ITSM Policies

Policy NameDescriptionOwnerLatest VersionView Policy
ACCESS CONTROL & SECRET AUTHENTICATION POLICYGoverns who can access what resources and how their identity is verified.CISOV2.7View
BACKUP & RECOVERY POLICYOutlines procedures for data backup and restoration to ensure business continuity.CISOV2.5View
CHANGE MANAGEMENT POLICYEstablishes a systematic approach to managing and approving changes to IT systems.CISOV2.6View
CLOUD SECURITY POLICYSets guidelines for securing data and applications hosted in cloud environments.CISOV1.5View
CRYPTOGRAPHIC CONTROLS AND KEY MANAGEMENT POLICYDictates the use of encryption and the secure management of cryptographic keys.CISOV2.6View
DATA DISPOSAL POLICYSpecifies secure methods for permanently removing data from storage media.CISOV2.5View
DATA RETENTION & DESTRUCTION POLICYDefines how long data should be kept and how it should be securely disposed of.CISOV2.6View
FORENSIC READINESS POLICYEnsures the organization is prepared to collect and preserve digital evidence for investigations.CISOV2.5View
INCIDENT RESPONSE PLANDetails the step-by-step actions to be taken during a security incident.CISOV2.6View
IT APPLICATION SECURITY POLICYAddresses security requirements for the development, acquisition, and deployment of IT applications.CISOV2.5View
IT ASSET MANAGEMENT POLICYDefines procedures for tracking and managing IT assets throughout their lifecycle.CISOV2.5View
IT SECURITY STRATEGY POLICYOutlines the long-term goals and approach for information security within the organization.CISOV2.5View
NETWORK SECURITY POLICYEstablishes controls to protect the organization’s network infrastructure from threats.CISOV2.6View
OFFSITE STORAGE POLICYGoverns the secure storage of data and physical media at external locations.CISOV2.5View
OPEN SOURCE SOFTWARE POLICYProvides guidelines for the secure and compliant use of open-source software.CISOV2.5View
PHYSICAL SECURITY POLICYSets standards for protecting physical assets and facilities from unauthorized access.CISOV2.5View
STANDARD PRACTICES – LOG MANAGEMENTSpecifies guidelines for the collection, retention, and analysis of system and security logs.CISOV2.6View
STANDARD PRACTICE – SECURITY INCIDENT MANAGEMENT PROCESSDetails the specific steps for handling security incidents, from detection to post-incident review.CISOV2.5View
DORMANT ACCOUNT VERIFICATION & DEACTIVATION SOPFormal process for identifying and securing user accounts that have been inactive for a specified period to prevent fraud and maintain system security.CISOView
THIRD PARTY MANAGEMENT POLICYOutlines procedures for assessing and managing security risks associated with third-party vendors.CISOV2.5View
THREAT AND VULNERABILITY PROTECTION POLICYDescribes measures to identify, assess, and mitigate security threats and vulnerabilities.CISOV2.5View