |
| THIRD PARTY MANAGEMENT POLICY | Outlines procedures for assessing and managing security risks associated with third-party vendors. | CISO | V2.5 | View | |
| THREAT AND VULNERABILITY PROTECTION POLICY | Describes measures to identify, assess, and mitigate security threats and vulnerabilities. | CISO | V2.5 | View | |